/linux/net/bridge/netfilter/ |
H A D | ebt_mark_m.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
H A D | ebt_mark.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
H A D | ebt_limit.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
H A D | ebtables.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
/linux/net/netfilter/ |
H A D | xt_limit.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
H A D | x_tables.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
H A D | Kconfig | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
/linux/include/linux/netfilter_arp/ |
H A D | arp_tables.h | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
/linux/include/linux/netfilter_ipv4/ |
H A D | ip_tables.h | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
/linux/include/linux/netfilter_ipv6/ |
H A D | ip6_tables.h | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
/linux/include/linux/netfilter/ |
H A D | x_tables.h | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
/linux/net/ipv4/netfilter/ |
H A D | arp_tables.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
H A D | ip_tables.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
/linux/net/ipv6/netfilter/ |
H A D | ip6_tables.c | diff 47a6959fa331fe892a4fc3b48ca08e92045c6bda Mon Apr 26 12:14:40 CEST 2021 Florian Westphal <fw@strlen.de> netfilter: allow to turn off xtables compat layer
The compat layer needs to parse untrusted input (the ruleset) to translate it to a 64bit compatible format.
We had a number of bugs in this department in the past, so allow users to turn this feature off.
Add CONFIG_NETFILTER_XTABLES_COMPAT kconfig knob and make it default to y to keep existing behaviour.
Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|