Files
kernel_arpi/include/uapi/linux
Pablo Neira Ayuso f0d1f04f0a netfilter: fix wrong arithmetics regarding NFT_REJECT_ICMPX_MAX
NFT_REJECT_ICMPX_MAX should be __NFT_REJECT_ICMPX_MAX - 1.

nft_reject_icmp_code() and nft_reject_icmpv6_code() are called from the
packet path, so BUG_ON in case we try to access an unknown abstracted
ICMP code. This should not happen since we already validate this from
nft_reject_{inet,bridge}_init().

Fixes: 51b0a5d ("netfilter: nft_reject: introduce icmp code abstraction for inet and bridge")
Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
2014-10-07 20:16:31 +02:00
..
2014-05-08 12:43:03 -04:00
2014-07-10 11:06:00 +01:00
2014-07-01 10:48:05 -06:00
2014-03-20 14:55:18 +01:00
2013-11-09 18:20:22 -05:00
2014-08-08 15:57:31 -07:00
2014-04-22 21:27:57 -04:00
2014-04-01 17:08:43 +02:00
2014-05-14 10:04:34 +01:00
2013-12-11 12:57:55 -08:00
2014-09-29 15:37:01 -04:00
2013-08-21 12:21:45 -07:00
2014-10-03 16:53:33 -07:00
2014-08-08 15:57:31 -07:00
2013-11-27 11:03:38 -08:00
2014-03-04 13:51:06 -05:00
2014-06-13 10:53:49 -04:00
2014-01-06 15:13:01 -05:00
2014-03-21 14:21:13 -04:00
2014-04-25 10:08:48 -07:00
2014-04-26 12:13:24 -04:00
2013-12-11 09:25:20 -02:00