diff options
author | Jakub Kicinski <kuba@kernel.org> | 2021-02-04 21:36:59 -0800 |
---|---|---|
committer | Jakub Kicinski <kuba@kernel.org> | 2021-02-04 21:37:00 -0800 |
commit | b3d2c7b876d450e1d2624fd67658acc96465a9e6 (patch) | |
tree | a267799b09073481f60bed915b19012a9e22b225 /tools | |
parent | 647b8dd5184665432cc8a2b5bca46a201f690c37 (diff) | |
parent | 8d6bca156e47d68551750a384b3ff49384c67be3 (diff) | |
download | linux-stable-b3d2c7b876d450e1d2624fd67658acc96465a9e6.tar.gz linux-stable-b3d2c7b876d450e1d2624fd67658acc96465a9e6.tar.bz2 linux-stable-b3d2c7b876d450e1d2624fd67658acc96465a9e6.zip |
Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf
Pablo Neira Ayuso says:
====================
Netfilter fixes for net
1) Fix combination of --reap and --update in xt_recent that triggers
UAF, from Jozsef Kadlecsik.
2) Fix current year in nft_meta selftest, from Fabian Frederick.
3) Fix possible UAF in the netns destroy path of nftables.
4) Fix incorrect checksum calculation when mangling ports in flowtable,
from Sven Auhagen.
* git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf:
netfilter: flowtable: fix tcp and udp header checksum update
netfilter: nftables: fix possible UAF over chains from packet path in netns
selftests: netfilter: fix current year
netfilter: xt_recent: Fix attempt to update deleted entry
====================
Link: https://lore.kernel.org/r/20210205001727.2125-1-pablo@netfilter.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'tools')
-rwxr-xr-x | tools/testing/selftests/netfilter/nft_meta.sh | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/tools/testing/selftests/netfilter/nft_meta.sh b/tools/testing/selftests/netfilter/nft_meta.sh index 087f0e6e71ce..f33154c04d34 100755 --- a/tools/testing/selftests/netfilter/nft_meta.sh +++ b/tools/testing/selftests/netfilter/nft_meta.sh @@ -23,7 +23,7 @@ ip -net "$ns0" addr add 127.0.0.1 dev lo trap cleanup EXIT -currentyear=$(date +%G) +currentyear=$(date +%Y) lastyear=$((currentyear-1)) ip netns exec "$ns0" nft -f /dev/stdin <<EOF table inet filter { |