mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
synced 2026-09-28 19:20:30 +00:00
netfilter: nft_limit: reject configurations that cause integer overflow
[ Upstream commitc9d9eb9c53] Reject bogus configs where internal token counter wraps around. This only occurs with very very large requests, such as 17gbyte/s. Its better to reject this rather than having incorrect ratelimit. Fixes:d2168e849e("netfilter: nft_limit: add per-byte limiting") Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
parent
c817f5c016
commit
bc6e242bb7
1 changed files with 16 additions and 7 deletions
Loading…
Add table
Add a link
Reference in a new issue