diff options
author | Pablo Neira Ayuso <pablo@netfilter.org> | 2024-01-29 13:12:33 +0100 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2024-01-31 23:14:14 +0100 |
commit | 8059918a1377f2f1fff06af4f5a4ed3d5acd6bc4 (patch) | |
tree | 5cf96a37323e797c0f49d93cacc352869653cc06 /crypto/adiantum.c | |
parent | 259eb32971e9eb24d1777a28d82730659f50fdcb (diff) |
netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations
- Disallow families other than NFPROTO_{IPV4,IPV6,INET}.
- Disallow layer 4 protocol with no ports, since destination port is a
mandatory attribute for this object.
Fixes: 857b46027d6f ("netfilter: nft_ct: add ct expectations support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'crypto/adiantum.c')
0 files changed, 0 insertions, 0 deletions