From: "Kadlecsik József" <kadlec@blackhole.kfki.hu>
To: netfilter@vger.kernel.org, netfilter-devel@vger.kernel.org
Subject: [ANNOUNCE] ipset 7.5 released
Date: Thu, 9 Jan 2020 20:42:56 +0100 (CET) [thread overview]
Message-ID: <alpine.DEB.2.20.2001092035200.7220@blackhole.kfki.hu> (raw)
Hi,
ipset 7.5 is just released - please upgrade to this version! The syzkaller
fuzzer discovered a NULL dereference bug in ipset, which was fixed by
Florian Westphal. The CAP_NET_ADMIN capability is required to exploit the
vulnerability. Other than that, the release brings a lot of backward
compatibility improvements, thanks to Serhey Popovych.
Userspace changes:
- configure.ac: Support building with old autoconf 2.63
(Serhey Popovych)
- configure.ac: Build on kernels without skb->vlan_proto correctly
(Serhey Popovych)
- configure.ac: Add cond_resched_rcu() checks (Serhey Popovych)
- configure.ac: Better match for ipv6_skip_exthdr() frag_offp
arg presence (Serhey Popovych)
- Document explicitly that protocol is not stored in bitmap:port
Kernel part changes:
- netfilter: ipset: avoid null deref when IPSET_ATTR_LINENO is present
(Florian Westphal)
- ip_set: Pass init_net when @net is missing in match check params
data structure (Serhey Popovych)
- netfilter: xt_set: Do not restrict --map-set to the mangle table
(Serhey Popovych)
- compat: em_ipset: Build on old kernels (Serhey Popovych)
- compat: Use skb_vlan_tag_present() instead of vlan_tx_tag_present()
(Serhey Popovych)
You can download the source code of ipset from:
http://ipset.netfilter.org
ftp://ftp.netfilter.org/pub/ipset/
git://git.netfilter.org/ipset.git
Best regards,
Jozsef
-
E-mail : kadlec@blackhole.kfki.hu, kadlecsik.jozsef@wigner.mta.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences
H-1525 Budapest 114, POB. 49, Hungary
reply other threads:[~2020-01-09 19:43 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=alpine.DEB.2.20.2001092035200.7220@blackhole.kfki.hu \
--to=kadlec@blackhole.kfki.hu \
--cc=netfilter-devel@vger.kernel.org \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).