Netfilter-Devel Archive on
 help / color / Atom feed
* [ANNOUNCE] ipset 7.5 released
@ 2020-01-09 19:42 Kadlecsik József
  0 siblings, 0 replies; only message in thread
From: Kadlecsik József @ 2020-01-09 19:42 UTC (permalink / raw)
  To: netfilter, netfilter-devel


ipset 7.5 is just released - please upgrade to this version! The syzkaller 
fuzzer discovered a NULL dereference bug in ipset, which was fixed by 
Florian Westphal. The CAP_NET_ADMIN capability is required to exploit the 
vulnerability. Other than that, the release brings a lot of backward 
compatibility improvements, thanks to Serhey Popovych.

Userspace changes:
  - Support building with old autoconf 2.63
    (Serhey Popovych)
  - Build on kernels without skb->vlan_proto correctly
    (Serhey Popovych)
  - Add cond_resched_rcu() checks (Serhey Popovych)
  - Better match for ipv6_skip_exthdr() frag_offp
    arg presence (Serhey Popovych)
  - Document explicitly that protocol is not stored in bitmap:port
Kernel part changes:
  - netfilter: ipset: avoid null deref when IPSET_ATTR_LINENO is present
    (Florian Westphal)
  - ip_set: Pass init_net when @net is missing in match check params
    data structure (Serhey Popovych)
  - netfilter: xt_set: Do not restrict --map-set to the mangle table
    (Serhey Popovych)
  - compat: em_ipset: Build on old kernels (Serhey Popovych)
  - compat: Use skb_vlan_tag_present() instead of vlan_tx_tag_present()
    (Serhey Popovych)

You can download the source code of ipset from:

Best regards,
E-mail  :,
PGP key :
Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences
          H-1525 Budapest 114, POB. 49, Hungary

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, back to index

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-01-09 19:42 [ANNOUNCE] ipset 7.5 released Kadlecsik József

Netfilter-Devel Archive on

Archives are clonable:
	git clone --mirror netfilter-devel/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 netfilter-devel netfilter-devel/ \
	public-inbox-index netfilter-devel

Example config snippet for mirrors

Newsgroup available over NNTP:

AGPL code for this site: git clone