diff options
| author | Florian Westphal <fw@strlen.de> | 2016-04-01 14:17:22 +0200 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2016-06-24 10:18:22 -0700 |
| commit | 611d408a531fdbecf07e268ac87e37d71dd5cd8e (patch) | |
| tree | 4380e451a5953edb0d587ee120e3076ba8b1375b /tools/perf/scripts/python/sctop.py | |
| parent | d6f7cd1b21b9e797e09269ee16655f9c0e4a3fa1 (diff) | |
netfilter: x_tables: validate targets of jumps
commit 36472341017529e2b12573093cc0f68719300997 upstream.
When we see a jump also check that the offset gets us to beginning of
a rule (an ipt_entry).
The extra overhead is negible, even with absurd cases.
300k custom rules, 300k jumps to 'next' user chain:
[ plus one jump from INPUT to first userchain ]:
Before:
real 0m24.874s
user 0m7.532s
sys 0m16.076s
After:
real 0m27.464s
user 0m7.436s
sys 0m18.840s
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'tools/perf/scripts/python/sctop.py')
0 files changed, 0 insertions, 0 deletions
