No description
  • C 98.8%
  • Makefile 1%
  • M4 0.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Pablo Neira Ayuso 6b3bded9a9 set: Check array boundary when parsing NFTA_SET_DESC_CONCAT
When parsing NFTA_SET_DESC_CONCAT coming from the kernel, make sure
provided list does not go over the boundary, resulting in an array
overrun. This is hardening for correctness, kernel should not be sending
a list larger than NFT_REG32_COUNT.

Reported-by: Bar Hofesh <bar.hofesh@brightsec.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
2026-10-06 13:32:39 +02:00
examples examples: nft-rule-add: Fix compile on musl libc 2026-03-20 11:25:20 +01:00
include src: add connlimit stateful object support 2026-08-17 23:03:11 +02:00
m4 initial version of libnftables 2012-10-11 15:15:02 +02:00
src set: Check array boundary when parsing NFTA_SET_DESC_CONCAT 2026-10-06 13:32:39 +02:00
tests tests: Fix for ASAN 2024-12-04 15:44:05 +01:00
.gitignore Update gitignore. 2020-01-18 21:22:29 +01:00
autogen.sh build: add an autogen.sh script 2013-05-16 18:43:00 +02:00
configure.ac build: libnftnl 1.3.2 release 2026-08-31 19:13:47 +02:00
COPYING update COPYING 2014-01-15 10:19:06 +01:00
doxygen.cfg.in src: get rid of aliases and compat 2016-12-20 14:17:22 +01:00
libnftnl.pc.in Add Requires.private field to libnftnl.pc 2019-07-05 20:27:45 +02:00
Make_global.am build: libnftnl 1.3.2 release 2026-08-31 19:13:47 +02:00
Makefile.am rename library to libnftnl 2014-01-20 10:43:45 +01:00