summaryrefslogtreecommitdiffstats
path: root/kernel/include/linux
diff options
context:
space:
mode:
authorVasily Averin <vvs@virtuozzo.com>2020-11-19 14:59:51 +0100
committerJozsef Kadlecsik <kadlec@netfilter.org>2020-11-19 14:59:51 +0100
commit434aa00c04428bdded30191477064ab4078e7fe8 (patch)
tree426a007553fa86e3ee59455854f6cb669d8d5ffd /kernel/include/linux
parent018b075caad2f2f224e4d1b365a88d0dcf97e223 (diff)
netfilter: ipset: enable memory accounting for ipset allocations
Currently netadmin inside non-trusted container can quickly allocate whole node's memory via request of huge ipset hashtable. Other ipset-related memory allocations should be restricted too. v2: fixed typo ALLOC -> ACCOUNT Signed-off-by: Vasily Averin <vvs@virtuozzo.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Jozsef Kadlecsik <kadlec@netfilter.org>
Diffstat (limited to 'kernel/include/linux')
0 files changed, 0 insertions, 0 deletions