diff options
author | Jozsef Kadlecsik <kadlec@netfilter.org> | 2021-07-14 12:37:07 +0200 |
---|---|---|
committer | Jozsef Kadlecsik <kadlec@netfilter.org> | 2021-07-14 12:40:49 +0200 |
commit | 15932461c91e8aedf54e885d429b954b439605d2 (patch) | |
tree | 23bed1696242969f326735a809da308b94ff5cd6 /lib | |
parent | 578462f89dab9d91c38f74a93bc6855ced11ea3c (diff) |
Limit the maximal range of consecutive elements to add/delete
The range size of consecutive elements were not limited. Thus one
could define a huge range which may result soft lockup errors due
to the long execution time. Now the range size is limited to 2^20
entries. Reported by Brad Spengler.
Signed-off-by: Jozsef Kadlecsik <kadlec@netfilter.org>
Diffstat (limited to 'lib')
-rw-r--r-- | lib/errcode.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/lib/errcode.c b/lib/errcode.c index b38f95e..76bab74 100644 --- a/lib/errcode.c +++ b/lib/errcode.c @@ -25,6 +25,8 @@ static const struct ipset_errcode_table core_errcode_table[] = { "The set with the given name does not exist" }, { EMSGSIZE, 0, "Kernel error received: message could not be created" }, + { ERANGE, 0, + "The specified range is too large, split it up into smaller ranges" }, { IPSET_ERR_PROTOCOL, 0, "Kernel error received: ipset protocol error" }, |