]> git.ipfire.org Git - thirdparty/ipset.git/commit
netfilter: ipset: enable memory accounting for ipset allocations
authorVasily Averin <vvs@virtuozzo.com>
Thu, 19 Nov 2020 13:59:51 +0000 (14:59 +0100)
committerJozsef Kadlecsik <kadlec@netfilter.org>
Thu, 19 Nov 2020 13:59:51 +0000 (14:59 +0100)
commit434aa00c04428bdded30191477064ab4078e7fe8
tree426a007553fa86e3ee59455854f6cb669d8d5ffd
parent018b075caad2f2f224e4d1b365a88d0dcf97e223
netfilter: ipset: enable memory accounting for ipset allocations

Currently netadmin inside non-trusted container can quickly allocate
whole node's memory via request of huge ipset hashtable.
Other ipset-related memory allocations should be restricted too.

v2: fixed typo ALLOC -> ACCOUNT

Signed-off-by: Vasily Averin <vvs@virtuozzo.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Jozsef Kadlecsik <kadlec@netfilter.org>
kernel/net/netfilter/ipset/ip_set_core.c