Re: [PATCH net] netfilter: nat: cope with negative port range

2018-02-13 Thread Paolo Abeni
On Tue, 2018-02-13 at 18:02 +0100, Florian Westphal wrote: > Paolo Abeni wrote: > > Fixes: c7232c9979cb ("netfilter: add protocol independent NAT core") > > are you sure? > When I looked this was a day 0 bug, the code was just moved from ipv4. You are right, the named commit just move around the

Re: [PATCH net] netfilter: nat: cope with negative port range

2018-02-13 Thread Florian Westphal
Paolo Abeni wrote: > Fixes: c7232c9979cb ("netfilter: add protocol independent NAT core") are you sure? When I looked this was a day 0 bug, the code was just moved from ipv4. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majord...@vger.k

[PATCH net] netfilter: nat: cope with negative port range

2018-02-13 Thread Paolo Abeni
syzbot reported a division by 0 bug in the netfilter nat code: divide error: [#1] SMP KASAN Dumping ftrace buffer: (ftrace buffer empty) Modules linked in: CPU: 1 PID: 4168 Comm: syzkaller034710 Not tainted 4.16.0-rc1+ #309 Hardware name: Google Google Compute Engine/Google Compute Engine