Fix CVE-2024-27415.
Florian Westphal (1):
netfilter: bridge: confirm multicast packets before passing them up
the stack
Pablo Neira Ayuso (1):
netfilter: br_netfilter: skip conntrack input hook for promisc packets
include/linux/netfilter.h | 1 +
net/bridge/br_input.c | 15 ++-
net/bridge/br_netfilter_hooks.c | 102 +++++++++++++++++++++
net/bridge/br_private.h | 1 +
net/bridge/netfilter/nf_conntrack_bridge.c | 36 ++++++++
net/netfilter/nf_conntrack_core.c | 1 +
6 files changed, 152 insertions(+), 4 deletions(-)
--
2.34.1