Page MenuHomeFreeBSD

pf: limit how many headers we look at
ClosedPublic

Authored by kp on Jun 3 2025, 12:48 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Feb 9, 10:22 AM
Unknown Object (File)
Sat, Feb 7, 3:12 AM
Unknown Object (File)
Thu, Jan 22, 11:17 PM
Unknown Object (File)
Jan 21 2026, 3:08 AM
Unknown Object (File)
Jan 19 2026, 1:03 PM
Unknown Object (File)
Jan 14 2026, 12:29 PM
Unknown Object (File)
Dec 28 2025, 2:19 PM
Unknown Object (File)
Nov 4 2025, 2:04 AM

Details

Reviewers
None
Group Reviewers
pfsense
Commits
rGdda88af8fa4e: pf: limit how many headers we look at
Summary

Limit the nested header chain for IPv6 extensions headers and for
authentication headers in the IPv4 case. This prevents spending
excessive cpu time on crafted packets.
OK henning@

Obtained from: OpenBSD, bluhm <bluhm@openbsd.org>, 2e5bc81177
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable