]> www.infradead.org Git - users/jedix/linux-maple.git/commit
netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
authorPablo Neira Ayuso <pablo@netfilter.org>
Tue, 22 Apr 2025 19:52:44 +0000 (21:52 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 5 May 2025 11:17:32 +0000 (13:17 +0200)
commitb85e3367a5716ed3662a4fe266525190d2af76df
tree20e2a7d10eb64ea8f94746508cd959de9ac43a3c
parent4c5c6aa9967dbe55bd017bb509885928d0f31206
netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX

Otherwise, it is possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof()
when resizing hashtable because __GFP_NOWARN is unset.

Similar to:

  b541ba7d1f5a ("netfilter: conntrack: clamp maximum hashtable size to INT_MAX")

Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_set_pipapo.c