aboutsummaryrefslogtreecommitdiff
path: root/net/ipv4
diff options
context:
space:
mode:
authorHarald Welte <laforge@netfilter.org>2005-11-09 13:02:16 -0800
committerDavid S. Miller <davem@davemloft.net>2005-11-09 13:02:16 -0800
commited77de9fc69076e6e7c85edf7c1b70650f53121a (patch)
treeeb75bc1a632003f97d50920023e7802f5e2ae169 /net/ipv4
parent5978a9b82c55b82a1087bd86e0ae8b00f94d0d0b (diff)
[NETFILTER] nfnetlink: only load subsystems if CAP_NET_ADMIN is set
Without this patch, any user can cause nfnetlink subsystems to be autoloaded. Those subsystems however could add significant processing overhead to packet processing, and would refuse any configuration messages from non-CAP_NET_ADMIN processes anyway. This patch follows a suggestion from Patrick McHardy. Signed-off-by: Harald Welte <laforge@netfilter.org> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv4')
0 files changed, 0 insertions, 0 deletions