freebsd kernel with SKQ
Go to file
Kristof Provost d47023236c pf: Limit the maximum number of fragments per packet
Similar to the network stack issue fixed in r337782 pf did not limit the number
of fragments per packet, which could be exploited to generate high CPU loads
with a crafted series of packets.

Limit each packet to no more than 64 fragments. This should be sufficient on
typical networks to allow maximum-sized IP frames.

This addresses the issue for both IPv4 and IPv6.

MFC after:	3 days
Security:	CVE-2018-5391
Sponsored by:	Klara Systems
2018-08-17 15:00:10 +00:00
bin ls(1): Add --color=when 2018-08-17 04:15:51 +00:00
cddl Add partial documentation for dtrace(1)'s -x configuration options. 2018-08-16 19:28:44 +00:00
contrib Fix a broken "SEE ALSO" section of hlfsd(8). 2018-08-14 20:33:48 +00:00
crypto Merge OpenSSL 1.0.2p. 2018-08-14 17:48:02 +00:00
etc Revert parts of r337849 and r337857 2018-08-15 23:18:34 +00:00
gnu Update libstdc++ configuration. 2018-07-16 18:53:28 +00:00
include Install symlink for sys/nvpair.h in include/Makefile symlinks target 2018-08-13 05:16:27 +00:00
kerberos5 krb5-config build: Remove gratuitous escaping 2018-08-12 00:06:21 +00:00
lib Fix style nits. 2018-08-17 14:37:13 +00:00
libexec Remove pointless comment. 2018-08-03 10:59:05 +00:00
release build: skip the database check when generating install media 2018-08-17 07:27:15 +00:00
rescue Avoid referencing private lib names directly. 2017-11-10 07:53:02 +00:00
sbin Consistently use NULL to terminate the argv; no functional changes. 2018-08-17 14:57:13 +00:00
secure Fix build after r337852: Don't rebuild moduli based on unrelated moduli.c 2018-08-16 19:48:07 +00:00
share Add efidev(4)/efirt(9) 2018-08-17 04:17:51 +00:00
stand Add ashldi3 and ashrdi3 to mips. 2018-08-16 19:39:02 +00:00
sys pf: Limit the maximum number of fragments per packet 2018-08-17 15:00:10 +00:00
targets Remove special cases for armeb in the build. 2018-07-17 23:23:54 +00:00
tests Add test cases for Poly1305 from RFC 7539 2018-08-17 00:32:00 +00:00
tools Specify DB_FROM_SRC=yes when doing any installation target. 2018-08-16 22:13:43 +00:00
usr.bin dtc(1): Update to 97d2d5715eeb45108cc60367fdf6bd5b2046b050 2018-08-17 13:24:48 +00:00
usr.sbin Add the possibility to mark packets urgent based on their length. 2018-08-17 10:18:45 +00:00
.arcconfig callsign isn't required anymore 2016-09-29 06:19:45 +00:00
.arclint arc lint: ignore /tests/ in chmod 2017-12-19 03:38:06 +00:00
.gitattributes Remove spuriously added svn properties 2018-08-02 18:37:02 +00:00
.gitignore Ignore _.universe-toolchain file. 2018-07-01 13:50:37 +00:00
COPYRIGHT Remove 'All Rights Reserved' from the collection copyright and templates. 2018-05-09 02:02:49 +00:00
LOCKS LOCKS: update current locks 2018-06-09 03:08:04 +00:00
MAINTAINERS Add pointer to freebsd-numerics for libm. 2018-07-16 15:29:32 +00:00
Makefile Import OpenSSL 1.0.2p. 2018-08-14 16:18:14 +00:00
Makefile.inc1 build: skip the database check when generating install media 2018-08-17 07:27:15 +00:00
Makefile.libcompat Install the 32-bit compat sanitizer libraries. 2018-08-03 18:52:51 +00:00
Makefile.sys.inc AUTO_OBJ: For all top-level targets enforce using an OBJDIR. 2017-12-05 21:29:47 +00:00
ObsoleteFiles.inc Add a few forgotten files to ObsoleteFiles.inc: 2018-07-25 17:14:05 +00:00
README Import OpenSSL 1.0.2p. 2018-08-14 16:18:14 +00:00
README.md README: add generic notes about GENERIC and NOTES 2018-06-17 19:44:24 +00:00
UPDATING ls(1): Add --color=when 2018-08-17 04:15:51 +00:00

FreeBSD Source:

This is the top level of the FreeBSD source directory. This file was last revised on: FreeBSD

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html, and https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html for more information, including setting make(1) variables.

Source Roadmap:

bin		System/user commands.

cddl		Various commands and libraries under the Common Development
		and Distribution License.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

rescue		Build system for statically linked /rescue utilities.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

stand		Boot loader sources.

sys		Kernel sources.

sys/<arch>/conf Kernel configuration files. GENERIC is the configuration
		used in release builds. NOTES contains documentation of
		all possible entries.

tests		Regression tests which can be run by Kyua.  See tests/README
		for additional information.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see:

https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/current-stable.html