Description: netfilter: nftables: avoid overflows in nft_hash_buckets() References: Notes: carnil> Introduced in 0ed6389c483d ("netfilter: nf_tables: rename set carnil> implementations"). Vulnerable versions: 4.9-rc1. Bugs: upstream: released (5.13-rc1) [a54754ec9891830ba548e2010c889e3c8146e449] 6.7-upstream-stable: N/A "Fixed before branching point" 6.6-upstream-stable: N/A "Fixed before branching point" 6.1-upstream-stable: N/A "Fixed before branching point" 5.10-upstream-stable: released (5.10.38) [72b49dd116ca00a46a11d5a4d8d7987f05ed9cd7] 4.19-upstream-stable: released (4.19.191) [efcd730ddd6f25578bd31bfe703e593e2421d708] sid: released (5.10.38-1) 6.1-bookworm-security: N/A "Fixed before branching point" 5.10-bullseye-security: N/A "Fixed before branching point" 4.19-buster-security: released (4.19.194-1)