AI suggested a new package netfilter-persistent. I got excited
That's where I lost the game.
Turns out ufw and netfilter-persistent both packages want to own firewall-restore at boot, so apt resolves the conflict by removing one.
AI suggested a new package netfilter-persistent. I got excited
That's where I lost the game.
Turns out ufw and netfilter-persistent both packages want to own firewall-restore at boot, so apt resolves the conflict by removing one.
c'est comme netfilter, quand tu sais pas trop où vont les paquets, tu utilises floufilter.
Et tant qu’on y est, en Wi-Fi, faut-il appeler Wireguard Wifiguard ?
/me sort
c'est comme netfilter, quand tu sais pas trop où vont les paquets, tu utilises floufilter.
1/6: Network namespaces (netns)
A separate network namespace gives a Linux container its own virtualized (and fully isolated from the host) network "context" - a loopback device, a route table, netfilter/iptables rules, etc.
1/6: Network namespaces (netns)
A separate network namespace gives a Linux container its own virtualized (and fully isolated from the host) network "context" - a loopback device, a route table, netfilter/iptables rules, etc.
github.com/hack3ric/flow
github.com/hack3ric/flow
osec.io/blog/2024-11...
#linux #vulnerability #doublefree #kernel #cybersecurity #exploitation
osec.io/blog/2024-11...
#linux #vulnerability #doublefree #kernel #cybersecurity #exploitation
netfilter: nf_tables, introduced in 2014 and patched in Jan 2024.
securityaffairs.com/184076/secur...
netfilter: nf_tables, introduced in 2014 and patched in Jan 2024.
securityaffairs.com/184076/secur...
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: use...
https://www.thehackerwire.com/vulnerability/CVE-2026-97417/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: use...
https://www.thehackerwire.com/vulnerability/CVE-2026-97417/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
For example, Linux only got a decent netfilter (nftables) in 2014
For example, Linux only got a decent netfilter (nftables) in 2014
📊 n/a
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
sip_skip_whitespace() ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86907
#cybersecurity #infosec #cve #euvd
📊 n/a
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
sip_skip_whitespace() ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86907
#cybersecurity #infosec #cve #euvd
📊 7.5/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
The timestamp-only fas...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86030
#cybersecurity #infosec #cve #euvd
📊 7.5/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
The timestamp-only fas...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86030
#cybersecurity #infosec #cve #euvd
📊 7.0/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: cttimeout: prevent UAF during module unload
nf_ct_set_timeout() protects th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86740
#cybersecurity #infosec #cve #euvd
📊 7.0/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: cttimeout: prevent UAF during module unload
nf_ct_set_timeout() protects th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86740
#cybersecurity #infosec #cve #euvd
📊 7.0/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_log: unregister loggers before per-net teardown
nf_log_syslog and nfnetl...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86739
#cybersecurity #infosec #cve #euvd
📊 7.0/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_log: unregister loggers before per-net teardown
nf_log_syslog and nfnetl...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86739
#cybersecurity #infosec #cve #euvd
📊 7.8/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state
sashik...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86167
#cybersecurity #infosec #cve #euvd
📊 7.8/10
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state
sashik...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86167
#cybersecurity #infosec #cve #euvd
📊 n/a
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
sashiko says:
If map_ad...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87067
#cybersecurity #infosec #cve #euvd
📊 n/a
🏢 Linux
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
sashiko says:
If map_ad...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87067
#cybersecurity #infosec #cve #euvd
#Linux #netfilter
#Linux #netfilter
https://qriousec.github.io/post/cve-2023-52927/
https://qriousec.github.io/post/cve-2023-52927/