-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Backports 5.0.x V2 Batched backports of several issues #4725
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
When a TCP DNS flow would start with a GAP on the TS side, the successful protocol detection on the TC side would trigger 'opposing side' reassembly and app-layer processing. In this case the stream flags would indicate the wrong direction and the wrong parser would be called. (cherry picked from commit efee458)
Suricata generates an error on unrecognised ERF types. Suricata should ignore ERF 'Provenance' records with ERF_TYPE_META. (cherry picked from commit 47082dd)
This commit places restrictions on the length of the file name specified in attachments (`name=` or `filename=`) to `NAME_MAX`. Names exceeding these limits will be truncated and processing will continue with the truncated name. (cherry picked from commit d0d20bd)
(cherry picked from commit 130b8d2)
(cherry picked from commit 9a33b5d)
(cherry picked from commit c92975e)
(cherry picked from commit bcea730)
(cherry picked from commit 6d94b09)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit 6c35039)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit 9fe51a8)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit c2071e1)
Corrects misplaced backticks preventing proper formatting of `mpm-algo` section. (cherry picked from commit 8c132c0)
For the backport, ERSPAN TypeI decode is 1. Disabled by default 2. Configurable: `decoder.erspan_typeI.enabled` (cherry picked from commit ae6beed)
Switch to isspace() as well. (cherry picked from commit 52970d8)
(cherry picked from commit 0715e13)
This commit removes documentation for the never-implemented bitmask option for the `byte_jump` and `byte_test` keywords.
This was referenced Mar 24, 2020
Continued in #4728 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
TEST: This PR includes use of v2 of the github checkouts action for centos-8 only.
Continuation of #4620, #4625, #4635, #4658, #4694, #4703
Backports of: