Find a file
Lennart Poettering 361d374a0f dhcp6: make sure we have enough space for the DHCP6 option header
Fixes a vulnerability originally discovered by Felix Wilhelm from
Google.

CVE-2018-15688
LP: #1795921
https://bugzilla.redhat.com/show_bug.cgi?id=1639067

(cherry picked from commit 4dac5eaba4e419b29c97da38a8b1f82336c2c892)
(cherry picked from commit 01ca2053bb)
(cherry picked from commit fc230dca13)
(cherry picked from commit cc1e5a7f57)
(cherry picked from commit c3221cb0c5)
(cherry picked from commit f4f7655341)
(cherry picked from commit 2a25872910)
(cherry picked from commit ec471872e4)
(cherry picked from commit 6e56de0d87)
2018-10-29 21:56:12 +01:00
callouts build: extract version macros from "nm-version.h" to new header file "nm-version-macros.h" 2015-09-30 23:35:52 +02:00
clients clients: fix appending integer to result in nmc_property_set_bytes() 2017-05-23 16:51:07 +02:00
contrib travis: fix setting NMTST_DEBUG for travis-check.sh script 2016-02-25 15:18:06 +01:00
data systemd: order NetworkManager.serivce after network-pre.target 2016-01-23 16:57:56 +01:00
docs build: extract version macros from "nm-version.h" to new header file "nm-version-macros.h" 2015-09-30 23:35:52 +02:00
examples examples: fix crash in add-connection-libnm 2016-04-20 07:53:02 +02:00
include macros: add NM_SET_OUT() macro 2016-04-11 15:32:48 +02:00
initscript remove paldo initscript 2013-05-06 16:33:14 +02:00
introspection introspection: add AUDIT domain to available list in SetLogging() description 2015-08-31 09:08:55 +02:00
libnm libnm: fix memleak of GUdevDevice in get_bus_name() 2017-03-20 11:36:18 +01:00
libnm-core libnm-core: remove INFERRABLE flag from dhcp-hostname property 2017-02-06 17:59:48 +01:00
libnm-glib libnm: fix memleak of GUdevDevice in get_bus_name() 2017-03-20 11:36:18 +01:00
libnm-util release: bump version to 1.0.10 2015-12-23 14:59:08 +01:00
m4 build: hack around compiler warning in g-ir-scanner 2015-11-11 15:45:59 +01:00
man man: fix typos 2015-12-24 09:58:33 +01:00
po po: fix some typos in Galician translation 2015-12-23 14:52:56 +01:00
policy policy: allow non-local admin sessions to control the network (rh #1145646) 2014-10-13 15:58:46 -05:00
src dhcp6: make sure we have enough space for the DHCP6 option header 2018-10-29 21:56:12 +01:00
tools tests/valgrind: rename name of logfile for valgrind run 2015-12-05 20:36:24 +01:00
vapi vapi: add some missing device and setting types 2015-01-23 15:37:47 -06:00
.dir-locals.el misc: add toplevel .dir-locals file that tells Emacs to show trailing whitespace 2013-03-08 15:15:28 +01:00
.gitignore build: extract version macros from "nm-version.h" to new header file "nm-version-macros.h" 2015-09-30 23:35:52 +02:00
.travis.yml build: fix travis file syntax 2016-03-02 15:39:42 +01:00
AUTHORS misc: update maintainers and authors 2016-04-21 13:39:38 -05:00
autogen.sh build: don't default to -Werror 2015-06-18 12:11:37 +02:00
ChangeLog fix typos in documentation and messages 2014-04-03 17:12:31 +02:00
configure.ac release: bump version to 1.0.13 (development) 2016-04-02 00:34:51 +02:00
CONTRIBUTING doc: update code style docs 2009-10-07 12:28:10 -07:00
COPYING docs: create new master NM documentation module 2011-02-16 16:24:16 -06:00
MAINTAINERS misc: update maintainers and authors 2016-04-21 13:39:38 -05:00
Makefile.am build: correctly set DISTCHECK_CONFIGURE_FLAGS 2015-06-18 12:11:38 +02:00
Makefile.glib build: update Makefile.glib 2013-04-19 10:52:21 -04:00
NetworkManager.pc.in build: update NetworkManager.pc 2013-01-29 16:17:30 -05:00
NEWS release: update NEWS 2016-04-02 00:19:47 +02:00
README trivial: typo fixes 2010-09-25 00:34:10 -05:00
TODO todo: remove item about finished VPN IPv6 support 2013-04-10 10:06:38 -05:00
valgrind.suppressions valgrind: add suppression for glib's g_thread_return() 2015-11-18 12:17:27 +01:00

******************
2008-12-11: NetworkManager core daemon has moved to git.freedesktop.org!

git clone git://git.freedesktop.org/git/NetworkManager/NetworkManager.git
******************


Networking that Just Works
--------------------------

NetworkManager attempts to keep an active network connection available at all
times.  The point of NetworkManager is to make networking configuration and
setup as painless and automatic as possible.  NetworkManager is intended to
replace default route, replace other routes, set IP addresses, and in general
configure networking as NM sees fit (with the possibility of manual override as
necessary).  In effect, the goal of NetworkManager is to make networking Just
Work with a minimum of user hassle, but still allow customization and a high
level of manual network control.  If you have special needs, we'd like to hear
about them, but understand that NetworkManager is not intended for every
use-case.

NetworkManager will attempt to keep every network device in the system up and
active, as long as the device is available for use (has a cable plugged in,
the killswitch isn't turned on, etc).  Network connections can be set to
'autoconnect', meaning that NetworkManager will make that connection active
whenever it and the hardware is available.

"Settings services" store lists of user- or administrator-defined "connections",
which contain all the settings and parameters required to connect to a specific
network.  NetworkManager will _never_ activate a connection that is not in this
list, or that the user has not directed NetworkManager to connect to.


How it works:

The NetworkManager daemon runs as a privileged service (since it must access
and control hardware), but provides a D-Bus interface on the system bus to
allow for fine-grained control of networking.  NetworkManager does not store
connections or settings, it is only the mechanism by which those connections
are selected and activated.

To store pre-defined network connections, two separate services, the "system
settings service" and the "user settings service" store connection information
and provide these to NetworkManager, also via D-Bus.  Each settings service
can determine how and where it persistently stores the connection information;
for example, the GNOME applet stores its configuration in GConf, and the system
settings service stores it's config in distro-specific formats, or in a distro-
agnostic format, depending on user/administrator preference.

A variety of other system services are used by NetworkManager to provide
network functionality: wpa_supplicant for wireless connections and 802.1x
wired connections, pppd for PPP and mobile broadband connections, DHCP clients
for dynamic IP addressing, dnsmasq for proxy nameserver and DHCP server
functionality for internet connection sharing, and avahi-autoipd for IPv4
link-local addresses.  Most communication with these daemons occurs, again,
via D-Bus.


Why doesn't my network Just Work?

Driver problems are the #1 cause of why NetworkManager sometimes fails to
connect to wireless networks.  Often, the driver simply doesn't behave in a
consistent manner, or is just plain buggy.  NetworkManager supports _only_
those drivers that are shipped with the upstream Linux kernel, because only
those drivers can be easily fixed and debugged.  ndiswrapper, vendor binary
drivers, or other out-of-tree drivers may or may not work well with
NetworkManager, precisely because they have not been vetted and improved by the
open-source community, and because problems in these drivers usually cannot
be fixed.

Sometimes, command-line tools like 'iwconfig' will work, but NetworkManager will
fail.  This is again often due to buggy drivers, because these drivers simply
aren't expecting the dynamic requests that NetworkManager and wpa_supplicant
make.  Driver bugs should be filed in the bug tracker of the distribution being
run, since often distributions customize their kernel and drivers.

Sometimes, it really is NetworkManager's fault.  If you think that's the case,
please file a bug at http://bugzilla.gnome.org and choose the NetworkManager
component.  Attaching the output of /var/log/messages or /var/log/daemon.log
(wherever your distribution directs syslog's 'daemon' facility output) is often
very helpful, and (if you can get) a working wpa_supplicant config file helps
enormously.