summaryrefslogtreecommitdiffstats
path: root/net/netfilter/nft_payload.c
diff options
context:
space:
mode:
authorFlorian Westphal2016-12-13 13:59:33 +0100
committerPablo Neira Ayuso2016-12-14 23:39:06 +0100
commit3e38df136e453aa69eb4472108ebce2fb00b1ba6 (patch)
tree84b1474ffeb5ec38448abeb61cc5cf380e1ab892 /net/netfilter/nft_payload.c
parentnetfilter: nft_queue: use raw_smp_processor_id() (diff)
downloadkernel-qcow2-linux-3e38df136e453aa69eb4472108ebce2fb00b1ba6.tar.gz
kernel-qcow2-linux-3e38df136e453aa69eb4472108ebce2fb00b1ba6.tar.xz
kernel-qcow2-linux-3e38df136e453aa69eb4472108ebce2fb00b1ba6.zip
netfilter: nf_tables: fix oob access
BUG: KASAN: slab-out-of-bounds in nf_tables_rule_destroy+0xf1/0x130 at addr ffff88006a4c35c8 Read of size 8 by task nft/1607 When we've destroyed last valid expr, nft_expr_next() returns an invalid expr. We must not dereference it unless it passes != nft_expr_last() check. Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/netfilter/nft_payload.c')
0 files changed, 0 insertions, 0 deletions