Skip to content

Commit 3c167e1

Browse files
committed
netfilter: nf_conntrack_bridge: initialize err to 0
jira LE-1907 cve CVE-2024-27415 Rebuild_History Non-Buildable kernel-5.14.0-427.33.1.el9_4 commit-author Linkui Xiao <xiaolinkui@kylinos.cn> commit a44af08 K2CI reported a problem: consume_skb(skb); return err; [nf_br_ip_fragment() error] uninitialized symbol 'err'. err is not initialized, because returning 0 is expected, initialize err to 0. Fixes: 3c171f4 ("netfilter: bridge: add connection tracking system") Reported-by: k2ci <kernel-bot@kylinos.cn> Signed-off-by: Linkui Xiao <xiaolinkui@kylinos.cn> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> (cherry picked from commit a44af08) Signed-off-by: Jonathan Maple <jmaple@ciq.com>
1 parent 65676da commit 3c167e1

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

net/bridge/netfilter/nf_conntrack_bridge.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ static int nf_br_ip_fragment(struct net *net, struct sock *sk,
3737
ktime_t tstamp = skb->tstamp;
3838
struct ip_frag_state state;
3939
struct iphdr *iph;
40-
int err;
40+
int err = 0;
4141

4242
/* for offloaded checksums cleanup checksum before fragmentation */
4343
if (skb->ip_summed == CHECKSUM_PARTIAL &&

0 commit comments

Comments
 (0)