Commit e352fe4
committed
netfilter: nf_tables: unbind non-anonymous set if rule construction fails
jira LE-1907
cve CVE-2023-3390
Rebuild_History Non-Buildable kernel-rt-5.14.0-284.30.1.rt14.315.el9_2
commit-author Pablo Neira Ayuso <pablo@netfilter.org>
commit 3e70489
Otherwise a dangling reference to a rule object that is gone remains
in the set binding list.
Fixes: 26b5a57 ("netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
(cherry picked from commit 3e70489)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>1 parent 6a0ab7e commit e352fe4
1 file changed
+2
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4921 | 4921 | | |
4922 | 4922 | | |
4923 | 4923 | | |
| 4924 | + | |
| 4925 | + | |
4924 | 4926 | | |
4925 | 4927 | | |
4926 | 4928 | | |
| |||
0 commit comments