diff options
author | Pablo Neira Ayuso <pablo@netfilter.org> | 2014-02-07 12:53:07 +0100 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2014-02-07 14:21:49 +0100 |
commit | bd7fc645dabab423ef362186db2917f3919321d3 (patch) | |
tree | 05a217da614270195838d57284b6e85d7935834e | |
parent | 0165d9325d6a3cf856e2cbbe64a0f4635ac75893 (diff) | |
download | op-kernel-dev-bd7fc645dabab423ef362186db2917f3919321d3.zip op-kernel-dev-bd7fc645dabab423ef362186db2917f3919321d3.tar.gz |
netfilter: nf_tables: do not allow NFT_SET_ELEM_INTERVAL_END flag and data
This combination is not allowed since end interval elements cannot
contain data.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Acked-by: Patrick McHardy <kaber@trash.net>
-rw-r--r-- | net/netfilter/nf_tables_api.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c index 3a2e480..d0c790e3e 100644 --- a/net/netfilter/nf_tables_api.c +++ b/net/netfilter/nf_tables_api.c @@ -2741,6 +2741,9 @@ static int nft_add_set_elem(const struct nft_ctx *ctx, struct nft_set *set, if (nla[NFTA_SET_ELEM_DATA] == NULL && !(elem.flags & NFT_SET_ELEM_INTERVAL_END)) return -EINVAL; + if (nla[NFTA_SET_ELEM_DATA] != NULL && + elem.flags & NFT_SET_ELEM_INTERVAL_END) + return -EINVAL; } else { if (nla[NFTA_SET_ELEM_DATA] != NULL) return -EINVAL; |