Commit 566645e
committed
netfilter: nf_tables: disallow element updates of bound anonymous sets
jira VUlN-429
subsystem-sync netfilter:nf_tables 4.18.0-511
commit-author Pablo Neira Ayuso <pablo@netfilter.org>
commit c88c535
Anonymous sets come with NFT_SET_CONSTANT from userspace. Although API
allows to create anonymous sets without NFT_SET_CONSTANT, it makes no
sense to allow to add and to delete elements for bound anonymous sets.
Fixes: 9651851 ("netfilter: add nftables")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
(cherry picked from commit c88c535)
Signed-off-by: Greg Rose <g.v.rose@ciq.com>1 parent d4cad0a commit 566645e
1 file changed
+5
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5646 | 5646 | | |
5647 | 5647 | | |
5648 | 5648 | | |
5649 | | - | |
| 5649 | + | |
| 5650 | + | |
5650 | 5651 | | |
5651 | 5652 | | |
5652 | 5653 | | |
| |||
5851 | 5852 | | |
5852 | 5853 | | |
5853 | 5854 | | |
5854 | | - | |
| 5855 | + | |
| 5856 | + | |
| 5857 | + | |
5855 | 5858 | | |
5856 | 5859 | | |
5857 | 5860 | | |
| |||
0 commit comments