Commit ae5e128
committed
netfilter: nf_tables: skip bound chain on rule flush
jira VULN-6585
cve CVE-2023-3777
commit-author Pablo Neira Ayuso <pablo@netfilter.org>
commit 6eaf41e
Skip bound chain when flushing table rules, the rule that owns this
chain releases these objects.
Otherwise, the following warning is triggered:
WARNING: CPU: 2 PID: 1217 at net/netfilter/nf_tables_api.c:2013 nf_tables_chain_destroy+0x1f7/0x210 [nf_tables]
CPU: 2 PID: 1217 Comm: chain-flush Not tainted 6.1.39 #1
RIP: 0010:nf_tables_chain_destroy+0x1f7/0x210 [nf_tables]
Fixes: d0e2c7d ("netfilter: nf_tables: add NFT_CHAIN_BINDING")
Reported-by: Kevin Rich <kevinrich1337@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Florian Westphal <fw@strlen.de>
(cherry picked from commit 6eaf41e)
Signed-off-by: Anmol Jain <ajain@ciq.com>1 parent 2dd2826 commit ae5e128
1 file changed
+2
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3756 | 3756 | | |
3757 | 3757 | | |
3758 | 3758 | | |
| 3759 | + | |
| 3760 | + | |
3759 | 3761 | | |
3760 | 3762 | | |
3761 | 3763 | | |
| |||
0 commit comments