mirror of https://gitee.com/openkylin/linux.git
netfilter: nf_tables: skip transaction if no update flags in tables
Skip transaction handling for table updates with no changes in the flags. This fixes a crash when passing the table flag with all bits unset. Reported-by: Ana Rey <anarey@gmail.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
e940f5d6ba
commit
63283dd21e
|
@ -407,6 +407,9 @@ static int nf_tables_updtable(struct nft_ctx *ctx)
|
||||||
if (flags & ~NFT_TABLE_F_DORMANT)
|
if (flags & ~NFT_TABLE_F_DORMANT)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (flags == ctx->table->flags)
|
||||||
|
return 0;
|
||||||
|
|
||||||
trans = nft_trans_alloc(ctx, NFT_MSG_NEWTABLE,
|
trans = nft_trans_alloc(ctx, NFT_MSG_NEWTABLE,
|
||||||
sizeof(struct nft_trans_table));
|
sizeof(struct nft_trans_table));
|
||||||
if (trans == NULL)
|
if (trans == NULL)
|
||||||
|
|
Loading…
Reference in New Issue