Since we cannot make sure the 'hook_mask' will always be none zero
here. If it equals to zero, the num_hooks will be zero too, and then
kmalloc() will return ZERO_SIZE_PTR, which is (void *)16.
Then the following error check will fails:
ops = kmalloc(sizeof(*ops) * num_hooks, GFP_KERNEL);
if (ops == NULL)
return ERR_PTR(-ENOMEM);
So this patch fix this with just doing the zero check before calling
kmalloc() is called.
Maybe the case above will never happen here, but in theory.
Signed-off-by: Xiubo Li <redacted>
---
net/netfilter/x_tables.c | 3 +++
1 file changed, 3 insertions(+)
From: Pablo Neira Ayuso <pablo@netfilter.org> Date: 2016-06-01 09:27:18
On Wed, Jun 01, 2016 at 04:34:28PM +0800, Xiubo Li wrote:
quoted hunk
Since we cannot make sure the 'hook_mask' will always be none zero
here. If it equals to zero, the num_hooks will be zero too, and then
kmalloc() will return ZERO_SIZE_PTR, which is (void *)16.
Then the following error check will fails:
ops = kmalloc(sizeof(*ops) * num_hooks, GFP_KERNEL);
if (ops == NULL)
return ERR_PTR(-ENOMEM);
So this patch fix this with just doing the zero check before calling
kmalloc() is called.
Maybe the case above will never happen here, but in theory.
Signed-off-by: Xiubo Li <redacted>
---
net/netfilter/x_tables.c | 3 +++
1 file changed, 3 insertions(+)