Thread (8 messages) 8 messages, 3 authors, 2020-01-21

Re: [PATCH nf] netfilter: nf_tables: check for valid chain type pointer before dereference

From: Florian Westphal <fw@strlen.de>
Date: 2020-01-21 14:36:02
Also in: netfilter-devel

Pablo Neira Ayuso [off-list ref] wrote:
quoted
Otherwise, if a helper function to check for the families that are
really supported could be another alternative. But not sure it is
worth?
Not worth.

Probably this patch instead? Just make sure that access to the chain
type array is safe, no direct access to chain_type[][] anymore.

This includes the check for the default type too, since it cannot be
assume to always have a filter chain for unsupported families.

Thanks for explaining.
LGTM, this will prbably also fix the other sytbot splat wrt.
nla_strcmp().
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help