]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
netfilter: nft_dynset: disallow object maps
authorPablo Neira Ayuso <pablo@netfilter.org>
Tue, 15 Aug 2023 13:39:02 +0000 (15:39 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 26 Aug 2023 12:23:34 +0000 (14:23 +0200)
commitbf221e5e4b19c5b463af94281cb3dc4f8c792741
tree3591ad274efb07774d25774db9d22952093f7f72
parent9177869b85ddd9184d4f5e09eaa3d2d8547089af
netfilter: nft_dynset: disallow object maps

[ Upstream commit 23185c6aed1ffb8fc44087880ba2767aba493779 ]

Do not allow to insert elements from datapath to objects maps.

Fixes: 8aeff920dcc9 ("netfilter: nf_tables: add stateful object reference to set elements")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/netfilter/nft_dynset.c