]> git.ipfire.org Git - thirdparty/nftables.git/commit
src: fix crash when inputting an incomplete set add command
authorLiping Zhang <zlpnobody@gmail.com>
Sat, 11 Mar 2017 04:20:11 +0000 (12:20 +0800)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 13 Mar 2017 11:11:44 +0000 (12:11 +0100)
commitc6cd7c22548a545ea9a831a1ea725d1716295b4a
tree07ac30f3364115c3eff3cd90ba195223eeeb3563
parente02bd59c4009bedba89da88b199e715441975439
src: fix crash when inputting an incomplete set add command

After inputting the following nft command, set->keytype is not initialized
but we try to destroy it, so NULL pointer dereference will happen:
  # nft add set t s
  Segmentation fault (core dumped)
  #0  dtype_free (dtype=0x0) at datatype.c:1049
  #1  set_datatype_destroy (dtype=0x0) at datatype.c:1051
  #2  0x0000000000407f1a in set_free (set=0x838790) at rule.c:213
  #3  0x000000000042ff70 in nft_parse (scanner=scanner@entry=0x8386a0,
    state=state@entry=0x7ffc313ea670) at parser_bison.c:9355
  #4  0x000000000040727d in nft_run (scanner=scanner@entry=0x8386a0,
    state=state@entry=0x7ffc313ea670, msgs=msgs@entry=0x7ffc313ea660)
    at main.c:237
  #5  0x0000000000406e4a in main (argc=<optimized out>, argv=<optimized
    out>) at main.c:376

Fixes: b9b6092304ae ("evaluate: store byteorder for set keys")
Signed-off-by: Liping Zhang <zlpnobody@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
src/datatype.c
src/rule.c