]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
netfilter: nft_nat: allow to specify layer 4 protocol NAT only
authorPablo Neira Ayuso <pablo@netfilter.org>
Tue, 20 Jul 2021 16:22:50 +0000 (18:22 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 4 Aug 2021 10:23:46 +0000 (12:23 +0200)
[ Upstream commit a33f387ecd5aafae514095c2c4a8c24f7aea7e8b ]

nft_nat reports a bogus EAFNOSUPPORT if no layer 3 information is specified.

Fixes: d07db9884a5f ("netfilter: nf_tables: introduce nft_validate_register_load()")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/netfilter/nft_nat.c

index 3e82a7d0df2a4491eca25f8a2bcec1e6e3c90701..2c3d7ff6f58a73dd897efebd0cbf60362384a131 100644 (file)
@@ -153,7 +153,9 @@ static int nft_nat_init(const struct nft_ctx *ctx, const struct nft_expr *expr,
                alen = FIELD_SIZEOF(struct nf_nat_range, min_addr.ip6);
                break;
        default:
-               return -EAFNOSUPPORT;
+               if (tb[NFTA_NAT_REG_ADDR_MIN])
+                       return -EAFNOSUPPORT;
+               break;
        }
        priv->family = family;