]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
authorFlorian Westphal <fw@strlen.de>
Mon, 13 Apr 2026 04:32:47 +0000 (04:32 +0000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 18 Apr 2026 08:35:57 +0000 (10:35 +0200)
commit 07ace0bbe03b3d8e85869af1dec5e4087b1d57b8 upstream

pipapo relies on kmalloc(0) returning ZERO_SIZE_PTR (i.e., not NULL
but pointer is invalid).

Rework this to not call slab allocator when we'd request a 0-byte
allocation.

Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Mukul Sikka <mukul.sikka@broadcom.com>
Signed-off-by: Brennan Lamoreaux <brennan.lamoreaux@broadcom.com>
[Keerthana: In older stable branches (v6.6 and earlier), the allocation logic in
pipapo_clone() still relies on `src->rules` rather than `src->rules_alloc`
(introduced in v6.9 via 9f439bd6ef4f). Consequently, the previously
backported INT_MAX clamping check uses `src->rules`. This patch correctly
moves that `src->rules > (INT_MAX / ...)` check inside the new
`if (src->rules > 0)` block]
Signed-off-by: Keerthana K <keerthana.kalyanasundaram@broadcom.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/netfilter/nft_set_pipapo.c

index 673d73dce3883a9ef61c2d02c30896d5fcfec095..cfd0d020f3382bdc29baad2c962f54bb729d363b 100644 (file)
@@ -525,6 +525,8 @@ static struct nft_pipapo_elem *pipapo_get(const struct net *net,
        int i;
 
        m = priv->clone;
+       if (m->bsize_max == 0)
+               return ret;
 
        res_map = kmalloc_array(m->bsize_max, sizeof(*res_map), GFP_ATOMIC);
        if (!res_map) {
@@ -1395,14 +1397,20 @@ static struct nft_pipapo_match *pipapo_clone(struct nft_pipapo_match *old)
                       src->bsize * sizeof(*dst->lt) *
                       src->groups * NFT_PIPAPO_BUCKETS(src->bb));
 
-               if (src->rules > (INT_MAX / sizeof(*src->mt)))
-                       goto out_mt;
+               if (src->rules > 0) {
+                       if (src->rules > (INT_MAX / sizeof(*src->mt)))
+                               goto out_mt;
+
+                       dst->mt = kvmalloc_array(src->rules, sizeof(*src->mt),
+                                                GFP_KERNEL);
+                       if (!dst->mt)
+                               goto out_mt;
 
-               dst->mt = kvmalloc(src->rules * sizeof(*src->mt), GFP_KERNEL_ACCOUNT);
-               if (!dst->mt)
-                       goto out_mt;
+                       memcpy(dst->mt, src->mt, src->rules * sizeof(*src->mt));
+               } else {
+                       dst->mt = NULL;
+               }
 
-               memcpy(dst->mt, src->mt, src->rules * sizeof(*src->mt));
                src++;
                dst++;
        }