Re: [PATCH] netfilter/nf_tables: fix UAF in catchall element removal

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, 28 Dec 2023 at 06:38, Wander Lairson Costa <wander@xxxxxxxxxx> wrote:
>
> If the catchall element is gc'd when the pipapo set is removed, the element
> can be deactivated twice.
>
> When a set is deleted, the nft_map_deactivate() is called to deactivate the
> data of the set elements [1].

Please send this to the netdev list and netfilter-devel, it's already
on a public list thanks to the stable cc.

Pablo & al - see

    https://lore.kernel.org/all/20231228143737.17712-1-wander@xxxxxxxxxx/

for the original full email.

            Linus




[Index of Archives]     [Linux Kernel]     [Kernel Development Newbies]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite Hiking]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux