Commit 351c22a
committed
netfilter: nf_tables: Reject tables of unsupported family
jira VULN-8894
cve CVE-2023-6040
commit-author Phil Sutter <[email protected]>
commit f1082dd
An nftables family is merely a hollow container, its family just a
number and such not reliant on compile-time options other than nftables
support itself. Add an artificial check so attempts at using a family
the kernel can't support fail as early as possible. This helps user
space detect kernels which lack e.g. NFPROTO_INET.
Signed-off-by: Phil Sutter <[email protected]>
Signed-off-by: Pablo Neira Ayuso <[email protected]>
(cherry picked from commit f1082dd)
Signed-off-by: Brett Mastbergen <[email protected]>1 parent 99ce2db commit 351c22a
1 file changed
+27
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1076 | 1076 | | |
1077 | 1077 | | |
1078 | 1078 | | |
| 1079 | + | |
| 1080 | + | |
| 1081 | + | |
| 1082 | + | |
| 1083 | + | |
| 1084 | + | |
| 1085 | + | |
| 1086 | + | |
| 1087 | + | |
| 1088 | + | |
| 1089 | + | |
| 1090 | + | |
| 1091 | + | |
| 1092 | + | |
| 1093 | + | |
| 1094 | + | |
| 1095 | + | |
| 1096 | + | |
| 1097 | + | |
| 1098 | + | |
| 1099 | + | |
| 1100 | + | |
| 1101 | + | |
| 1102 | + | |
1079 | 1103 | | |
1080 | 1104 | | |
1081 | 1105 | | |
| |||
1090 | 1114 | | |
1091 | 1115 | | |
1092 | 1116 | | |
| 1117 | + | |
| 1118 | + | |
| 1119 | + | |
1093 | 1120 | | |
1094 | 1121 | | |
1095 | 1122 | | |
| |||
0 commit comments