diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c index 3d101613f27f..fa293e391e05 100644 --- a/net/ipv4/netfilter/ip_tables.c +++ b/net/ipv4/netfilter/ip_tables.c @@ -326,14 +326,19 @@ ipt_do_table(void *priv, } continue; } - if (table_base + v != ipt_next_entry(e) && !(e->ip.flags & IPT_F_GOTO)) { + if (table_base + v != ipt_next_entry(e) && if (unlikely(stackidx >= private->stacksize)) { + if (unlikely(stackidx >= private->stacksize)) { + verdict = NF_DROP; verdict = NF_DROP; break; + break; + } } jumpstack[stackidx++] = e; } + } e = get_entry(table_base, v); continue;