diff options
| author | Florian Westphal <fw@strlen.de> | 2026-07-10 12:44:41 +0200 |
|---|---|---|
| committer | Florian Westphal <fw@strlen.de> | 2026-07-10 16:28:47 +0200 |
| commit | f468c48d488d0ea2df3422b3e1dfafae1611e853 (patch) | |
| tree | 5d51b56d9084788cae8d18ab846c98bd02fa3fa3 | |
| parent | b3fe4cbd583895987935a9bdad01c8f9d3a02310 (diff) | |
netfilter: xt_physdev: masks are not c-strings
... and must not be subjected to the 'nul terminated' constraint.
If the interface name is 15 characters long, the mask is 16-bytes
'0xff' (to cover for \0) and the valid device name is rejected.
Fixes: 8df772afc9d0 ("netfilter: x_physdev: reject empty or not-nul terminated device names")
Cc: stable@vger.kernel.org
Closes: https://bugs.launchpad.net/neutron/+bug/2159935
Signed-off-by: Florian Westphal <fw@strlen.de>
| -rw-r--r-- | net/netfilter/xt_physdev.c | 5 |
1 files changed, 0 insertions, 5 deletions
diff --git a/net/netfilter/xt_physdev.c b/net/netfilter/xt_physdev.c index dd98f758176c..a388881c68d4 100644 --- a/net/netfilter/xt_physdev.c +++ b/net/netfilter/xt_physdev.c @@ -130,11 +130,6 @@ static int physdev_mt_check(const struct xt_mtchk_param *par) if (X(physoutdev)) return -ENAMETOOLONG; } - - if (X(in_mask)) - return -ENAMETOOLONG; - if (X(out_mask)) - return -ENAMETOOLONG; #undef X if (!brnf_probed) { |
