diff options
| author | Pablo Neira Ayuso <pablo@netfilter.org> | 2026-07-16 10:13:37 +0200 |
|---|---|---|
| committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2026-07-23 17:59:30 +0200 |
| commit | f4f699790590bd0896c48a71e9232a65198f92f0 (patch) | |
| tree | c652c8c73988804181e038d45e8e4a72aec07b8d /include/linux/timerqueue.h | |
| parent | 712d2993bea555f1f09cd53cbdb25714f28e85db (diff) | |
netfilter: nf_tables: make nft_object rhltable per table
The nft_object rhltable is global, this allows for accessing objects
that are being dismangled from lookup path by other existing netns.
Given the nft_obj_destroy() releases the object inmediately, this might
lead to use-after-free of these objects that are being released.
Make the existing rhltable per table to address this issue to deal with
with the nft_rcv_nl_event() path too.
Update nft_obj_lookup() to take the table as non-const, otherwise,
compiler complains when passing the objname_ht to rhltable_lookup().
Fixes: 4d44175aa5bb ("netfilter: nf_tables: handle nft_object lookups via rhltable")
Suggested-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'include/linux/timerqueue.h')
0 files changed, 0 insertions, 0 deletions
