summaryrefslogtreecommitdiffstats
path: root/arch/arc
diff options
context:
space:
mode:
authorFlorian Westphal <fw@strlen.de>2018-11-04 12:07:14 +0100
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2019-12-13 08:51:11 +0100
commit2d484087a00c267c25ad33b2e09ac6cfe48457e8 (patch)
treeb575bbe03ed10b9513daa5a334b02fe3afef20dd /arch/arc
parent6ce317fdc212aa0cae3c0b375d6273161caad2e5 (diff)
downloadlinux-stable-2d484087a00c267c25ad33b2e09ac6cfe48457e8.tar.gz
linux-stable-2d484087a00c267c25ad33b2e09ac6cfe48457e8.tar.bz2
linux-stable-2d484087a00c267c25ad33b2e09ac6cfe48457e8.zip
netfilter: nf_tables: don't use position attribute on rule replacement
[ Upstream commit 447750f281abef547be44fdcfe3bc4447b3115a8 ] Its possible to set both HANDLE and POSITION when replacing a rule. In this case, the rule at POSITION gets replaced using the userspace-provided handle. Rule handles are supposed to be generated by the kernel only. Duplicate handles should be harmless, however better disable this "feature" by only checking for the POSITION attribute on insert operations. Fixes: 5e94846686d0 ("netfilter: nf_tables: add insert operation") Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'arch/arc')
0 files changed, 0 insertions, 0 deletions