mirror of
https://github.com/torvalds/linux.git
synced 2026-06-07 14:04:54 +02:00
netfilter: nf_tables: initialize registers in nft_do_chain()
commit4c905f6740upstream. Initialize registers to avoid stack leak into userspace. Fixes:96518518cc("netfilter: add nftables") Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
eb1ba8d1c3
commit
2c74374c2e
|
|
@ -162,7 +162,7 @@ nft_do_chain(struct nft_pktinfo *pkt, void *priv)
|
||||||
struct nft_rule *const *rules;
|
struct nft_rule *const *rules;
|
||||||
const struct nft_rule *rule;
|
const struct nft_rule *rule;
|
||||||
const struct nft_expr *expr, *last;
|
const struct nft_expr *expr, *last;
|
||||||
struct nft_regs regs;
|
struct nft_regs regs = {};
|
||||||
unsigned int stackptr = 0;
|
unsigned int stackptr = 0;
|
||||||
struct nft_jumpstack jumpstack[NFT_JUMP_STACK_SIZE];
|
struct nft_jumpstack jumpstack[NFT_JUMP_STACK_SIZE];
|
||||||
bool genbit = READ_ONCE(net->nft.gencursor);
|
bool genbit = READ_ONCE(net->nft.gencursor);
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user