mirror of
https://github.com/edk2-porting/linux-next.git
synced 2025-01-12 15:44:01 +08:00
netfilter: nf_tables: skip netlink portID validation if zero
nft_table_lookup() allows us to obtain the table object by the name and
the family. The netlink portID validation needs to be skipped for the
dump path, since the ownership only applies to commands to update the
given table. Skip validation if the specified netlink PortID is zero
when calling nft_table_lookup().
Fixes: 6001a930ce
("netfilter: nftables: introduce table ownership")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
ea45fdf82c
commit
534799097a
@ -571,7 +571,7 @@ static struct nft_table *nft_table_lookup(const struct net *net,
|
||||
table->family == family &&
|
||||
nft_active_genmask(table, genmask)) {
|
||||
if (nft_table_has_owner(table) &&
|
||||
table->nlpid != nlpid)
|
||||
nlpid && table->nlpid != nlpid)
|
||||
return ERR_PTR(-EPERM);
|
||||
|
||||
return table;
|
||||
|
Loading…
Reference in New Issue
Block a user