Pablo Neira Ayuso 2f07a81c5d netfilter: nf_tables: disallow jump to implicit chain from set element
commit f323ef3a0d49e147365284bc1f02212e617b7f09 upstream.

Extend struct nft_data_desc to add a flag field that specifies
nft_data_init() is being called for set element data.

Use it to disallow jump to implicit chain from set element, only jump
to chain via immediate expression is allowed.

Fixes: d0e2c7de92c7 ("netfilter: nf_tables: add NFT_CHAIN_BINDING")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-17 15:13:59 +02:00
..
2022-02-25 09:36:06 +01:00
2022-07-27 10:18:21 -07:00
2022-05-25 12:22:58 -07:00
2022-04-07 21:06:41 -07:00
2022-05-24 12:40:28 -03:00
2022-07-02 11:20:56 -07:00
2022-05-28 11:39:01 -07:00
2022-05-10 11:59:22 +02:00
2022-03-03 09:55:28 +00:00