diff options
author | Pablo Neira Ayuso <pablo@netfilter.org> | 2024-03-10 10:02:41 +0100 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2024-03-21 00:21:54 +0100 |
commit | b0e256f3dd2ba6532f37c5c22e07cb07a36031ee (patch) | |
tree | 5f72b4aa9048eb367d9d61f58c5b3018330b6d82 /net/netfilter/nf_tables_api.c | |
parent | Merge branch 'octeontx2-pf-mbox-fixes' (diff) | |
download | wireguard-linux-b0e256f3dd2ba6532f37c5c22e07cb07a36031ee.tar.xz wireguard-linux-b0e256f3dd2ba6532f37c5c22e07cb07a36031ee.zip |
netfilter: nft_set_pipapo: release elements in clone only from destroy path
Clone already always provides a current view of the lookup table, use it
to destroy the set, otherwise it is possible to destroy elements twice.
This fix requires:
212ed75dc5fb ("netfilter: nf_tables: integrate pipapo into commit protocol")
which came after:
9827a0e6e23b ("netfilter: nft_set_pipapo: release elements in clone from abort path").
Fixes: 9827a0e6e23b ("netfilter: nft_set_pipapo: release elements in clone from abort path")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to '')
0 files changed, 0 insertions, 0 deletions