aboutsummaryrefslogtreecommitdiffstatshomepage
path: root/net/netfilter/nft_fwd_netdev.c
diff options
context:
space:
mode:
authorFlorian Westphal <fw@strlen.de>2023-06-21 21:11:03 +0200
committerPablo Neira Ayuso <pablo@netfilter.org>2023-06-26 08:05:57 +0200
commita412dbf40ff37515acca4bba666f5386aa37246e (patch)
treed29ebda49810ab08757b1d5c33f2ea6001d04df1 /net/netfilter/nft_fwd_netdev.c
parentnetfilter: nf_tables: Introduce NFT_MSG_GETSETELEM_RESET (diff)
downloadwireguard-linux-a412dbf40ff37515acca4bba666f5386aa37246e.tar.xz
wireguard-linux-a412dbf40ff37515acca4bba666f5386aa37246e.zip
netfilter: nf_tables: limit allowed range via nla_policy
These NLA_U32 types get stored in u8 fields, reject invalid values instead of silently casting to u8. Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/netfilter/nft_fwd_netdev.c')
-rw-r--r--net/netfilter/nft_fwd_netdev.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/net/netfilter/nft_fwd_netdev.c b/net/netfilter/nft_fwd_netdev.c
index 7b9d4d1bd17c..a5268e6dd32f 100644
--- a/net/netfilter/nft_fwd_netdev.c
+++ b/net/netfilter/nft_fwd_netdev.c
@@ -40,7 +40,7 @@ static void nft_fwd_netdev_eval(const struct nft_expr *expr,
static const struct nla_policy nft_fwd_netdev_policy[NFTA_FWD_MAX + 1] = {
[NFTA_FWD_SREG_DEV] = { .type = NLA_U32 },
[NFTA_FWD_SREG_ADDR] = { .type = NLA_U32 },
- [NFTA_FWD_NFPROTO] = { .type = NLA_U32 },
+ [NFTA_FWD_NFPROTO] = NLA_POLICY_MAX(NLA_BE32, 255),
};
static int nft_fwd_netdev_init(const struct nft_ctx *ctx,