summaryrefslogtreecommitdiff
path: root/net/netfilter/xt_nat.c
diff options
context:
space:
mode:
authorPablo Neira Ayuso <pablo@netfilter.org>2018-10-09 20:06:36 +0200
committerPablo Neira Ayuso <pablo@netfilter.org>2018-10-11 11:29:53 +0200
commitd701d8117200399d85e63a737d2e4e897932f3b6 (patch)
tree7a3d7c8160dda988d6c0f2b52f9cd6ca576dd15b /net/netfilter/xt_nat.c
parent18c0ab87364ac5128a152055fdcb1d27e01caf01 (diff)
netfilter: nft_compat: do not dump private area
Zero pad private area, otherwise we expose private kernel pointer to userspace. This patch also zeroes the tail area after the ->matchsize and ->targetsize that results from XT_ALIGN(). Fixes: 0ca743a55991 ("netfilter: nf_tables: add compatibility layer for x_tables") Reported-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/netfilter/xt_nat.c')
0 files changed, 0 insertions, 0 deletions