Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 55df35d2 authored by Patrick McHardy's avatar Patrick McHardy Committed by Pablo Neira Ayuso
Browse files

netfilter: nf_tables: reject NFT_SET_ELEM_INTERVAL_END flag for non-interval sets

parent 16c45eda
Loading
Loading
Loading
Loading
+3 −0
Original line number Diff line number Diff line
@@ -3138,6 +3138,9 @@ static int nft_add_set_elem(struct nft_ctx *ctx, struct nft_set *set,
		elem.flags = ntohl(nla_get_be32(nla[NFTA_SET_ELEM_FLAGS]));
		if (elem.flags & ~NFT_SET_ELEM_INTERVAL_END)
			return -EINVAL;
		if (!(set->flags & NFT_SET_INTERVAL) &&
		    elem.flags & NFT_SET_ELEM_INTERVAL_END)
			return -EINVAL;
	}

	if (set->flags & NFT_SET_MAP) {