netfilter: nf_tables: check if catch-all set element is active in next generation
When deactivating the catch-all set element, check the state in the next generation that represents this transaction. This bug uncovered after the recent removal of the element busy mark a2dd0233 ("netfilter: nf_tables: remove busy mark and gc batch API"). Fixes: aaa31047 ("netfilter: nftables: add catch-all set element support") Cc: stable@vger.kernel.org Reported-by:lonial con <kongln9170@gmail.com> Signed-off-by:
Pablo Neira Ayuso <pablo@netfilter.org>
Loading
Please register or sign in to comment