Skip to content
Commit 31cc578a authored by Saeed Mirzamohammadi's avatar Saeed Mirzamohammadi Committed by Pablo Neira Ayuso
Browse files

netfilter: nftables_offload: KASAN slab-out-of-bounds Read in nft_flow_rule_create



This patch fixes the issue due to:

BUG: KASAN: slab-out-of-bounds in nft_flow_rule_create+0x622/0x6a2
net/netfilter/nf_tables_offload.c:40
Read of size 8 at addr ffff888103910b58 by task syz-executor227/16244

The error happens when expr->ops is accessed early on before performing the boundary check and after nft_expr_next() moves the expr to go out-of-bounds.

This patch checks the boundary condition before expr->ops that fixes the slab-out-of-bounds Read issue.

Add nft_expr_more() and use it to fix this problem.

Signed-off-by: default avatarSaeed Mirzamohammadi <saeed.mirzamohammadi@oracle.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent 64747d5e
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment