netfilter: nf_tables: fix oob access
authorFlorian Westphal <fw@strlen.de>
Tue, 13 Dec 2016 12:59:33 +0000 (13:59 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 14 Dec 2016 22:39:06 +0000 (23:39 +0100)
commit3e38df136e453aa69eb4472108ebce2fb00b1ba6
tree84b1474ffeb5ec38448abeb61cc5cf380e1ab892
parentc2e756ff9e699865d294cdc112acfc36419cf5cc
netfilter: nf_tables: fix oob access

BUG: KASAN: slab-out-of-bounds in nf_tables_rule_destroy+0xf1/0x130 at addr ffff88006a4c35c8
Read of size 8 by task nft/1607

When we've destroyed last valid expr, nft_expr_next() returns an invalid expr.
We must not dereference it unless it passes != nft_expr_last() check.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c