netfilter: nft_lookup: add missing attribute validation for NFTA_LOOKUP_SET_ID
authorPatrick McHardy <kaber@trash.net>
Fri, 30 Jan 2015 07:46:33 +0000 (07:46 +0000)
committerPablo Neira Ayuso <pablo@netfilter.org>
Fri, 30 Jan 2015 18:08:20 +0000 (19:08 +0100)
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_lookup.c

index 6404a726d17b78fc6db6f411216195e68db63950..9615b8b9fb37dcf769207537f0545dd2a08c62d6 100644 (file)
@@ -39,6 +39,7 @@ static void nft_lookup_eval(const struct nft_expr *expr,
 
 static const struct nla_policy nft_lookup_policy[NFTA_LOOKUP_MAX + 1] = {
        [NFTA_LOOKUP_SET]       = { .type = NLA_STRING },
+       [NFTA_LOOKUP_SET_ID]    = { .type = NLA_U32 },
        [NFTA_LOOKUP_SREG]      = { .type = NLA_U32 },
        [NFTA_LOOKUP_DREG]      = { .type = NLA_U32 },
 };