netfilter: ctnetlink: missing validation of CTA_EXPECT_ZONE attribute
authorPablo Neira Ayuso <pablo@netfilter.org>
Wed, 22 Sep 2010 06:35:36 +0000 (08:35 +0200)
committerPatrick McHardy <kaber@trash.net>
Wed, 22 Sep 2010 06:35:36 +0000 (08:35 +0200)
This patch adds the missing validation of the CTA_EXPECT_ZONE
attribute in the ctnetlink code.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Patrick McHardy <kaber@trash.net>
net/netfilter/nf_conntrack_netlink.c

index 5bae1cd15eea93ee3f74cb51dab972c10c96d33c..37533a30413b0c9c14054fab300bdd75a57b0620 100644 (file)
@@ -1733,6 +1733,7 @@ static const struct nla_policy exp_nla_policy[CTA_EXPECT_MAX+1] = {
        [CTA_EXPECT_TIMEOUT]    = { .type = NLA_U32 },
        [CTA_EXPECT_ID]         = { .type = NLA_U32 },
        [CTA_EXPECT_HELP_NAME]  = { .type = NLA_NUL_STRING },
+       [CTA_EXPECT_ZONE]       = { .type = NLA_U16 },
 };
 
 static int