netfilter: nf_tables: revert do not remove elements if set backend implements .abort
commit f86fb94011aeb3b26337fc22204ca726aeb8bc24 upstream.
nf_tables_abort_release() path calls nft_set_elem_destroy() for
NFT_MSG_NEWSETELEM which releases the element, however, a reference to
the element still remains in the working copy.
Fixes: ebd032fa8818 ("netfilter: nf_tables: do not remove elements if set backend implements .abort")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
c2eaa8319f
commit
e1512ff1ec
1 changed files with 1 additions and 4 deletions
|
|
@ -9931,10 +9931,7 @@ static int __nf_tables_abort(struct net *net, enum nfnl_abort_action action)
|
|||
break;
|
||||
}
|
||||
te = (struct nft_trans_elem *)trans->data;
|
||||
if (!te->set->ops->abort ||
|
||||
nft_setelem_is_catchall(te->set, &te->elem))
|
||||
nft_setelem_remove(net, te->set, &te->elem);
|
||||
|
||||
nft_setelem_remove(net, te->set, &te->elem);
|
||||
if (!nft_setelem_is_catchall(te->set, &te->elem))
|
||||
atomic_dec(&te->set->nelems);
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue