netfilter: nft_connlimit: memleak if nf_ct_netns_get() fails
authorPablo Neira Ayuso <pablo@netfilter.org>
Thu, 13 Jan 2022 11:22:38 +0000 (12:22 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 13 Jan 2022 11:26:04 +0000 (12:26 +0100)
commit7d70984a1ad4c445dff08edb9aacce8906b6a222
tree3414111276231cf315c111451816a7e7fceaaae6
parentfe75e84a8fe17449ea16b73cfcfc9e7d06a49130
netfilter: nft_connlimit: memleak if nf_ct_netns_get() fails

Check if nf_ct_netns_get() fails then release the limit object
previously allocated via kmalloc().

Fixes: 37f319f37d90 ("netfilter: nft_connlimit: move stateful fields out of expression data")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_connlimit.c