netfilter: nf_tables: validate catch-all set elements
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 17 Apr 2023 10:14:29 +0000 (12:14 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 18 Apr 2023 07:12:22 +0000 (09:12 +0200)
commitd46fc894147cf98dd6e8210aa99ed46854191840
tree2fbd07e6a402920e533d3fb11667ae7d7b0aa333
parentc55c0e91c813589dc55bea6bf9a9fbfaa10ae41d
netfilter: nf_tables: validate catch-all set elements

catch-all set element might jump/goto to chain that uses expressions
that require validation.

Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/net/netfilter/nf_tables.h
net/netfilter/nf_tables_api.c
net/netfilter/nft_lookup.c