netfilter: ctnetlink: be more strict when NF_CONNTRACK_MARK is not set
When CONFIG_NF_CONNTRACK_MARK is not set, any CTA_MARK or CTA_MARK_MASK in netlink message are not supported. We should return an error when one of them is set, not both Fixes: 9306425b ("netfilter: ctnetlink: must check mark attributes vs NULL") Signed-off-by:Romain Bellan <romain.bellan@wifirst.fr> Signed-off-by:
Florent Fourcot <florent.fourcot@wifirst.fr> Signed-off-by:
Pablo Neira Ayuso <pablo@netfilter.org>
Showing
Please register or sign in to comment