• John W. Linville's avatar
    netfilter: nf_tables: fix type mismatch with error return from nft_parse_u32_check · f1d505bb
    John W. Linville authored
    Commit 36b701fa ("netfilter: nf_tables: validate maximum value of
    u32 netlink attributes") introduced nft_parse_u32_check with a return
    value of "unsigned int", yet on error it returns "-ERANGE".
    
    This patch corrects the mismatch by changing the return value to "int",
    which happens to match the actual users of nft_parse_u32_check already.
    
    Found by Coverity, CID 1373930.
    
    Note that commit 21a9e0f1 ("netfilter: nft_exthdr: fix error
    handling in nft_exthdr_init()) attempted to address the issue, but
    did not address the return type of nft_parse_u32_check.
    Signed-off-by: default avatarJohn W. Linville <linville@tuxdriver.com>
    Cc: Laura Garcia Liebana <nevola@gmail.com>
    Cc: Pablo Neira Ayuso <pablo@netfilter.org>
    Cc: Dan Carpenter <dan.carpenter@oracle.com>
    Fixes: 36b701fa ("netfilter: nf_tables: validate maximum value...")
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    f1d505bb
nf_tables.h 29.6 KB