Commit dc264f1f authored by wenxu's avatar wenxu Committed by Pablo Neira Ayuso

netfilter: flowtable: fix NULL pointer dereference in tunnel offload support

The tc ct action does not cache the route in the flowtable entry.

Fixes: 88bf6e41 ("netfilter: flowtable: add tunnel encap/decap action offload support")
Fixes: cfab6dbd ("netfilter: flowtable: add tunnel match offload support")
Signed-off-by: default avatarwenxu <wenxu@ucloud.cn>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent 475beb9c
...@@ -92,7 +92,7 @@ static int nf_flow_rule_match(struct nf_flow_match *match, ...@@ -92,7 +92,7 @@ static int nf_flow_rule_match(struct nf_flow_match *match,
NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_TCP, tcp); NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_TCP, tcp);
NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_PORTS, tp); NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_PORTS, tp);
if (other_dst->lwtstate) { if (other_dst && other_dst->lwtstate) {
tun_info = lwt_tun_info(other_dst->lwtstate); tun_info = lwt_tun_info(other_dst->lwtstate);
nf_flow_rule_lwt_match(match, tun_info); nf_flow_rule_lwt_match(match, tun_info);
} }
...@@ -483,7 +483,7 @@ static void flow_offload_encap_tunnel(const struct flow_offload *flow, ...@@ -483,7 +483,7 @@ static void flow_offload_encap_tunnel(const struct flow_offload *flow,
struct dst_entry *dst; struct dst_entry *dst;
dst = flow->tuplehash[dir].tuple.dst_cache; dst = flow->tuplehash[dir].tuple.dst_cache;
if (dst->lwtstate) { if (dst && dst->lwtstate) {
struct ip_tunnel_info *tun_info; struct ip_tunnel_info *tun_info;
tun_info = lwt_tun_info(dst->lwtstate); tun_info = lwt_tun_info(dst->lwtstate);
...@@ -503,7 +503,7 @@ static void flow_offload_decap_tunnel(const struct flow_offload *flow, ...@@ -503,7 +503,7 @@ static void flow_offload_decap_tunnel(const struct flow_offload *flow,
struct dst_entry *dst; struct dst_entry *dst;
dst = flow->tuplehash[!dir].tuple.dst_cache; dst = flow->tuplehash[!dir].tuple.dst_cache;
if (dst->lwtstate) { if (dst && dst->lwtstate) {
struct ip_tunnel_info *tun_info; struct ip_tunnel_info *tun_info;
tun_info = lwt_tun_info(dst->lwtstate); tun_info = lwt_tun_info(dst->lwtstate);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment