netfilter: nft_immediate: drop chain reference counter on error
[ Upstream commit b29be0ca8e816119ccdf95cc7d7c7be9bde005f1 ]
In the init path, nft_data_init() bumps the chain reference counter,
decrement it on error by following the error path which calls
nft_data_release() to restore it.
Fixes: 4bedf9eee016 ("netfilter: nf_tables: fix chain binding transaction logic")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
cf3c516dec
commit
06ce3b8ec4
@@ -78,7 +78,7 @@ static int nft_immediate_init(const struct nft_ctx *ctx,
|
|||||||
case NFT_GOTO:
|
case NFT_GOTO:
|
||||||
err = nf_tables_bind_chain(ctx, chain);
|
err = nf_tables_bind_chain(ctx, chain);
|
||||||
if (err < 0)
|
if (err < 0)
|
||||||
return err;
|
goto err1;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
break;
|
break;
|
||||||
|
|||||||
Reference in New Issue
Block a user