netfilter: nfnetlink_acct: validate NFACCT_QUOTA parameter
authorPhil Turnbull <phil.turnbull@oracle.com>
Tue, 3 May 2016 20:39:19 +0000 (16:39 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 11 Aug 2019 10:20:43 +0000 (12:20 +0200)
commit68e3b4e85ababf838bca52076c3b5cd78f5d0f1f
tree38ee306c1271d76e07a8373633239e2cb700a8ed
parentebb9ffd10a3849d8d87ad311921462dea3a582ec
netfilter: nfnetlink_acct: validate NFACCT_QUOTA parameter

[ Upstream commit eda3fc50daa93b08774a18d51883c5a5d8d85e15 ]

If a quota bit is set in NFACCT_FLAGS but the NFACCT_QUOTA parameter is
missing then a NULL pointer dereference is triggered. CAP_NET_ADMIN is
required to trigger the bug.

Signed-off-by: Phil Turnbull <phil.turnbull@oracle.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/netfilter/nfnetlink_acct.c