aboutsummaryrefslogtreecommitdiff
path: root/sys/dev/ice/ice_adminq_cmd.h
diff options
context:
space:
mode:
authorR. Christian McDonald <rcm@FreeBSD.org>2026-09-28 23:01:08 +0000
committerR. Christian McDonald <rcm@FreeBSD.org>2026-09-29 00:02:02 +0000
commitf084f28a52c5fb4557ff0b56e98ca36af3d8eec0 (patch)
tree072c044eceed8c17ab1bfd69d0fdc567b9646949 /sys/dev/ice/ice_adminq_cmd.h
parent334e8745e9db4d5f28be995dea7c260d72404cae (diff)
pf: fix NULL dereference in pfr_set_addrs() with feedbackHEADmain
Since DIOCRSETADDRS was converted to netlink, pf_handle_table_set_addrs() calls pfr_set_addrs() with a NULL size2, as the netlink interface has no buffer to return the deleted addresses in. pfr_set_addrs() only checked size2 for NULL at the end of the function; with PFR_FLAG_FEEDBACK set it dereferenced it unconditionally first. pfctl sets PFR_FLAG_FEEDBACK when run with -v, so "pfctl -v -t foo -T replace ..." panicked the kernel with a NULL pointer dereference. To reproduce: pfctl -e pfctl -t foo -T add 192.0.2.1 pfctl -v -t foo -T replace 192.0.2.2 Check size2 for NULL before dereferencing it, as is already done at the end of the function. The per-address feedback for added and changed addresses is still copied back as before; only the list of deleted addresses, which the netlink caller has no room for, is skipped. While here, compare size2 against NULL explicitly in the second check as well, per style(9). Add a regression test. Approved by: kp (mentor) Fixes: 08ed87a4a276 ("pf: convert DIOCRSETADDRS to netlink") MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D60096
Diffstat (limited to 'sys/dev/ice/ice_adminq_cmd.h')
0 files changed, 0 insertions, 0 deletions