diff options
| author | R. Christian McDonald <rcm@FreeBSD.org> | 2026-09-28 23:01:08 +0000 |
|---|---|---|
| committer | R. Christian McDonald <rcm@FreeBSD.org> | 2026-09-29 00:02:02 +0000 |
| commit | f084f28a52c5fb4557ff0b56e98ca36af3d8eec0 (patch) | |
| tree | 072c044eceed8c17ab1bfd69d0fdc567b9646949 /usr.sbin/jexec/jexec.8 | |
| parent | 334e8745e9db4d5f28be995dea7c260d72404cae (diff) | |
Since DIOCRSETADDRS was converted to netlink, pf_handle_table_set_addrs()
calls pfr_set_addrs() with a NULL size2, as the netlink interface has no
buffer to return the deleted addresses in. pfr_set_addrs() only checked
size2 for NULL at the end of the function; with PFR_FLAG_FEEDBACK set it
dereferenced it unconditionally first. pfctl sets PFR_FLAG_FEEDBACK
when run with -v, so "pfctl -v -t foo -T replace ..." panicked the
kernel with a NULL pointer dereference. To reproduce:
pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -v -t foo -T replace 192.0.2.2
Check size2 for NULL before dereferencing it, as is already done at the
end of the function. The per-address feedback for added and changed
addresses is still copied back as before; only the list of deleted
addresses, which the netlink caller has no room for, is skipped.
While here, compare size2 against NULL explicitly in the second check as
well, per style(9).
Add a regression test.
Approved by: kp (mentor)
Fixes: 08ed87a4a276 ("pf: convert DIOCRSETADDRS to netlink")
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D60096
Diffstat (limited to 'usr.sbin/jexec/jexec.8')
0 files changed, 0 insertions, 0 deletions
