CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]  2026/09/21 07:58:20

Modified files:
        sys/net        : pf_table.c 

Log message:
pf: do not free the caller's ruleset when attaching a table fails

pfr_attach_table() takes a struct pf_ruleset * from its caller and, on its
own error paths, calls pfr_destroy_ktable() on the table it just made.  That
drops the table's reference on the ruleset and calls
pf_remove_if_empty_ruleset(), which may unlink and free the anchor the
ruleset is embedded in -- and then pfr_attach_table() returns NULL to a
caller still holding the pointer.

Reached from userland with DIOCADDRULE and a PF_ADDR_DYNIFTL source, after
DIOCSETLIMIT has lowered PF_LIMIT_TABLES to one item of headroom: the first
pfr_create_ktable() takes it and the root table's fails.

Hold a table reference on the ruleset for the duration instead, so the
ruleset outlives every failure path inside pfr_attach_table() and stays the
caller's to remove.

OK sashan@

Reported-by: [email protected]

Reply via email to