CVSROOT: /cvs
Module name: src
Changes by: [email protected] 2026/10/02 03:40:22
Modified files:
sys/net : pf.c pf_table.c
Log message:
pf(4): pfr_insert_kentry() always needs PF_LOCK()
pfr_insert_kentry() inserts an IP address into a table. The table's
consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK()
protection is missing for the code path executed on behalf
of the overload action in a pf rule. The overload action instructs
the firewall to insert the packet's source address into the table specified
as the overload action parameter. That particular code path in
pf_test() function runs without any lock protection.
The bug was introduced in revision 1.1074 and remained unnoticed
until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>)
OK henning@, OK dlg@, OK jmatthew@