CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]  2026/10/02 03:40:22

Modified files:
        sys/net        : pf.c pf_table.c 

Log message:
pf(4): pfr_insert_kentry() always needs PF_LOCK()

pfr_insert_kentry() inserts an IP address into a table. The table's
consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK()
protection is missing for the code path executed on behalf
of the overload action in a pf rule. The overload action instructs
the firewall to insert the packet's source address into the table specified
as the overload action parameter. That particular code path in
pf_test() function runs without any lock protection.

The bug was introduced in revision 1.1074 and remained unnoticed
until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>)

OK henning@, OK dlg@, OK jmatthew@

Reply via email to