Still reproducible on noble (24.04), nftables 1.0.9-1ubuntu0.1. Minimal
reproducer, in a scratch network namespace (sudo unshare -n bash):
nft -f - <<'EOF'
table inet demo { flags dormant; chain c { type filter hook output priority 0;
policy accept; } }
EOF
nft -j list table inet demo
Expected "flags": "dormant". Instead the value is freed memory. Here it
printed the table's own name, "flags":"demo", and with other rulesets
the JSON is truncated, as originally reported.
The root cause is a use-after-free in table_flags_json() in src/json.c.
For a single flag it takes a borrowed reference with json_unpack(root,
"[o]", &tmp), then calls json_decref(root), which frees the array
together with the flag string, so tmp dangles.
Fixed upstream in nftables 1.1.0 by "json: fix use after free in
table_flags_json()" (Thomas Haller), which now always emits flags as an
array. For a stable update that keeps the current output shape, the
minimal fix is taking a new reference, json_unpack(root, "[O]", &tmp).
Could this be backported to noble and jammy as an SRU?
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2017656
Title:
JSON output is corrupted if there is an empty table with flags
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/nftables/+bug/2017656/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs