Still reproducible on noble (24.04), nftables 1.0.9-1ubuntu0.1. Minimal
reproducer, in a scratch network namespace (sudo unshare -n bash):

 nft -f - <<'EOF'
 table inet demo { flags dormant; chain c { type filter hook output priority 0; 
policy accept; } }
 EOF
 nft -j list table inet demo

 Expected "flags": "dormant". Instead the value is freed memory. Here it
printed the table's own name, "flags":"demo", and with other rulesets
the JSON is truncated, as originally reported.

 The root cause is a use-after-free in table_flags_json() in src/json.c.
For a single flag it takes a borrowed reference with json_unpack(root,
"[o]", &tmp), then calls json_decref(root), which frees the array
together with the flag string, so tmp dangles.

 Fixed upstream in nftables 1.1.0 by "json: fix use after free in
table_flags_json()" (Thomas Haller), which now always emits flags as an
array. For a stable update that keeps the current output shape, the
minimal fix is taking a new reference, json_unpack(root, "[O]", &tmp).
Could this be backported to noble and jammy as an SRU?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2017656

Title:
  JSON output is corrupted if there is an empty table with flags

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/nftables/+bug/2017656/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to