netfilter: ctnetlink: missing validation of CTA_EXPECT_ZONE attribute
authorPablo Neira Ayuso <pablo@netfilter.org>
Wed, 22 Sep 2010 06:35:36 +0000 (08:35 +0200)
committerPatrick McHardy <kaber@trash.net>
Wed, 22 Sep 2010 06:35:36 +0000 (08:35 +0200)
This patch adds the missing validation of the CTA_EXPECT_ZONE
attribute in the ctnetlink code.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Patrick McHardy <kaber@trash.net>
net/netfilter/nf_conntrack_netlink.c

index 5bae1cd..37533a3 100644 (file)
@@ -1733,6 +1733,7 @@ static const struct nla_policy exp_nla_policy[CTA_EXPECT_MAX+1] = {
        [CTA_EXPECT_TIMEOUT]    = { .type = NLA_U32 },
        [CTA_EXPECT_ID]         = { .type = NLA_U32 },
        [CTA_EXPECT_HELP_NAME]  = { .type = NLA_NUL_STRING },
+       [CTA_EXPECT_ZONE]       = { .type = NLA_U16 },
 };
 
 static int