netfilter: nft_immediate: drop chain reference counter on error
[ Upstream commitpull/1175/headb29be0ca8e] In the init path, nft_data_init() bumps the chain reference counter, decrement it on error by following the error path which calls nft_data_release() to restore it. Fixes:4bedf9eee0("netfilter: nf_tables: fix chain binding transaction logic") Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
parent
bb1bf97fa1
commit
81f8a995eb
|
|
@ -78,7 +78,7 @@ static int nft_immediate_init(const struct nft_ctx *ctx,
|
|||
case NFT_GOTO:
|
||||
err = nf_tables_bind_chain(ctx, chain);
|
||||
if (err < 0)
|
||||
return err;
|
||||
goto err1;
|
||||
break;
|
||||
default:
|
||||
break;
|
||||
|
|
|
|||
Loading…
Reference in New Issue