netfilter: nft_tproxy: restrict to prerouting hook
commit 18bbc321 upstream. TPROXY is only allowed from prerouting, but nft_tproxy doesn't check this. This fixes a crash (null dereference) when using tproxy from e.g. output. Fixes: 4ed8eb65 ("netfilter: nf_tables: Add native tproxy support") Reported-by:Shell Chen <xierch@gmail.com> Signed-off-by:
Florian Westphal <fw@strlen.de> Signed-off-by:
Qingfang DENG <dqfext@gmail.com> Signed-off-by:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Loading
Please register or sign in to comment