netfilter: nf_tables: reject unbound anonymous set before commit phase

[ Upstream commit 938154b93b ]

Add a new list to track set transaction and to check for unbound
anonymous sets before entering the commit phase.

Bail out at the end of the transaction handling if an anonymous set
remains unbound.

Fixes: 96518518cc ("netfilter: add nftables")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
Pablo Neira Ayuso 2023-06-16 15:21:33 +02:00 • committed by Greg Kroah-Hartman
commit 46f801ab5f
2 changed files with 35 additions and 3 deletions