git: be7e57fbf972 - main - pf: free an unparsed rule with pf_krule_free() in pf_handle_addrule()
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 30 Sep 2026 23:31:22 UTC
The branch main has been updated by rcm:
URL: https://cgit.FreeBSD.org/src/commit/?id=be7e57fbf9729abdc14c9cb37a127c6a3fa95e27
commit be7e57fbf9729abdc14c9cb37a127c6a3fa95e27
Author: R. Christian McDonald <rcm@FreeBSD.org>
AuthorDate: 2026-09-30 23:25:48 +0000
Commit: R. Christian McDonald <rcm@FreeBSD.org>
CommitDate: 2026-09-30 23:25:48 +0000
pf: free an unparsed rule with pf_krule_free() in pf_handle_addrule()
When the PFNL_CMD_ADDRULE message fails to parse, pf_handle_addrule()
frees the rule with pf_free_rule(), which asserts the rules and config
locks (neither is held) and releases references that
pf_ioctl_addrule() has not taken yet. With INVARIANTS this panics on
any parse error; without, a rule address parsed as PF_ADDR_TABLE makes
pfr_detach_table() dereference NULL.
Use pf_krule_free(), as the ioctl paths do.
Reviewed by: kp
Approved by: kp (mentor)
Fixes: e249f5daa41f ("pf: fix memory leak on rule add parse failure")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60104
---
sys/netpfil/pf/pf_nl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sys/netpfil/pf/pf_nl.c b/sys/netpfil/pf/pf_nl.c
index 6281b2d0ad19..8d06798065ad 100644
--- a/sys/netpfil/pf/pf_nl.c
+++ b/sys/netpfil/pf/pf_nl.c
@@ -847,7 +847,7 @@ pf_handle_addrule(struct nlmsghdr *hdr, struct nl_pstate *npt)
error = nl_parse_nlmsg(hdr, &addrule_parser, npt, &attrs);
if (error != 0) {
- pf_free_rule(attrs.rule);
+ pf_krule_free(attrs.rule);
return (error);
}