git: be7e57fbf972 - main - pf: free an unparsed rule with pf_krule_free() in pf_handle_addrule()

From: R. Christian McDonald <rcm_at_FreeBSD.org>
Date: Wed, 30 Sep 2026 23:31:22 UTC
The branch main has been updated by rcm:

URL: https://cgit.FreeBSD.org/src/commit/?id=be7e57fbf9729abdc14c9cb37a127c6a3fa95e27

commit be7e57fbf9729abdc14c9cb37a127c6a3fa95e27
Author:     R. Christian McDonald <rcm@FreeBSD.org>
AuthorDate: 2026-09-30 23:25:48 +0000
Commit:     R. Christian McDonald <rcm@FreeBSD.org>
CommitDate: 2026-09-30 23:25:48 +0000

    pf: free an unparsed rule with pf_krule_free() in pf_handle_addrule()
    
    When the PFNL_CMD_ADDRULE message fails to parse, pf_handle_addrule()
    frees the rule with pf_free_rule(), which asserts the rules and config
    locks (neither is held) and releases references that
    pf_ioctl_addrule() has not taken yet. With INVARIANTS this panics on
    any parse error; without, a rule address parsed as PF_ADDR_TABLE makes
    pfr_detach_table() dereference NULL.
    
    Use pf_krule_free(), as the ioctl paths do.
    
    Reviewed by:            kp
    Approved by:            kp (mentor)
    Fixes:                  e249f5daa41f ("pf: fix memory leak on rule add parse failure")
    MFC after:              1 week
    Sponsored by:           Rubicon Communications, LLC ("Netgate")
    Differential Revision:  https://reviews.freebsd.org/D60104
---
 sys/netpfil/pf/pf_nl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sys/netpfil/pf/pf_nl.c b/sys/netpfil/pf/pf_nl.c
index 6281b2d0ad19..8d06798065ad 100644
--- a/sys/netpfil/pf/pf_nl.c
+++ b/sys/netpfil/pf/pf_nl.c
@@ -847,7 +847,7 @@ pf_handle_addrule(struct nlmsghdr *hdr, struct nl_pstate *npt)
 
 	error = nl_parse_nlmsg(hdr, &addrule_parser, npt, &attrs);
 	if (error != 0) {
-		pf_free_rule(attrs.rule);
+		pf_krule_free(attrs.rule);
 		return (error);
 	}