Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

From: Florian Westphal
Date: Mon Jul 25 2016 - 03:27:15 EST


Michal Kubecek <mkubecek@xxxxxxx> wrote:
> > What lock are you talking about?
> >
> > The table lock is aquired after the sanity/translation pass.
>
> I meant xt_compat_lock(AF_INET) (or AF_INET6 or NFPROTO_ARP) which is
> held for almost all of translate_compat_table().

Ah, true. Fortunately most installations won't use this.