From: Pablo Neira Ayuso Date: Thu, 10 Feb 2022 09:06:42 +0000 (+0100) Subject: netfilter: nft_synproxy: unregister hooks on init error path X-Git-Tag: baikal/mips/sdk6.1~6409^2~38^2~2 X-Git-Url: https://git.baikalelectronics.ru/?a=commitdiff_plain;h=6c33f5efa567a921831c5efdadfc9aa95ab33826;p=kernel.git netfilter: nft_synproxy: unregister hooks on init error path Disable the IPv4 hooks if the IPv6 hooks fail to be registered. Fixes: 4369d34f5e64 ("netfilter: nf_tables: Add synproxy support") Signed-off-by: Pablo Neira Ayuso --- diff --git a/net/netfilter/nft_synproxy.c b/net/netfilter/nft_synproxy.c index a0109fa1e92d0..1133e06f3c40e 100644 --- a/net/netfilter/nft_synproxy.c +++ b/net/netfilter/nft_synproxy.c @@ -191,8 +191,10 @@ static int nft_synproxy_do_init(const struct nft_ctx *ctx, if (err) goto nf_ct_failure; err = nf_synproxy_ipv6_init(snet, ctx->net); - if (err) + if (err) { + nf_synproxy_ipv4_fini(snet, ctx->net); goto nf_ct_failure; + } break; }