netfilter: nft_immediate: drop chain reference counter on error
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 1 Jan 2024 19:15:33 +0000 (20:15 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 3 Jan 2024 10:17:17 +0000 (11:17 +0100)
commitb29be0ca8e816119ccdf95cc7d7c7be9bde005f1
tree406469deb597fbfbc2a2e47b80b77ccae0e1097e
parente6345d2824a3f58aab82428d11645e0da861ac13
netfilter: nft_immediate: drop chain reference counter on error

In the init path, nft_data_init() bumps the chain reference counter,
decrement it on error by following the error path which calls
nft_data_release() to restore it.

Fixes: 4bedf9eee016 ("netfilter: nf_tables: fix chain binding transaction logic")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_immediate.c