netfilter: nft_synproxy: unregister hooks on init error path
authorPablo Neira Ayuso <pablo@netfilter.org>
Thu, 10 Feb 2022 09:06:42 +0000 (10:06 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 10 Feb 2022 15:33:57 +0000 (16:33 +0100)
Disable the IPv4 hooks if the IPv6 hooks fail to be registered.

Fixes: ad49d86e07a4 ("netfilter: nf_tables: Add synproxy support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_synproxy.c

index a0109fa..1133e06 100644 (file)
@@ -191,8 +191,10 @@ static int nft_synproxy_do_init(const struct nft_ctx *ctx,
                if (err)
                        goto nf_ct_failure;
                err = nf_synproxy_ipv6_init(snet, ctx->net);
-               if (err)
+               if (err) {
+                       nf_synproxy_ipv4_fini(snet, ctx->net);
                        goto nf_ct_failure;
+               }
                break;
        }