[PATCH] ipvs: reject invalid states in connection template sync records

Kyle Zeng posted 1 patch 1 month, 2 weeks ago
[PATCH] ipvs: reject invalid states in connection template sync records
Posted by Kyle Zeng 1 month, 2 weeks ago
IPVS sync receivers validate protocol states before creating or updating a
connection. For connection templates, however, they only log states outside
the template state range and still store the value in the connection.

A template can be returned by ordinary connection lookup. TCP and SCTP then
use the invalid state as an index into their transition tables.

Reject invalid template states in both sync protocol versions before
looking up or modifying a connection. The version 1 path handles both
IPv4 and IPv6 records.

Fixes: 275411430f89 ("ipvs: add assured state for conn templates")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Kyle Zeng <kylebot@openai.com>

diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c
index 93038ab..6f0c2a4 100644
--- a/net/netfilter/ipvs/ip_vs_sync.c
+++ b/net/netfilter/ipvs/ip_vs_sync.c
@@ -1002,10 +1002,10 @@ static void ip_vs_process_message_v0(struct netns_ipvs *ipvs, const char *buffer
 					pp->name, state);
 				continue;
 			}
-		} else {
-			if (state >= IP_VS_CTPL_S_LAST)
-				IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
-					  state);
+		} else if (state >= IP_VS_CTPL_S_LAST) {
+			IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
+				  state);
+			continue;
 		}
 
 		ip_vs_conn_fill_param(ipvs, AF_INET, s->protocol,
@@ -1162,10 +1162,10 @@ static inline int ip_vs_proc_sync_conn(struct netns_ipvs *ipvs, __u8 *p, __u8 *m
 			retc = 40;
 			goto out;
 		}
-	} else {
-		if (state >= IP_VS_CTPL_S_LAST)
-			IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n",
-				  state);
+	} else if (state >= IP_VS_CTPL_S_LAST) {
+		IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", state);
+		retc = 40;
+		goto out;
 	}
 	if (ip_vs_conn_fill_param_sync(ipvs, af, s, &param, pe_data,
 				       pe_data_len, pe_name, pe_name_len)) {
-- 
2.53.0
Re: [PATCH] ipvs: reject invalid states in connection template sync records
Posted by Julian Anastasov 1 month, 2 weeks ago
	Hello,

On Mon, 10 Aug 2026, Kyle Zeng wrote:

> IPVS sync receivers validate protocol states before creating or updating a
> connection. For connection templates, however, they only log states outside
> the template state range and still store the value in the connection.
> 
> A template can be returned by ordinary connection lookup. TCP and SCTP then
> use the invalid state as an index into their transition tables.

	I guess, this is possible again due to sync. I'll
provide fix for this problem.

> 
> Reject invalid template states in both sync protocol versions before
> looking up or modifying a connection. The version 1 path handles both
> IPv4 and IPv6 records.
> 
> Fixes: 275411430f89 ("ipvs: add assured state for conn templates")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Kyle Zeng <kylebot@openai.com>

	Looks good to me for the nf tree, thanks! Next time use
"nf" or "nf-next" tags for IPVS patches.

Acked-by: Julian Anastasov <ja@ssi.bg>

> 
> diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c
> index 93038ab..6f0c2a4 100644
> --- a/net/netfilter/ipvs/ip_vs_sync.c
> +++ b/net/netfilter/ipvs/ip_vs_sync.c
> @@ -1002,10 +1002,10 @@ static void ip_vs_process_message_v0(struct netns_ipvs *ipvs, const char *buffer
>  					pp->name, state);
>  				continue;
>  			}
> -		} else {
> -			if (state >= IP_VS_CTPL_S_LAST)
> -				IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
> -					  state);
> +		} else if (state >= IP_VS_CTPL_S_LAST) {
> +			IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
> +				  state);
> +			continue;
>  		}
>  
>  		ip_vs_conn_fill_param(ipvs, AF_INET, s->protocol,
> @@ -1162,10 +1162,10 @@ static inline int ip_vs_proc_sync_conn(struct netns_ipvs *ipvs, __u8 *p, __u8 *m
>  			retc = 40;
>  			goto out;
>  		}
> -	} else {
> -		if (state >= IP_VS_CTPL_S_LAST)
> -			IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n",
> -				  state);
> +	} else if (state >= IP_VS_CTPL_S_LAST) {
> +		IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", state);
> +		retc = 40;
> +		goto out;
>  	}
>  	if (ip_vs_conn_fill_param_sync(ipvs, af, s, &param, pe_data,
>  				       pe_data_len, pe_name, pe_name_len)) {
> -- 
> 2.53.0

Regards

--
Julian Anastasov <ja@ssi.bg>