From nobody Fri Sep 25 21:03:48 2026 Received: from mail-wm2-f9.google.com (mail-wm2-f9.google.com [74.125.225.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0BC564A64F0 for ; Mon, 21 Sep 2026 14:57:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.137 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002645; cv=none; b=SyCPTXqRQrkWkESgsJA9UBU2txTyNyoKqcgePUH3vtCmcstAon9FUjru8q4W8SYK3/Ehyvqg+ewjxV0o3IfctNH4ULvb8+UFQDF8xX2nwLYZYP+9k3H0b1g9Za1c0luvKJoI5y6GcqN7QAzy9IdwnqhufcP9e2vZkQ/F9DdJPT8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002645; c=relaxed/simple; bh=GewYnmEL4DmNXoNcMZj/SIhw9+Nkv+8Qj+/vw7RBrBE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=eQ+1hM5Ie3Fxl4PIJoZ0NcO0F+5TOm4rkAwcVimg7c48nyI9us9TlzSIbdHOck0kRyfKUTKrvjmnrhhTLIRqQFksMZks0jw2ET5UILeyHd1KlwVnVls2SHeAto8YwJ0bZMo6cgQuPfPChmwsxAGLIPitE6ptkJrNaPtTcZ20OvA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.225.137 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-wm2-f9.google.com with SMTP id 5b1f17b1804b1-49e6e43b9d8so11352075e9.1 for ; Mon, 21 Sep 2026 07:57:17 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790002634; x=1790607434; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=pQTMqBWHnIAoQBjOra2YMizNpxK4ySQgVrZe7YnTaiY=; b=N70MJj8MYXHe74CEXLmLnToGyJHQxCtqv7VEUAkRA3Ci/keIBUvECKL8SMcPCagf1x 9dnpDvP94XteziNir90zJDG6jnoaBpoesLP8m1Lx9jaYw35IgWHczL2I9MknqKIFQ0Cx c6siF7bLM2EaoitHamXzVfOgIiesSjGv3nNuptjdTjtrIa57wZtP2NKFP9MRsKa0/91t G0bEmA2rfe+oThLhhHdSMiUpqb1TQlEg55UJ7Fncyci1cZ50SQw3yg7pmbLRmfi1ZX3y ltoZKs1783OMOISoyKHjhOSfw5HjiDSvf0wj0HaOUm2dXy43gr9bTWn/LNsmFQjXaaFY 9vrw== X-Forwarded-Encrypted: i=1; AKwUvBxo4X1YQK45KbT3J6W3lPl1qjA2UWebgRoc7DuV3d8mP2kod/pEon6Z282YoYMMKPgQyZExR2B8oaDuyDM=@vger.kernel.org X-Gm-Message-State: AFuF++msUt9UENe4LKaNMXg5NEECSSi8c/VwbBbVRrottRRyikTZ4qoN yXXRgBxirXwatSNbUVDUi4g+NnFkMtDZ/qTGR52hnWjLTBPKcoienT3A X-Gm-Gg: AYBFou0f90KIbmrD8+z0QIKq2NzlxWi1YLsLj94eXkemMAoVp8wX/Ij2OqH1oLCm0JI o9JgASRuYVNfbBxJyFpbkj27aMwNj+fKZI4O2+SQ/5zfwKZPhqLUKjtvFDE/xuTljiG1JYm9QJ6 YChyYlwHemNU5fjNeHFkJ6namYDOYnqOd4/glWkEsVhYSJzgWNqbwWSZuVC50C6c9NVQTxPh6g5 3Ymjg3IbH/dK4aSwcVnMI8yvFQ9LCyeavBEolasPJGZ/gDORDWyZOh4dfpLEHCv/hSYd//moOKT kXfHq2zt37dMaUnJoj1MnICim9soqLtPiAjET+X8ibnz9zFCt035SF32Js8dGQ8zq4UIZmwJXMc Jda+SbVRe73SllarITLd7CzWCW2PvapNnxjINFCsQ5y2RqM9mAKWgF8lImYRo+ASD4wtlGAD2Nd YdacK0g3ifhxSlW1aLTApd4Q3xx79xaGq4dPr+lZvlFiZQLOkXCwkHpKsJ9CvMQK1JsTgIZw56n GGe9/BpmGDV0fOBoSboZrkZgJ90o+npHZjpdLj91yxNzJOWJG8t X-Received: by 2002:a05:600c:4e86:b0:49c:d52e:d0ea with SMTP id 5b1f17b1804b1-49fc566e6efmr144949645e9.4.1790002634076; Mon, 21 Sep 2026 07:57:14 -0700 (PDT) Received: from im-t490s.redhat.corp (78-80-107-225.customers.tmcz.cz. [78.80.107.225]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fcd0eabfcsm243153905e9.3.2026.09.21.07.57.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 07:57:13 -0700 (PDT) From: Ilya Maximets To: netdev@vger.kernel.org Cc: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Jamal Hadi Salim , Jiri Pirko , Xin Long , Marcelo Ricardo Leitner , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, dev@openvswitch.org, Ilya Maximets , stable@vger.kernel.org, Axel Mierczuk Subject: [PATCH net 1/6] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Date: Mon, 21 Sep 2026 16:55:43 +0200 Message-ID: <20260921145655.3167436-2-i.maximets@ovn.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260921145655.3167436-1-i.maximets@ovn.org> References: <20260921145655.3167436-1-i.maximets@ovn.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In a case where skb with an unconfirmed ct entry gets cloned, we may end up committing both but with different sets of extensions. The series of events: 1. The first clone wants to commit and runs the helpers wiring up the extension pointer into the expectation list. 2. Then it looses the confirmation keeping the entry unconfirmed. 3. Second clone now wants to commit labels and adds the new extension for that breaking the pointer in the expectation list causing UAF on the destruction path later. While this is possible to trigger, there should be no practical network pipeline where committing both clones without modifications into the same zone is needed. So, let's just reset the entry in case for some reason we got an skb with a shared one during commit. This doesn't affect any known use cases, but avoids any potential problems with sharing and modification of the unconfirmed ct entry. The fixes tag points to the introduction of helpers, since that's the main UAF trigger for the sharing. Fixes: cae3a2627520 ("openvswitch: Allow attaching helpers to ct action") Cc: stable@vger.kernel.org Reported-by: Axel Mierczuk Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole --- include/net/netfilter/nf_conntrack.h | 5 +++++ net/openvswitch/conntrack.c | 12 ++++++++++++ 2 files changed, 17 insertions(+) diff --git a/include/net/netfilter/nf_conntrack.h b/include/net/netfilter/n= f_conntrack.h index bc42dd0e10e65..c39425e54d87d 100644 --- a/include/net/netfilter/nf_conntrack.h +++ b/include/net/netfilter/nf_conntrack.h @@ -185,6 +185,11 @@ static inline void nf_ct_put(struct nf_conn *ct) nf_ct_destroy(&ct->ct_general); } =20 +static inline bool nf_ct_shared(const struct nf_conn *ct) +{ + return refcount_read(&ct->ct_general.use) > 1; +} + /* load module; enable/disable conntrack in this namespace */ int nf_ct_netns_get(struct net *net, u8 nfproto); void nf_ct_netns_put(struct net *net, u8 nfproto); diff --git a/net/openvswitch/conntrack.c b/net/openvswitch/conntrack.c index 0f433688e17b9..a733029c28dd0 100644 --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -734,6 +734,18 @@ static int __ovs_ct_lookup(struct net *net, struct sw_= flow_key *key, enum ip_conntrack_info ctinfo; struct nf_conn *ct; =20 + /* If the ct entry is not confirmed and shared with some other skb, + * e.g., a cloned one, we can't just modify it with the commit as we + * must not modify the extension set. Reset. + */ + if (cached && info->commit) { + ct =3D nf_ct_get(skb, &ctinfo); + if (ct && !nf_ct_is_confirmed(ct) && nf_ct_shared(ct)) { + nf_reset_ct(skb); + cached =3D false; + } + } + if (!cached) { struct nf_hook_state state =3D { .hook =3D NF_INET_PRE_ROUTING, --=20 2.55.0 From nobody Fri Sep 25 21:03:48 2026 Received: from mail-wm2-f5.google.com (mail-wm2-f5.google.com [74.125.225.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D64D4AB1CF for ; Mon, 21 Sep 2026 14:57:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.133 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002646; cv=none; b=lqJj/OJ27BtvCWhjIgW0f+FcUUEJno1KLbp/0D2aiW2nNMBmvwEY8heSVKkv21O639GZwcULtlBhaKRa6DZHA61heI9rfUzQlvUQ2IEBGm2ENp9XCpxVuunDOlWZEZey9kDDn5EboGdqQWnIEIiduxGfUg7hHoBytqra/XaYSmk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002646; c=relaxed/simple; bh=h/e4AULhjSmntZab1cGdfq7OkJUisqf0YdE9X03GDLM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gyD9UgzPfQu+vJm6RADoZNlrWS/OWZPvNSWa03xkjEjAjiDmrKsElAffYyBc1gj4kFZ3cxEF8uHeVFUaehtJyKW/VEZZaEppaQ7Z+T2w49ZEjDkLMWk6aEkQZ+NgcrLdZHdEAr+W726+YqQThNHZGe9kDqxsiyjhfGA9iXL0yXM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.225.133 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-wm2-f5.google.com with SMTP id 5b1f17b1804b1-49e66652cc3so16719675e9.1 for ; Mon, 21 Sep 2026 07:57:19 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790002637; x=1790607437; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VXSW6q1NZ2VUKtjXQJBrCrLariG7HqyHLR8Ed7NC5Gs=; b=U7iMBVcysn+pBQ8FN3dR7zssdtBGtcv1q0TxG5O1p9gmVDmlswIlX/6V86ZZeGAPPi T5WiN37fvk/U+72321EnL5FG8dSkhvQrbu2O4vdLuX95OeLhg3PkjDLsrCUMNDZrRcbI mv9Grw6nwBwH7KnQjcaplrl5Anv81qD12fggR1kUp0dsoPyAQ+uTAMyTxREvXQ4IJ+tS pDNmFo28UaBwedclb+s3PziVvc5qs9PVtPBHQJlKZ/F4rVZAN03lxP720oZ3j4N600Rl HJmsz4s8vL0kNQR15WogGOTHHpA4xpHjG+bjWxLDQntaV2rfu6AEhzdOSjJO6DPeIxXe 7x9w== X-Forwarded-Encrypted: i=1; AKwUvBy0KnwSe8NjfBmwwJS/C3zWhcsSn+mdYKIz60ExJwjLLv1jrTAe63BxzKg1BmEsfqVLPzmpLc+Exa2MKqg=@vger.kernel.org X-Gm-Message-State: AFuF++nJd7W4vVC0nR6CgSCFRcLVAsrj58IyJgUy8iQochBKc86AJyCs 9OGL7Ofps7BT01XtRvKzJ0ddwKUrflDG+XLZMwV+tMFSj6DGVD95dhde X-Gm-Gg: AYBFou3zYIMs5WMgg/1rklIE+vxokGjsKmofmv7V2p8sy69B7/s6tBs/YR0bynYRr9R u9aBp8YNOtCWSN49AOWRcktvXjANvxEgSXW1s3ZstG/w3jJlxRbI+JDQ0TJjmcsSRdJMe0LVaY2 jaMdfZm+nP19MClnFSFpLzkGquL841fWZ04Q7gIBanbGRpP1KgfLpcdlpZLDiiLT0XCKDuueMim i550N/3RXjvtapRhoRJxYJI3gKFluMJGaqvlnMzLzkyN1SElnIqUiM+5EGPFtFpHBsEjpnYYlFv VfKZ7M4kGCFw3kzdizX3jHdtnLSJIikg9EssG0sa6+MG/g2aj//1NmrkdTIPLiSSKW+ihln1VFV X1/7m55D0dZMTO1Juf9tMpEEBEn5cSZS1KCrVDa9TTsekrBlRmCi9xbJUWxVgLbdNk+aF2WBIde ZTjUmISD9HwX8wvXe27oz2Y49CXn2asQy/lwToTYj+khdNN8Er9EQYpqmgMZSZrD2k7PZdGCZdj yyY0UV3olMhq0TKCMoD38x+Z7RjBapQkveT2xTGSQ9dEwYa/hiJ X-Received: by 2002:a05:600d:4453:10b0:49f:cbf1:e77b with SMTP id 5b1f17b1804b1-49fcbf1e9eamr90041305e9.10.1790002636893; Mon, 21 Sep 2026 07:57:16 -0700 (PDT) Received: from im-t490s.redhat.corp (78-80-107-225.customers.tmcz.cz. [78.80.107.225]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fcd0eabfcsm243153905e9.3.2026.09.21.07.57.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 07:57:16 -0700 (PDT) From: Ilya Maximets To: netdev@vger.kernel.org Cc: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Jamal Hadi Salim , Jiri Pirko , Xin Long , Marcelo Ricardo Leitner , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, dev@openvswitch.org, Ilya Maximets , stable@vger.kernel.org Subject: [PATCH net 2/6] net: openvswitch: conntrack: remove 'add_helper' dead code Date: Mon, 21 Sep 2026 16:55:44 +0200 Message-ID: <20260921145655.3167436-3-i.maximets@ovn.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260921145655.3167436-1-i.maximets@ovn.org> References: <20260921145655.3167436-1-i.maximets@ovn.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" This variable can only become 'true' when the connection is not confirmed, but it is only checked when it is confirmed. So, it can be treated as being always false and just removed. Fixes: 3c1860543fcc ("openvswitch: add nf_ct_is_confirmed check before assi= gning the helper") Cc: stable@vger.kernel.org Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole --- net/openvswitch/conntrack.c | 10 ++-------- 1 file changed, 2 insertions(+), 8 deletions(-) diff --git a/net/openvswitch/conntrack.c b/net/openvswitch/conntrack.c index a733029c28dd0..c20f096eef40e 100644 --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -778,8 +778,6 @@ static int __ovs_ct_lookup(struct net *net, struct sw_f= low_key *key, =20 ct =3D nf_ct_get(skb, &ctinfo); if (ct) { - bool add_helper =3D false; - /* Packets starting a new connection must be NATted before the * helper, so that the helper knows about the NAT. We enforce * this by delaying both NAT and helper calls for unconfirmed @@ -811,7 +809,6 @@ static int __ovs_ct_lookup(struct net *net, struct sw_f= low_key *key, GFP_ATOMIC); if (err) return err; - add_helper =3D true; =20 /* helper installed, add seqadj if NAT is required */ if (info->nat && !nfct_seqadj(ct)) { @@ -821,13 +818,10 @@ static int __ovs_ct_lookup(struct net *net, struct sw= _flow_key *key, } =20 /* Call the helper only if: - * - nf_conntrack_in() was executed above ("!cached") or a - * helper was just attached ("add_helper") for a confirmed - * connection, or + * - nf_conntrack_in() was executed above ("!cached"), or * - When committing an unconfirmed connection. */ - if ((nf_ct_is_confirmed(ct) ? !cached || add_helper : - info->commit)) { + if ((nf_ct_is_confirmed(ct) ? !cached : info->commit)) { int err =3D nf_ct_helper(skb, ct, ctinfo, info->family); =20 err =3D verdict_to_errno(err); --=20 2.55.0 From nobody Fri Sep 25 21:03:48 2026 Received: from mail-wm2-f9.google.com (mail-wm2-f9.google.com [74.125.225.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 68CF14ABBCE for ; Mon, 21 Sep 2026 14:57:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.137 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002650; cv=none; b=T/bM/CiTAELjUdpGJUuoTge6VWvmbRSk3jFvNjOlbqXKs85KjygmlIoZ5OomhAJ+QyHJE4M+yTJIYMxIY3GW2ux0NpjDfN/Cai6qS55zjrOpewX8PGvGYBDRbInLgvivfg9qgMlOckUt67SvvZ06K+vksEAGtWdq1VyXkHdNya4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002650; c=relaxed/simple; bh=TzIqUe2bPr+rCrYGN26hULTVXKps5YUGqZ1r3naQPKI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=hSZyZtJptTpVzVN315JrXj1sUsKoSSR3qG6eR0X7++YmoNYwGlwOxjWw7bezEzjk8kL8iGX9eKxm8D7j8fNxnSt0QYUmwIKIHplFBAJTmj1g0SV2I3L7MnZdMzWMGhB6ZdqbqMgVaFn9Bt9+gwVe2OKovAJTYP0M6FpjZTJdsrE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.225.137 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-wm2-f9.google.com with SMTP id 5b1f17b1804b1-49e6eb11e9cso14239985e9.1 for ; Mon, 21 Sep 2026 07:57:24 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790002640; x=1790607440; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=r/iG3o43oIJZJaCYcUSYeC2n62gq4cdWVmWrUdZeO8U=; b=cFSakplkjI6i1P+HEGhcVypBZvG/TUDi6lp9SKiYolvtL0wdQiqSvjAIKTKuV3/hbn PjXLfvyJUJ+gROinRsoKf13caxVN8mo2QRnvhQtb7IbM1+w5SxBWfvkkNGhProk9fATG A1Pd3+IACaxeXIPlU1yAKlXyZ+Ehc7+Ul6K/282M+s56Udq5Eu3PXsKsNtZH85c7X6bp QWe0+1e/Iv7h3dRzTMC2SYb6Vl083YRu8lJRCSs33k3YDoDKAgirKKefRbLGD4xrOitU U/gG54bKmGNAnE3SPknRE9zvLxihmwyfZ0hyPiT424ctIh2SNAAIiwA/Ngnx1sNNflXe pKIg== X-Forwarded-Encrypted: i=1; AKwUvBwuXtd2vRJ2d0Yj1FJe4TW6H6GyLw5/HaY8n9rAFjsZqzxVzBlE/hym4wXJC2RZNsCKIVj/rDMMW5z+zyk=@vger.kernel.org X-Gm-Message-State: AFuF++nOm1LaQxHRmx/XDxNzVTCKwgLcv11UxcLg7qumBwQq/MfOrkYO xhymUSPSesOW9Y8zHXsquAM5HY+OwHLUMoqoR8OcApQ04+YE65J5IaCL X-Gm-Gg: AYBFou0VJneFFjKvq4RvJzw9Geh9zYsqU2i85OnzcLhwFoZE8tnsBdlGQ+cKgLs7jW8 ZivdE7bmDoi8yFRvM+z0aY58oqhCkQKiTHfcV6SLiJB+K6PtvuKz8yWh/TN+LgRCHu8sNebdwRB l3NJlAikmvvt2WmSw4p59cYbF5sIEDjQd+8tn+YpCV/BT21QuA0PI/mA4ZaxkMFgRFkxYDUQpV1 bZSSoGOnwkGE1i61WEJveQAOsvV7gNrdMSz+QiGynm5vp05fiKJxfKx7wg3TcN56ZMhGr7Yr0GP IS1SZo/bzgnMr5OicKikpu1Egb9Q9B9IOt8umvdocg4VPZ4MZMbokepELYriGbUuMeYHyeUuEfP ZhJKD8QihjC8gbgwcvVhp5uaYQJBr9BpQoL0T724H2zJYkUyh8NlJJpkoOekex56lyc9jM2bBXq w2Qq6cyGzl0olCENwO5OIVZdUNYJD/hro/LEoQgzJj1bzO9Bbj+UHpTKZAVqyw5LuUGF8KMp/Wj pIfdnVwCqgvaPPX/FZ/AXUvqrfdhv77PR/vf1nkt1VXFlFTrmvIV0BFETvxovA= X-Received: by 2002:a05:600c:4e86:b0:499:8b13:3a98 with SMTP id 5b1f17b1804b1-49fc56715d6mr143236515e9.4.1790002639706; Mon, 21 Sep 2026 07:57:19 -0700 (PDT) Received: from im-t490s.redhat.corp (78-80-107-225.customers.tmcz.cz. [78.80.107.225]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fcd0eabfcsm243153905e9.3.2026.09.21.07.57.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 07:57:19 -0700 (PDT) From: Ilya Maximets To: netdev@vger.kernel.org Cc: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Jamal Hadi Salim , Jiri Pirko , Xin Long , Marcelo Ricardo Leitner , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, dev@openvswitch.org, Ilya Maximets , stable@vger.kernel.org, Axel Mierczuk Subject: [PATCH net 3/6] net: openvswitch: conntrack: fix helper UAF due to extensions realloc Date: Mon, 21 Sep 2026 16:55:45 +0200 Message-ID: <20260921145655.3167436-4-i.maximets@ovn.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260921145655.3167436-1-i.maximets@ovn.org> References: <20260921145655.3167436-1-i.maximets@ovn.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" While calling the helpers, a raw pointer to the extensions area is wired into expectations list: -> nf_ct_helper() -> helper->help() -> nf_ct_expect_related_report() -> nf_ct_expect_insert() -> hlist_add_head_rcu(&exp->lnode, &master_help->expectations) In case the connection is not confirmed yet, more extensions can be added afterwards with *_ext_add() calls reallocating the extension space and leaving the now invalid pointer in the expectations list that is later accessed while removing the expectation. Make sure that helpers are called at the end after all the other extensions are already added. Note that the helper rejection now leaves the mark and labels set, but that's not different from how the NAT was handled before or how the mark and the labels were handled on confirmation failure. And there are no atomicity guarantees provided by the API anyway. Fixes: cae3a2627520 ("openvswitch: Allow attaching helpers to ct action") Cc: stable@vger.kernel.org Reported-by: Axel Mierczuk Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole --- net/openvswitch/conntrack.c | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/net/openvswitch/conntrack.c b/net/openvswitch/conntrack.c index c20f096eef40e..d3326edcabf76 100644 --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -817,11 +817,14 @@ static int __ovs_ct_lookup(struct net *net, struct sw= _flow_key *key, } } =20 - /* Call the helper only if: - * - nf_conntrack_in() was executed above ("!cached"), or - * - When committing an unconfirmed connection. + /* Call the helper only if nf_conntrack_in() was executed + * above ("!cached"). + * + * For unconfirmed connections it will be called later during + * commit as we need to have all the other extensions allocated + * before the call. */ - if ((nf_ct_is_confirmed(ct) ? !cached : info->commit)) { + if (nf_ct_is_confirmed(ct) && !cached) { int err =3D nf_ct_helper(skb, ct, ctinfo, info->family); =20 err =3D verdict_to_errno(err); @@ -1025,6 +1028,14 @@ static int ovs_ct_commit(struct net *net, struct sw_= flow_key *key, return err; =20 nf_conn_act_ct_ext_add(skb, ct, ctinfo); + + /* Call the helpers now. We couldn't do this before as + * all the extensions must be allocated before the call. + */ + err =3D nf_ct_helper(skb, ct, ctinfo, info->family); + err =3D verdict_to_errno(err); + if (err) + return err; } else if (IS_ENABLED(CONFIG_NF_CONNTRACK_LABELS) && labels_nonzero(&info->labels.mask)) { err =3D ovs_ct_set_labels(ct, key, &info->labels.value, --=20 2.55.0 From nobody Fri Sep 25 21:03:48 2026 Received: from mail-wm2-f7.google.com (mail-wm2-f7.google.com [74.125.225.135]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6C4FC4AC14D for ; Mon, 21 Sep 2026 14:57:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.135 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002650; cv=none; b=SX2gntyNB/aD37C5zgkoLsjcRG7JlzpEeGo+Oxfw8S+MLZ/jlj/tA766jECYdbHEW5bGjzAnPk0+ivjRMzQRGeSbVOARCCZkgAhIE78DpXI8MqPFS/79gpJrE18ADhXWKLr9bPay2XG0ZYEi1fexLSoFG7GJCHcu39XbEoGYMsQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002650; c=relaxed/simple; bh=OK1hcbfhrRYnS7Fji50QexykkRH0sRg4CUWkyRdbGGI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Jh1o/dcb+Jw5gv8PC8uXZiNJK8lep+4hIA37uILqgrPyJExPta9l26pA+TNTRixlYFLU8xgXVGKba+ExwDPD4WBxoscdGu+gFGin0D5m+GPs3y9tvrGIy8Ph7i+RGCZXmmGIsmnSbdr14ChqPmzhO+lOWtQdKjsTHk6WvUrE8wM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.225.135 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-wm2-f7.google.com with SMTP id 5b1f17b1804b1-49e8361492fso12427225e9.0 for ; Mon, 21 Sep 2026 07:57:25 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790002643; x=1790607443; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=JPeqxpJkKYTQM9xCANZhikKMsVz4xTfivxM0gs/My1U=; b=Kss6xwSBVY1oGu8dKD1kFsU8GYHEJRVqPsEf/aTeu+aBHbn14sn95ZaJHjYkA7oCBd OsCVIdkpyrOm39UGK3H2ZLUVh34HxXKIAOFY8MJEH+Kmg85m7pKGK/E2oEGlcE+lWUV5 i91z+RqJ8yQI7gbT2Oqd3v6GommhHR/65yrSyKn6jHyFGi7AZ/jxpeMNBHA0ICIf+gQ7 4j3a1iolwe63l5/fqvZagCLubKeaCtzNqeGGYBTdjZdsfqA0S9FjYbXzORGL/m5e1AA9 MYoacswfNqNI2r37VjNKUACqhWwCOb5Y/2RqZ1lx0cgtQUfoG0wpbRebJ+MTRe3ZafK7 bW1g== X-Forwarded-Encrypted: i=1; AKwUvBzLSpSItEbZjkXmWQsxYunhK09QsCiJUJSimaArOWLGqeLkStPTHYlcg6NsE3NCBgfMGfsBopsY8TzSmKg=@vger.kernel.org X-Gm-Message-State: AFuF++mVgs9QdliJEvLECoXA5wG2Uo3VBbEya5N2LTGMrCP7LcbwV+h7 t1b7OYJIThQdioMiVyvtKn5N38k9yPWqnOz3hSdX/PJFSrCcG9JzvF3a X-Gm-Gg: AYBFou0GHnq1XnXxO5mXh2cH612kUFzccpqSm0uLZCqSqh1DS9YAqDOheyJ29il4VNk Gz7Jk90+04NLy8uZMcLR/KlN5tQEkgF9Nzjao/yXhQT1OOC36WrKe8nCd6Gi4CzmfcF7ip8X96z ZHJjIB0rhKWaZRFtKEv/hYij2nac9HLoUp5H5bW8fvSASOmdE8ED2CnlSfHvcFd4PbhyAB5gt49 erFxt7kF2mnr3HrhY4T/G2Ig/zTnNBkGxiXzrvt00qMo4dHGT/mrV18JYewbTVo7oo2Oq33pGgV Gn3lFYnH9ZHnGCGU4hKGIqk5xf00gzGaf8vJHKcM0EiOZfqpdCINqEG+n6WXUcmzDlvdVFM3+YO h7q4PmzngnUDfQ7BlVWoxy/EXYwQp6tnJ/BHBelJqABUo/tDJKNPG1N+l/NWyjwy3oIp9OEygMm NJo53PoyVPq5ap78Q4uvSF4h36Mr8EI3SjNFHh7MEmQRuScaGd+r9keq5t1p87MZWbiUKBsIfp2 Z56SciUPoYbmeXeK0otRaM8wVPWIcjiNLrW0MQ33oBH1IjZKopY X-Received: by 2002:a05:600c:138b:b0:49c:f89b:f82 with SMTP id 5b1f17b1804b1-49fc568f8dcmr139432395e9.12.1790002642660; Mon, 21 Sep 2026 07:57:22 -0700 (PDT) Received: from im-t490s.redhat.corp (78-80-107-225.customers.tmcz.cz. [78.80.107.225]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fcd0eabfcsm243153905e9.3.2026.09.21.07.57.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 07:57:22 -0700 (PDT) From: Ilya Maximets To: netdev@vger.kernel.org Cc: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Jamal Hadi Salim , Jiri Pirko , Xin Long , Marcelo Ricardo Leitner , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, dev@openvswitch.org, Ilya Maximets , stable@vger.kernel.org, Axel Mierczuk Subject: [PATCH net 4/6] net/sched: act_ct: avoid modifying shared unconfirmed ct entry Date: Mon, 21 Sep 2026 16:55:46 +0200 Message-ID: <20260921145655.3167436-5-i.maximets@ovn.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260921145655.3167436-1-i.maximets@ovn.org> References: <20260921145655.3167436-1-i.maximets@ovn.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In a case where skb with an unconfirmed ct entry gets cloned, we may end up processing both again but with different sets of extensions. The series of events: 1. The first clone wants to commit and runs the helpers wiring up the extension pointer into the expectation list. 2. Then it looses the confirmation keeping the entry unconfirmed. 3. Second clone now wants to commit labels or run NAT and adds the new extension for that breaking the pointer in the expectation list causing UAF on the destruction path later. While this is possible to trigger, there should be no practical network pipeline where we need to process both clones without modifications in the same zone. So, let's just reset the entry in case for some reason we got an skb with a shared one. This doesn't affect any known use cases, but avoids any potential problems with sharing and modification of the unconfirmed ct entry. Unlike openvswitch module, act_ct allows for NAT without commit. Changing that would be a uAPI break. So, act_ct needs to reset on NAT regardless of the commit flag to avoid reallocation of the extension space. This, however, doesn't really change the picture for sensible networking cases as there should be no need to run the same packet twice (before and after the clone) through conntrack without packet header or zone changes and without commit. The fixes tag points to the introduction of helpers, since that's the main UAF trigger for the sharing. Fixes: a21b06e73191 ("net: sched: add helper support in act_ct") Cc: stable@vger.kernel.org Reported-by: Axel Mierczuk Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole Reviewed-by: Jamal Hadi Salim Reviewed-by: Xin Long --- net/sched/act_ct.c | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/net/sched/act_ct.c b/net/sched/act_ct.c index 55f3521edb4c9..e72143d36b119 100644 --- a/net/sched/act_ct.c +++ b/net/sched/act_ct.c @@ -979,11 +979,11 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct sk_buff *skb,= const struct tc_action *a, struct tcf_result *res) { struct net *net =3D dev_net(skb->dev); + bool cached, commit, clear, nat; enum ip_conntrack_info ctinfo; struct tcf_ct *c =3D to_ct(a); struct nf_conn *tmpl =3D NULL; struct nf_hook_state state; - bool cached, commit, clear; int nh_ofs, err, retval; struct tcf_ct_params *p; bool add_helper =3D false; @@ -998,6 +998,7 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct sk_buff *skb, c= onst struct tc_action *a, retval =3D p->action; commit =3D p->ct_action & TCA_CT_ACT_COMMIT; clear =3D p->ct_action & TCA_CT_ACT_CLEAR; + nat =3D p->ct_action & TCA_CT_ACT_NAT; tmpl =3D p->tmpl; =20 tcf_lastuse_update(&c->tcf_tm); @@ -1046,6 +1047,19 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct sk_buff *skb= , const struct tc_action *a, * different zone. */ cached =3D tcf_ct_skb_nfct_cached(net, skb, p); + + /* If the ct entry is not confirmed and shared with some other skb, + * e.g., a cloned one, we can't just modify it with a commit or nat + * as we must not modify the extension set. Reset. + */ + if (cached && (commit || nat)) { + ct =3D nf_ct_get(skb, &ctinfo); + if (ct && !nf_ct_is_confirmed(ct) && nf_ct_shared(ct)) { + nf_reset_ct(skb); + cached =3D false; + } + } + if (!cached) { if (tcf_ct_flow_table_lookup(p, skb, family)) { skip_add =3D true; @@ -1083,7 +1097,7 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct sk_buff *skb,= const struct tc_action *a, if (err) goto drop; add_helper =3D true; - if (p->ct_action & TCA_CT_ACT_NAT && !nfct_seqadj(ct)) { + if (nat && !nfct_seqadj(ct)) { if (!nfct_seqadj_ext_add(ct)) goto drop; } --=20 2.55.0 From nobody Fri Sep 25 21:03:48 2026 Received: from mail-wm2-f9.google.com (mail-wm2-f9.google.com [74.125.225.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 223BD495028 for ; Mon, 21 Sep 2026 14:57:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.137 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002652; cv=none; b=SY9HP8Agx1W7FjeYAtS+lNhyt/aDsnjJhQaGK31yRZ51wpk9TITm6t5DIT33EeG2nxmopBRWGLahWccQdQEv+lmYOEItKLjAcggeeaqbrbJ/48y2g8czcxwnBwht8liLTWSCeN3Q2D+WOaa3oPCLGdeaJC2mDDPBZ5tDV85kAUo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002652; c=relaxed/simple; bh=agbzHpR/PKZ0LLlY2lgVEH4d4x1op12XsKxqX/dfCv8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=q/x8sdykRSf12Azuy15Kk4srCbmPiSQOsgEmcnruXct9a9HJpXL9AsRDTU98AWBtWxlv2JFe+z0342VjIZwSU8pYHR/VqKpnls54B3yFlWN46LQZW8R0mH3/FEq3xmHFB/96LeaHiJgb0ffXGkva/Et3y9MowAx1n2vU4GxrRmA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.225.137 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-wm2-f9.google.com with SMTP id 5b1f17b1804b1-49e6bd65693so20717145e9.0 for ; Mon, 21 Sep 2026 07:57:28 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790002645; x=1790607445; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=0GaJZ+uFEU0tQWZqiav7JnKznavtITsSwryC+6XFRoE=; b=A8w7zBRLHFuF0FdTamNi0jszJK4zhNEZrLRc2ttiXOGmcqxoKwt/7eBWQh14ZFa9K8 J+RpIJl+HneyApGHaRpQxMHW/XymVo3z5ZFuN88fp+VFw1DSgvKIou1u8GpUnQJIhZ0e PlJaEXOkM1cINsGxs+Upm+1Y4oOVQaQ/PsSlgvFqk25VH26sJ1+MZiiWuEQhFS9O+Mf2 xmX6MlrJuAwa7Pne8XRXwHpoUAydSLDSi/LvkjxCewLzNfz6psPydWxbszeg9l5KTxan 5bo9XWVVjRbmNk/RUePMmmytWGukmJVKQjx4/Snw2OgWXVrJKio2x1bOQfxUlK1VIyLF q8lQ== X-Forwarded-Encrypted: i=1; AKwUvBxOHm+2ndr0BZanMKILT/QZeR/UCfT0p4lZpWnG3+Ly4hKj1tpI2p40BTvAPRJwYpGSIVafYhNOMFKQzeM=@vger.kernel.org X-Gm-Message-State: AFuF++lKkb8fdfQPlNUZeEWAuGP4+2CI9Hlk4HwCNrLDOfoTZWozic3h b2J8EqV4tf8/0h996WlvNB/Mx87Kl9MsAT5ilh/enIh2C38JVfOq3pkn X-Gm-Gg: AYBFou0i3Ar1OXnYjcgJGepy2da/J7JpuOyL9fccuXZ9yPmaEdZphemZyxrv0jHgYkE c+LJDAsyjLdF75S/YeAry0BDwt+3gozpIJdFaRjCBtkjc/QblMKQ3Ovkcb2JJxYcUR+bNVl+67D To3PsIjmnMDszPJqE/ANy7+RAf90Z/vDHUss1jAcMusKUvV7H2w2jLR9BOxH9GVI4eNzMevemsZ AVaRj7ymxbiwfZdnghQO3U93xYouHC7TYqXH1scUQ8rrzz47B/vSM/l1qQOayrSg/+Q+OJ/u1QA e+ZMo3qWAntfBbjlJrnRNlzNEPDfxtV5nPmrmJ1SeBNqDnafHmlchYF5V3PN9dMrRVfgt15bTNe TElApN4nZ5AWmlwfw/fdTuNXllxQAwYiFG4myCbsCZnMWePWTy2DOk9S1X9A8nomkUOEHaT9e9w 9ojzwkshlrZiZ7I3hS5+pUdULawcAAZ0b65osk/lIh/9ztVTL8lrdKvQoGJBMeRkTShfY//9RWL dsliEnYvUwhj92haJzHxlPt3ihGN4M55qj+wH19lXQ3XiOuIDgHHcLljr4YojQ= X-Received: by 2002:a05:600c:530e:b0:49c:cfbe:5a76 with SMTP id 5b1f17b1804b1-49fc568157amr140231615e9.2.1790002645153; Mon, 21 Sep 2026 07:57:25 -0700 (PDT) Received: from im-t490s.redhat.corp (78-80-107-225.customers.tmcz.cz. [78.80.107.225]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fcd0eabfcsm243153905e9.3.2026.09.21.07.57.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 07:57:24 -0700 (PDT) From: Ilya Maximets To: netdev@vger.kernel.org Cc: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Jamal Hadi Salim , Jiri Pirko , Xin Long , Marcelo Ricardo Leitner , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, dev@openvswitch.org, Ilya Maximets , stable@vger.kernel.org Subject: [PATCH net 5/6] net/sched: act_ct: remove 'add_helper' dead code Date: Mon, 21 Sep 2026 16:55:47 +0200 Message-ID: <20260921145655.3167436-6-i.maximets@ovn.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260921145655.3167436-1-i.maximets@ovn.org> References: <20260921145655.3167436-1-i.maximets@ovn.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" This variable can only become 'true' when the connection is not confirmed, but it is only checked when it is confirmed. So, it can be treated as being always false and just removed. Fixes: a21b06e73191 ("net: sched: add helper support in act_ct") Cc: stable@vger.kernel.org Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole Reviewed-by: Jamal Hadi Salim Reviewed-by: Xin Long --- net/sched/act_ct.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/net/sched/act_ct.c b/net/sched/act_ct.c index e72143d36b119..f62051ec9d57d 100644 --- a/net/sched/act_ct.c +++ b/net/sched/act_ct.c @@ -986,7 +986,6 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct sk_buff *skb, c= onst struct tc_action *a, struct nf_hook_state state; int nh_ofs, err, retval; struct tcf_ct_params *p; - bool add_helper =3D false; bool skb_is_ours =3D false; bool skip_add =3D false; bool defrag =3D false; @@ -1096,14 +1095,14 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct sk_buff *sk= b, const struct tc_action *a, err =3D __nf_ct_try_assign_helper(ct, p->tmpl, GFP_ATOMIC); if (err) goto drop; - add_helper =3D true; + if (nat && !nfct_seqadj(ct)) { if (!nfct_seqadj_ext_add(ct)) goto drop; } } =20 - if (nf_ct_is_confirmed(ct) ? ((!cached && !skip_add) || add_helper) : com= mit) { + if (nf_ct_is_confirmed(ct) ? (!cached && !skip_add) : commit) { err =3D nf_ct_helper(skb, ct, ctinfo, family); if (err !=3D NF_ACCEPT) goto nf_error; --=20 2.55.0 From nobody Fri Sep 25 21:03:48 2026 Received: from mail-wm2-f10.google.com (mail-wm2-f10.google.com [74.125.225.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D14FE4AD4D5 for ; Mon, 21 Sep 2026 14:57:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.138 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002653; cv=none; b=YUHKor26uQ0pb1SQrWP6TZAV2Uzq4cOfaw4K4qxfd+Z1BAZn8fRSoqyVFKyYkm4JuamXoEOKCMepoaTfujEYLa+trfoDbIsxD9LDcSSCs07ZGI8+bcfFIH9vbbuMYuWmd3+BDE2tVS7PAPBqQq8rNn8aZsdHuaU74vFnn8FIiDY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790002653; c=relaxed/simple; bh=O84UlgIt22qVXOTeLEKlJ+J21Nne9exAai0M6IVznd0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qDujWzBCjB9/tMfUZU3Tq1sXK6cOT9RDGIbW9qecDKtGMTVHchGeOXI3F5urKD7dME1QAshS/hCE9oeCAOLtJ8i9Arv/HnqGeR9nLuJ1AXUQlSUbrF4pHKaNhQyKtYkkA6Oc/FhD89A5/MLDn/ew2SogWDHkugvi1xPD250DYno= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.225.138 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-wm2-f10.google.com with SMTP id 5b1f17b1804b1-49b963f51f6so13081635e9.1 for ; Mon, 21 Sep 2026 07:57:30 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790002648; x=1790607448; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=D5yxLi0HeeDyCNaoa/cXH7lPCvNUM8Mh94Wvp96R2LI=; b=MP1c9CzXiYHJ770APFAlK5pdk8ckTF68azi4aXS1xYxtdEaG7guqWWjVjRJgF8AsjV IIHscM9SZETl64v2xRMSfVoHPHq46NAjUHxR00AKUJFSqEjT4F/CNoNS7OR1r5EkIiTS fsfBBrPC2JGzCjSuEfFuw9BODGkPWWoOONl8oH8zA+9s1PTSu7F7tSs5j5So5k6zrU3y dJgZSf5RPr+0ZyAGY8ozd4noZbOOI77polyWjCCK1+mvcw8+/HlJTY3r00gEdM5PpM5n uNRxdwmj2FMoaGl0gB/a07Q0ZhXGlocRLflOQoPaYiXqfarj+ELl+sRXVehR3it2MiZj biCA== X-Forwarded-Encrypted: i=1; AKwUvByvUpyDM973C1xrD/wXXtVvoMjePHXbsphPdE0+D3DAe+kEniklms/jFzGG3WEcIGIy616YuG2dndu7oMc=@vger.kernel.org X-Gm-Message-State: AFuF++mN/1hJ0CNq4WY6scJEPR/FwM7JC7TlYgZs024DBBUV9186kVkQ oiEz8Fj333AqbiA8prHh/LA15FXE813GaGXKbKL7+aNc82Q/Zix+FIw0 X-Gm-Gg: AYBFou2AHoAz6GoVFzu8iCJ5J/zoJqFhWqUa7MQkh+wAtlK2UhF0ZRMJuWQGLitzf6w EJYcR1dDqtjwytbgfjRwQJ0oy9O8J9YWUJjKQ5uWUwYQ7NEeM1fpgJkYTjsaQUCPy3zsXgapQGj Npg1KP952ux1QCwHjdNQvAQQ51aYNw8u6PrrlMUDzXTs+7Oh/kLSPeECthiY69EGC36LXpx4qs3 vg6r148CP898pnXGmxvzyLC60AuiGadpVw0ZXTqPZ3emYTfZLhEQNLCRl3x5COXrEMkk4z9x+up UGOty0c3QH4lPKUPmd1V1Dund7B2qBL801qheMdS2w0ywJfjZ3bzthgg2gm0nc5YQmKgqeAKY8z e9DPQjnlRng5d423YD6P+bwBoLNDR5GFIBvPGnEe/2h1ii1wBYuayMutgcDBw7AcJdWJAQN4ml3 kRD6hsbn5pcxGliWNoq6hDMBJBv59fq5Q/vFx6zJIQ2pAs1ozBKA8NYvY8+thBkcJMeIHLdwOAA 1XYd+RX8IwGhzilIOYC/+Ma17uob72YWZhlY/Y5h/EPO4OH5P0u3ZM= X-Received: by 2002:a05:600c:34c3:b0:49c:fa21:e74a with SMTP id 5b1f17b1804b1-49fc5757f73mr156995365e9.32.1790002647731; Mon, 21 Sep 2026 07:57:27 -0700 (PDT) Received: from im-t490s.redhat.corp (78-80-107-225.customers.tmcz.cz. [78.80.107.225]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fcd0eabfcsm243153905e9.3.2026.09.21.07.57.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 07:57:27 -0700 (PDT) From: Ilya Maximets To: netdev@vger.kernel.org Cc: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Jamal Hadi Salim , Jiri Pirko , Xin Long , Marcelo Ricardo Leitner , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, dev@openvswitch.org, Ilya Maximets , stable@vger.kernel.org, Axel Mierczuk Subject: [PATCH net 6/6] net/sched: act_ct: fix helper UAF due to extensions realloc Date: Mon, 21 Sep 2026 16:55:48 +0200 Message-ID: <20260921145655.3167436-7-i.maximets@ovn.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260921145655.3167436-1-i.maximets@ovn.org> References: <20260921145655.3167436-1-i.maximets@ovn.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" While calling the helpers, a raw pointer to the extensions area is wired into expectations list: -> nf_ct_helper() -> helper->help() -> nf_ct_expect_related_report() -> nf_ct_expect_insert() -> hlist_add_head_rcu(&exp->lnode, &master_help->expectations) In case the connection is not confirmed yet, more extensions can be added afterwards with *_ext_add() calls reallocating the extension space and leaving the now invalid pointer in the expectations list that is later accessed while removing the expectation. Make sure that helpers are called at the end after all the other extensions are already added. Note that the helper rejection now leaves the mark and labels set, but that's not different from how the NAT was handled before or how the mark and the labels were handled on confirmation failure. And there are no atomicity guarantees provided by the API anyway. Fixes: a21b06e73191 ("net: sched: add helper support in act_ct") Cc: stable@vger.kernel.org Reported-by: Axel Mierczuk Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole Reviewed-by: Jamal Hadi Salim Reviewed-by: Xin Long --- net/sched/act_ct.c | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/net/sched/act_ct.c b/net/sched/act_ct.c index f62051ec9d57d..411e3dd92d072 100644 --- a/net/sched/act_ct.c +++ b/net/sched/act_ct.c @@ -1102,19 +1102,25 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct sk_buff *sk= b, const struct tc_action *a, } } =20 - if (nf_ct_is_confirmed(ct) ? (!cached && !skip_add) : commit) { - err =3D nf_ct_helper(skb, ct, ctinfo, family); - if (err !=3D NF_ACCEPT) - goto nf_error; - } - if (commit) { tcf_ct_act_set_mark(ct, p->mark, p->mark_mask); tcf_ct_act_set_labels(ct, p->labels, p->labels_mask); =20 if (!nf_ct_is_confirmed(ct)) nf_conn_act_ct_ext_add(skb, ct, ctinfo); + } =20 + /* Run helpers for the connection if nf_conntrack_in() was executed + * or if we're about to commit. This has to be done after all the + * extensions are already added. + */ + if (nf_ct_is_confirmed(ct) ? (!cached && !skip_add) : commit) { + err =3D nf_ct_helper(skb, ct, ctinfo, family); + if (err !=3D NF_ACCEPT) + goto nf_error; + } + + if (commit) { /* This will take care of sending queued events * even if the connection is already confirmed. */ --=20 2.55.0