All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steffen Klassert <steffen.klassert@secunet.com>
To: David Miller <davem@davemloft.net>, Jakub Kicinski <kuba@kernel.org>
Cc: Herbert Xu <herbert@gondor.apana.org.au>,
	Steffen Klassert <steffen.klassert@secunet.com>,
	<netdev@vger.kernel.org>
Subject: [PATCH 0/10] pull request (net): ipsec 2026-08-18
Date: Tue, 18 Aug 2026 11:28:31 +0200	[thread overview]
Message-ID: <20260818092920.653034-1-steffen.klassert@secunet.com> (raw)

1) xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
   Tighten the secpath-depth check so a full chain can't write
   past xvec[].

2) Add and revert "esp: do not unref managed frag pages in esp_ssg_unref()"
   The patch does not fully fully resolve the issue, a corrected version
   will follow.

3) xfrm: espintcp: fix UAF during close
   Synchronize espintcp close with the xfrm_trans_reinject work
   queue so the freed socket message isn't dereferenced again.

4) xfrm: drop ESP-in-TCP packets with no ingress device
   Drop queued ESP-in-TCP records whose saved ingress device has
   gone away, avoiding a NULL device deref in the XFRM input path.

5) xfrm: avoid lock inversion in nat keepalive work
   Split the NAT keepalive walk into a reference-collection phase
   and a per-state lock phase to break the AB-BA with state removal.
   This patch has some issues that are fixed with a followup patch.

6) xfrm: Fix skb double-free in xfrm_dev_direct_output()
   Stop freeing the skb unconditionally in xfrm_dev_direct_output(),
   letting local_out()'s result indicate when ownership has moved on.

7) xfrm: ah6: validate routing header segments_left
   Validate the segments_left/hdrlen invariant before rearranging
   the routing-header addresses, avoiding an OOB memmove on
   malformed HDRINCL packets.

8) xfrm: fix xfrm_state_construct() auth-trunc leak
   Detect an already-attached auth-trunc allocation by the pointer
   rather than inferring it from the algorithm id, so a prior
   attach isn't overwritten and lost.

9) xfrm: bound nat keepalive state collection
   Replace the per-state allocation in the NAT keepalive walk
   with a fixed-size batch that drains under BH-disabled locking
   and resumes from the cursor, bounding the worker's memory.

Please pull or let me know if there are problems.

Thanks!

The following changes since commit 3f1f755366687d051174739fb99f7d560202f60b:

  net: openvswitch: reject oversized nested action attrs (2026-07-11 13:09:11 +0200)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec.git tags/ipsec-2026-08-18

for you to fetch changes up to 4e9442ce551ebd84b52ad649df721e2dc28af95a:

  xfrm: bound nat keepalive state collection (2026-08-18 07:35:01 +0200)

----------------------------------------------------------------
ipsec-2026-08-18

----------------------------------------------------------------
Asim Viladi Oglu Manizada (1):
      xfrm: ah6: validate routing header segments_left

Maher Azzouzi (1):
      esp: do not unref managed frag pages in esp_ssg_unref()

Sabrina Dubroca (1):
      xfrm: espintcp: fix UAF during close

Sanghyun Park (1):
      xfrm: Fix skb double-free in xfrm_dev_direct_output()

Steffen Klassert (1):
      Revert "esp: do not unref managed frag pages in esp_ssg_unref()"

Xiang Mei (1):
      xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full

Zhiling Zou (1):
      xfrm: drop ESP-in-TCP packets with no ingress device

Zihan Xi (3):
      xfrm: avoid lock inversion in nat keepalive work
      xfrm: fix xfrm_state_construct() auth-trunc leak
      xfrm: bound nat keepalive state collection

 net/ipv6/ah6.c                | 29 ++++++++++++++---------
 net/ipv6/xfrm6_input.c        |  2 +-
 net/xfrm/espintcp.c           |  9 +++++++-
 net/xfrm/xfrm_nat_keepalive.c | 53 +++++++++++++++++++++++++++++++++++--------
 net/xfrm/xfrm_output.c        |  4 +---
 net/xfrm/xfrm_user.c          |  2 +-
 6 files changed, 73 insertions(+), 26 deletions(-)

             reply	other threads:[~2026-08-18  9:29 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-18  9:28 Steffen Klassert [this message]
2026-08-18  9:28 ` [PATCH 01/10] xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full Steffen Klassert
2026-08-18  9:28 ` [PATCH 02/10] esp: do not unref managed frag pages in esp_ssg_unref() Steffen Klassert
2026-08-18  9:28 ` [PATCH 03/10] xfrm: espintcp: fix UAF during close Steffen Klassert
2026-08-18  9:28 ` [PATCH 04/10] xfrm: drop ESP-in-TCP packets with no ingress device Steffen Klassert
2026-08-18  9:28 ` [PATCH 05/10] xfrm: avoid lock inversion in nat keepalive work Steffen Klassert
2026-08-18  9:28 ` [PATCH 06/10] xfrm: Fix skb double-free in xfrm_dev_direct_output() Steffen Klassert
2026-08-18  9:28 ` [PATCH 07/10] xfrm: ah6: validate routing header segments_left Steffen Klassert
2026-08-18  9:28 ` [PATCH 08/10] xfrm: fix xfrm_state_construct() auth-trunc leak Steffen Klassert
2026-08-18  9:28 ` [PATCH 09/10] Revert "esp: do not unref managed frag pages in esp_ssg_unref()" Steffen Klassert
2026-08-18  9:28 ` [PATCH 10/10] xfrm: bound nat keepalive state collection Steffen Klassert
2026-08-20 11:19 ` [PATCH 0/10] pull request (net): ipsec 2026-08-18 Paolo Abeni
2026-08-20 11:33   ` Steffen Klassert

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260818092920.653034-1-steffen.klassert@secunet.com \
    --to=steffen.klassert@secunet.com \
    --cc=davem@davemloft.net \
    --cc=herbert@gondor.apana.org.au \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.