All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH net,v2 0/4] Netfilter fixes for net
@ 2026-09-11 11:21 Pablo Neira Ayuso
  2026-09-11 11:21 ` [PATCH net 1/4] netfilter: nft_nat: fully initialise new_addr in netmap setup Pablo Neira Ayuso
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-11 11:21 UTC (permalink / raw)
  To: netfilter-devel

v2: - reword the commit description of the nf_nat_register_fn() to
      explicitly refer to the memleak, so LLM does not get confused.
    - drop the xt_IDLETIMER and module = THIS_MODULE in netlink_dump.
    - keep back IPVS fix as Julian prefer to send a v2. 
-o-

Hi,

The following patchset contains Netfilter fixes for net:

1) Fix KMSAN reports an uninit-value in nf_nat_setup_info() for netmap,
   from Theodor Arsenij Larionov Trichkine.
 
2) Restrict deletion of netdevice in basechain and flowtable to exact
   matching only, from Fernando F. Mancera.
 
3) Fix nf_nat_register_fn() error path allowing for a memleak.
 
4) Hold reference on ct until flow is released to address, otherwise
   access to release ct->ext or different ct due to typesafe RCU
   semantics.
 
Please, pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-26-09-11

Thanks.

----------------------------------------------------------------

The following changes since commit 78445023439506ebd83b86d40b1e428a3b309d4a:

  Merge tag 'net-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net (2026-09-10 14:07:48 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-26-09-11

for you to fetch changes up to e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d:

  netfilter: flowtable: hold reference on ct until flow is released (2026-09-11 13:04:15 +0200)

----------------------------------------------------------------
netfilter pull request 26-09-11

----------------------------------------------------------------
Fernando Fernandez Mancera (1):
      netfilter: nf_tables: fix device name and prefix match in hook lookup

Pablo Neira Ayuso (2):
      netfilter: nf_nat: unregister and release hooks on error
      netfilter: flowtable: hold reference on ct until flow is released

Theodor Arsenij Larionov Trichkine (1):
      netfilter: nft_nat: fully initialise new_addr in netmap setup

 net/netfilter/nf_flow_table_core.c | 12 ++++++++--
 net/netfilter/nf_nat_core.c        | 46 +++++++++++++++++++++++++-------------
 net/netfilter/nf_tables_api.c      | 22 ++++++++++--------
 net/netfilter/nft_nat.c            |  2 +-
 4 files changed, 54 insertions(+), 28 deletions(-)

^ permalink raw reply	[flat|nested] 8+ messages in thread
* [PATCH net,v2 0/4] Netfilter fixes for net
@ 2024-11-28 12:38 Pablo Neira Ayuso
  2024-11-28 14:33 ` Paolo Abeni
  0 siblings, 1 reply; 8+ messages in thread
From: Pablo Neira Ayuso @ 2024-11-28 12:38 UTC (permalink / raw)
  To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, fw

v2: Amended missing Fixes: tag in patch #4.

-o-

Hi,

The following patchset contains Netfilter fixes for net:

1) Fix esoteric UB due to uninitialized stack access in ip_vs_protocol_init(),
   from Jinghao Jia.

2) Fix iptables xt_LED slab-out-of-bounds, reported by syzbot,
   patch from Dmitry Antipov.

3) Remove WARN_ON_ONCE reachable from userspace to cap maximum cgroup
   levels to 255, reported by syzbot.

4) Fix nft_inner incorrect use of percpu area to store tunnel parser
   context with softirqs, reported by syzbot.

Please, pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-24-11-28

Thanks.

----------------------------------------------------------------

The following changes since commit 04f5cb48995d51deed0af71aaba1b8699511313f:

  Documentation: tls_offload: fix typos and grammar (2024-11-28 12:09:06 +0100)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git tags/nf-24-11-28

for you to fetch changes up to e4e12f81c14c8c0c5a2920587ad2619abf1b8e30:

  netfilter: nft_inner: incorrect percpu area handling under softirq (2024-11-28 13:32:17 +0100)

----------------------------------------------------------------
netfilter pull request 24-11-28

----------------------------------------------------------------
Dmitry Antipov (1):
      netfilter: x_tables: fix LED ID check in led_tg_check()

Jinghao Jia (1):
      ipvs: fix UB due to uninitialized stack access in ip_vs_protocol_init()

Pablo Neira Ayuso (2):
      netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level
      netfilter: nft_inner: incorrect percpu area handling under softirq

 include/net/netfilter/nf_tables_core.h |  1 +
 net/netfilter/ipvs/ip_vs_proto.c       |  4 +--
 net/netfilter/nft_inner.c              | 56 ++++++++++++++++++++++++++--------
 net/netfilter/nft_socket.c             |  2 +-
 net/netfilter/xt_LED.c                 |  4 ++-
 5 files changed, 50 insertions(+), 17 deletions(-)

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-11 11:21 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 11:21 [PATCH net,v2 0/4] Netfilter fixes for net Pablo Neira Ayuso
2026-09-11 11:21 ` [PATCH net 1/4] netfilter: nft_nat: fully initialise new_addr in netmap setup Pablo Neira Ayuso
2026-09-11 11:21 ` [PATCH net 2/4] netfilter: nf_tables: fix device name and prefix match in hook lookup Pablo Neira Ayuso
2026-09-11 11:21 ` [PATCH net 3/4] netfilter: nf_nat: unregister and release hooks on error Pablo Neira Ayuso
2026-09-11 11:21 ` [PATCH net 4/4] netfilter: flowtable: hold reference on ct until flow is released Pablo Neira Ayuso
  -- strict thread matches above, loose matches on Subject: below --
2024-11-28 12:38 [PATCH net,v2 0/4] Netfilter fixes for net Pablo Neira Ayuso
2024-11-28 14:33 ` Paolo Abeni
2024-11-28 14:41   ` Pablo Neira Ayuso

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.