From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6733445517D; Thu, 17 Sep 2026 15:52:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660373; cv=none; b=cDe0TAGr4+Val0EmCeVIgRjpvsEZg6YTEaCd+OwPmyugyb3wrDF0jHGpsCA0oZgwjYCImGEVTVbe3/x/lHcXKn1Kea1LSsmpPL4AF81X3aEgpAE6KkHnDU3/dqyukQeL2JkxFQp5wqMAU3yBdnCWG5c65O+VvIXdGA6kCdGnTFc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660373; c=relaxed/simple; bh=LcEt3f+ioxGMzIoghLM461i9EZee1z/VgXwpeyeaTko=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=O/BUdJ3CKyaPsFDedqxWbZePcc/8BcNBKyoMFQ3qDvqdmUdK/pQ/bwPIbJ4ZOj112aEh7TjmJdovETHsX2NDmCrdla2IIlN3wOAK35ENCHsPvBiE3PIqty1xhJ1HWOCH5bG9etPs/fZelPpAnj8KMCXfN3W5BWhCCrviQD69h2c= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=SBt9qiC+; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="SBt9qiC+" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8885C1F000FF; Thu, 17 Sep 2026 15:52:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789660372; bh=vJF733Dd8N88B4wof7BmvOvPmeDOMGiM/xMBnEHm0z0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SBt9qiC+HHBP64UT3GG/1dkG+u2lZZ/N1ZDJca02UMaePPd1YzlcAmIDCDO+gqYSA HPF9seTgXk7pP1kw4VQqGpAAYCb7Hb9iI3NJzs8AAc0I0sUx+04y1va5k6fCBoPKC4 uxHfdQGrgXr7r7D1TNeyMZ75owtO76UWcJbjjrD0= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Kyle Zeng , Julian Anastasov , Pablo Neira Ayuso Subject: [PATCH 7.2 569/733] ipvs: reject invalid states in connection template sync records Date: Thu, 17 Sep 2026 16:14:37 +0100 Message-ID: <20260917151406.525300742@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Kyle Zeng commit 74cb39735b6cd0aff4b5584158f09376fd97aadf upstream. IPVS sync receivers validate protocol states before creating or updating a connection. For connection templates, however, they only log states outside the template state range and still store the value in the connection. A template can be returned by ordinary connection lookup. TCP and SCTP then use the invalid state as an index into their transition tables. Reject invalid template states in both sync protocol versions before looking up or modifying a connection. The version 1 path handles both IPv4 and IPv6 records. Fixes: 275411430f89 ("ipvs: add assured state for conn templates") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Kyle Zeng Acked-by: Julian Anastasov Signed-off-by: Pablo Neira Ayuso Signed-off-by: Greg Kroah-Hartman --- net/netfilter/ipvs/ip_vs_sync.c | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) --- a/net/netfilter/ipvs/ip_vs_sync.c +++ b/net/netfilter/ipvs/ip_vs_sync.c @@ -999,10 +999,10 @@ static void ip_vs_process_message_v0(str pp->name, state); continue; } - } else { - if (state >= IP_VS_CTPL_S_LAST) - IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n", - state); + } else if (state >= IP_VS_CTPL_S_LAST) { + IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n", + state); + continue; } ip_vs_conn_fill_param(ipvs, AF_INET, s->protocol, @@ -1159,10 +1159,10 @@ static inline int ip_vs_proc_sync_conn(s retc = 40; goto out; } - } else { - if (state >= IP_VS_CTPL_S_LAST) - IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", - state); + } else if (state >= IP_VS_CTPL_S_LAST) { + IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", state); + retc = 40; + goto out; } if (ip_vs_conn_fill_param_sync(ipvs, af, s, ¶m, pe_data, pe_data_len, pe_name, pe_name_len)) {