From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 70D0F3CF688; Wed, 30 Sep 2026 17:12:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788332; cv=none; b=fmx86JIdt1BVP70v7tLxvs60jy7DBd9iy9jdwps/pZiAHMh3hlmfcBoi72ZUKEA+ZNwGT+qAa7+goLbrlkl1nSD2YBrhll2DZDt8dwqPacHTHlw/eATb5lkMNdbtOYtNkbEuR2OPPwKJ1evWh7pISE+8ucHfk8u2a/smlw93/b4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788332; c=relaxed/simple; bh=DIGPcmLd+to0yG+t0FRlak50sbKocT4AzOpnTbaW+8c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HHd7NiLue6WFQqRX8+aGAzixsTfnh8FWs0SR9UUmwgn5lOdWJ9MMOS99wvGyf/nSe2Q/lsAdNZIMPcA4jXYy6+RdtKF+JxOvroijBeuy8JfUFTg20XTJd0eAx5mmiHmT8GigV6Q2uZ2vEqXoNC2HHh7stFuZRaDhcXy0f5JQvDE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=qakP8Ar+; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="qakP8Ar+" Received: by smtp.kernel.org (Postfix) with ESMTPSA id AAEFD1F000FF; Wed, 30 Sep 2026 17:12:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788331; bh=P+azkoHNX2WmRh7cUA+RJt5xr4+7K923sDtnV/WaHiE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qakP8Ar+r8JF9f5Rcy90DgnyiiRjlMF4X19whQgfUXu/GblkMoZpviexvcKpAeJD5 8H3HFdOUQJojfSXi5Om1R6EsRm4ENt80qn+4frjSzIyWlc+Pf8CjkL/qeQC4iG4sXQ K/lDD2Vc30bSrYTHs4HyRguGwlJ8MWXflu63/wnc= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 6.12 087/877] netfilter: flowtable: hold reference on ct until flow is released Date: Wed, 30 Sep 2026 17:16:38 +0200 Message-ID: <20260930152416.617597202@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Pablo Neira Ayuso [ Upstream commit e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d ] nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe semantics also allow to refer to the wrong conntrack from the flowtable datapath. Hold reference on ct until flow is released after rcu grace period. Add rcu_barrier() on module exit path, to ensure pending flow entries are release before module goes away. Fixes: 0ff90b6c2034 ("netfilter: nf_flow_offload: fix use-after-free and a resource leak") Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/netfilter/nf_flow_table_core.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c index b9e3ac950894f..b00f1c68a8e76 100644 --- a/net/netfilter/nf_flow_table_core.c +++ b/net/netfilter/nf_flow_table_core.c @@ -205,6 +205,14 @@ static void flow_offload_route_release(struct flow_offload *flow) nft_flow_dst_release(flow, FLOW_OFFLOAD_DIR_REPLY); } +static void flow_offload_free_rcu(struct rcu_head *rcu_head) +{ + struct flow_offload *flow = container_of(rcu_head, struct flow_offload, rcu_head); + + nf_ct_put(flow->ct); + kfree(flow); +} + void flow_offload_free(struct flow_offload *flow) { switch (flow->type) { @@ -214,8 +222,7 @@ void flow_offload_free(struct flow_offload *flow) default: break; } - nf_ct_put(flow->ct); - kfree_rcu(flow, rcu_head); + call_rcu(&flow->rcu_head, flow_offload_free_rcu); } EXPORT_SYMBOL_GPL(flow_offload_free); @@ -686,6 +693,7 @@ static int __init nf_flow_table_module_init(void) static void __exit nf_flow_table_module_exit(void) { + rcu_barrier(); nf_flow_table_offload_exit(); unregister_pernet_subsys(&nf_flow_table_net_ops); } -- 2.53.0