From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B78B9340260; Wed, 30 Sep 2026 17:16:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788581; cv=none; b=krRB/ZkrV8UhLvQDwNd1+NT311OyBscWaysFRDNiDWN7GJgyS/3+OPgJFcwiNJkx9ZlZgWRo7RZLPye09IxZxDWp8mzCF23y94SIgLpy7itFz+VwMqsMV5OlPXp1Fux6iv/1xGzELdRK3J5Ojxvo5Iyd6e3RZuUYGTamA9JS6Ok= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788581; c=relaxed/simple; bh=X6OGBTAjlrOZ5+GAeZ/e7APdBCd8OGysJ+C2jVFdx4w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=TbHPLrDvgQIxywIXNjTQSdh9kb/D/jmVPsO2HzkDWskVe2VBsIgIvhOVESuzHIGPYL5BVTr6TK8Xk46yIlZtD0w5wvtWfMcE+yW+Y/O+9gtvNLQtDoPK423PIds6irRMDid+EBYkqovofi8gJTIzCVTnuHzWnp/atA9Vcvkb+kc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=C7ag5cPG; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="C7ag5cPG" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 1588D1F000FF; Wed, 30 Sep 2026 17:16:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788580; bh=Ya6r0Pmxyfxz3+MU4sNZi3++78YhaazkG9okf6dPA7M=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=C7ag5cPGPo8+j4sjcoumTW+hFcYcYKAwQe5hOJswUBMnTjZm/3o2mvuwallb0hjBR ZMaPQF0Y7FJo0hqacDCV1hMa4mMerJlQys4VJtzKXjR3TxUlD7VKUsDl1NfR/PVPLw IByTDGaDZoJtZpr8YMzayPH9NQf7/SfNWGNLANOA= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Vega , Zhiling Zou , Ilya Maximets , Aaron Conole , Jakub Kicinski Subject: [PATCH 6.12 176/877] openvswitch: avoid reallocating confirmed conntrack labels Date: Wed, 30 Sep 2026 17:18:07 +0200 Message-ID: <20260930152418.527465295@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Zhiling Zou commit 3f118c8217c109fd13ca61caa301d72c483897ef upstream. ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it. Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage. Fixes: c2ac66735870 ("openvswitch: Allow matching on conntrack label") Cc: stable@vger.kernel.org Reported-by: Vega Signed-off-by: Zhiling Zou Reviewed-by: Ilya Maximets Reviewed-by: Aaron Conole Link: https://patch.msgid.link/372fbb062b40ae6723684f55484be86ff0064f8e.1789218015.git.zhilinz@nebusec.ai Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman --- net/openvswitch/conntrack.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -366,7 +366,7 @@ static struct nf_conn_labels *ovs_ct_get struct nf_conn_labels *cl; cl = nf_ct_labels_find(ct); - if (!cl) { + if (!cl && !nf_ct_is_confirmed(ct)) { nf_ct_labels_ext_add(ct); cl = nf_ct_labels_find(ct); }