From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 84BDD4E06D3; Wed, 30 Sep 2026 16:24:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790785497; cv=none; b=K+YlF+ZYoxxOWhew4yED6FGRXR6fAN/+thPaFRK7ejS0Z8+qD+ffJiz8agju8X96xUqtg2RbxJb9+mMnE9KWFVWHdQlFVDwL29dOeslwLwv26LUvfQ3O4bgyBNvLXaNFZDt2+yy+RSFq7aytD4l9bEKFZzWexLpMYciquA0BUJ0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790785497; c=relaxed/simple; bh=NPwvvvvUimsEI05IloY3ksjojefqiN+bXvh5dY8BKBc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=sTpwuR8NN++2Lth9Yikf5ZqZISSR/WtNHnQemxe07Sf+/HxS8a0yMBBCJxAfP3jfatP67cvJ7UxaOXtyDbKTDWAM1t7qZFlppdyoE303fvSSp9Y1Ccewkcw6d/F82JfgJL1D6dIAxKLA0HYAfSA+uI0n0w7UuPQN7TpagB7PSCA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=f6aEoioW; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="f6aEoioW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7D5291F00899; Wed, 30 Sep 2026 16:24:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790785492; bh=a5dpYHnEEM7XMUC1uH3k7wfxvD+D++kszLRmcuwrnI0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=f6aEoioWfUCiHQd6q8M4qQ61wemHszZC/7xUz++43YcQNOdzdeJntWMxAI3jGoJOR ZGqRps2jR4xHkOstg2aRC3MYvD9nIXyrrD7QnIR41W7DiwNvIfMi7hVWKBgrNPFFWa Q9b4ySUw+Jeb3jU8oTk2e2PIkJnKhApdvRphdVaE= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Kyle Zeng , Julian Anastasov , Pablo Neira Ayuso Subject: [PATCH 6.1 527/982] ipvs: reject invalid states in connection template sync records Date: Wed, 30 Sep 2026 17:21:03 +0200 Message-ID: <20260930152428.093775814@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152416.775402466@linuxfoundation.org> References: <20260930152416.775402466@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Kyle Zeng commit 74cb39735b6cd0aff4b5584158f09376fd97aadf upstream. IPVS sync receivers validate protocol states before creating or updating a connection. For connection templates, however, they only log states outside the template state range and still store the value in the connection. A template can be returned by ordinary connection lookup. TCP and SCTP then use the invalid state as an index into their transition tables. Reject invalid template states in both sync protocol versions before looking up or modifying a connection. The version 1 path handles both IPv4 and IPv6 records. Fixes: 275411430f89 ("ipvs: add assured state for conn templates") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Kyle Zeng Acked-by: Julian Anastasov Signed-off-by: Pablo Neira Ayuso Signed-off-by: Greg Kroah-Hartman --- net/netfilter/ipvs/ip_vs_sync.c | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) --- a/net/netfilter/ipvs/ip_vs_sync.c +++ b/net/netfilter/ipvs/ip_vs_sync.c @@ -1000,10 +1000,10 @@ static void ip_vs_process_message_v0(str pp->name, state); continue; } - } else { - if (state >= IP_VS_CTPL_S_LAST) - IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n", - state); + } else if (state >= IP_VS_CTPL_S_LAST) { + IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n", + state); + continue; } ip_vs_conn_fill_param(ipvs, AF_INET, s->protocol, @@ -1160,10 +1160,10 @@ static inline int ip_vs_proc_sync_conn(s retc = 40; goto out; } - } else { - if (state >= IP_VS_CTPL_S_LAST) - IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", - state); + } else if (state >= IP_VS_CTPL_S_LAST) { + IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", state); + retc = 40; + goto out; } if (ip_vs_conn_fill_param_sync(ipvs, af, s, ¶m, pe_data, pe_data_len, pe_name, pe_name_len)) {