From: Steffen Klassert <steffen.klassert@secunet.com>
To: Paolo Abeni <pabeni@redhat.com>
Cc: David Miller <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>,
Herbert Xu <herbert@gondor.apana.org.au>,
<netdev@vger.kernel.org>
Subject: Re: [PATCH 0/10] pull request (net): ipsec 2026-08-18
Date: Thu, 20 Aug 2026 13:33:08 +0200 [thread overview]
Message-ID: <aobl9LSwwUNOhMI5@secunet.com> (raw)
In-Reply-To: <7c5a9d55-a15b-4235-a308-cc6f65ce2de9@redhat.com>
Hi Paolo,
On Thu, Aug 20, 2026 at 01:19:19PM +0200, Paolo Abeni wrote:
> Hi Steffen!
>
> On 8/18/26 11:28 AM, Steffen Klassert wrote:
> > 1) xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
> > Tighten the secpath-depth check so a full chain can't write
> > past xvec[].
> >
> > 2) Add and revert "esp: do not unref managed frag pages in esp_ssg_unref()"
> > The patch does not fully fully resolve the issue, a corrected version
> > will follow.
> >
> > 3) xfrm: espintcp: fix UAF during close
> > Synchronize espintcp close with the xfrm_trans_reinject work
> > queue so the freed socket message isn't dereferenced again.
> >
> > 4) xfrm: drop ESP-in-TCP packets with no ingress device
> > Drop queued ESP-in-TCP records whose saved ingress device has
> > gone away, avoiding a NULL device deref in the XFRM input path.
> >
> > 5) xfrm: avoid lock inversion in nat keepalive work
> > Split the NAT keepalive walk into a reference-collection phase
> > and a per-state lock phase to break the AB-BA with state removal.
> > This patch has some issues that are fixed with a followup patch.
> >
> > 6) xfrm: Fix skb double-free in xfrm_dev_direct_output()
> > Stop freeing the skb unconditionally in xfrm_dev_direct_output(),
> > letting local_out()'s result indicate when ownership has moved on.
> >
> > 7) xfrm: ah6: validate routing header segments_left
> > Validate the segments_left/hdrlen invariant before rearranging
> > the routing-header addresses, avoiding an OOB memmove on
> > malformed HDRINCL packets.
> >
> > 8) xfrm: fix xfrm_state_construct() auth-trunc leak
> > Detect an already-attached auth-trunc allocation by the pointer
> > rather than inferring it from the algorithm id, so a prior
> > attach isn't overwritten and lost.
> >
> > 9) xfrm: bound nat keepalive state collection
> > Replace the per-state allocation in the NAT keepalive walk
> > with a fixed-size batch that drains under BH-disabled locking
> > and resumes from the cursor, bounding the worker's memory.
> >
> > Please pull or let me know if there are problems.
> Sashiko has a few comments:
>
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260818092920.653034-1-steffen.klassert%40secunet.com
>
> do you think they deserve a v2 or could be handled as follow-ups?
These are already addressed in the pull request. Patch 2 is reverted
and patch 5 has a followup fix (patch 10).
>
> Also the fixes tag in patch 10/10 looks invalid. Possibly a rebase
> would be needed?
The fixes tag referes to a commit in the ipsec tee (patch 5),
so I think it is valid.
Steffen
prev parent reply other threads:[~2026-08-20 11:33 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-18 9:28 [PATCH 0/10] pull request (net): ipsec 2026-08-18 Steffen Klassert
2026-08-18 9:28 ` [PATCH 01/10] xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full Steffen Klassert
2026-08-18 9:28 ` [PATCH 02/10] esp: do not unref managed frag pages in esp_ssg_unref() Steffen Klassert
2026-08-18 9:28 ` [PATCH 03/10] xfrm: espintcp: fix UAF during close Steffen Klassert
2026-08-18 9:28 ` [PATCH 04/10] xfrm: drop ESP-in-TCP packets with no ingress device Steffen Klassert
2026-08-18 9:28 ` [PATCH 05/10] xfrm: avoid lock inversion in nat keepalive work Steffen Klassert
2026-08-18 9:28 ` [PATCH 06/10] xfrm: Fix skb double-free in xfrm_dev_direct_output() Steffen Klassert
2026-08-18 9:28 ` [PATCH 07/10] xfrm: ah6: validate routing header segments_left Steffen Klassert
2026-08-18 9:28 ` [PATCH 08/10] xfrm: fix xfrm_state_construct() auth-trunc leak Steffen Klassert
2026-08-18 9:28 ` [PATCH 09/10] Revert "esp: do not unref managed frag pages in esp_ssg_unref()" Steffen Klassert
2026-08-18 9:28 ` [PATCH 10/10] xfrm: bound nat keepalive state collection Steffen Klassert
2026-08-20 11:19 ` [PATCH 0/10] pull request (net): ipsec 2026-08-18 Paolo Abeni
2026-08-20 11:33 ` Steffen Klassert [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aobl9LSwwUNOhMI5@secunet.com \
--to=steffen.klassert@secunet.com \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.