From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 421443803D2; Sat, 12 Sep 2026 19:32:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789241548; cv=none; b=kAWpZRsgvZ0xJNcesLap8vFaxpcEyx6oRZ+cjPjDwPOfGGAHeTAwtG/oUfYU/f+rGI1wi9InxFQsR/A0faUjzTmgZpogPS6LpRFjwqVtUny+yI/iNpWv4SALBiWzPvTHWsoQTdzlcMpjkcYtpSo6CSEAi5lO0VZYLDt8jZnR4UI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789241548; c=relaxed/simple; bh=dAS7iACsLqNqrWiJsKruKUZfFjFAUecCn6zKc+gtMqY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=b8ZxoVZAxAaprp14ZzzxEII+8LzvYIUsTPGWjysn5hQpXAdO/dvsGWYCQs4BVB6BziA5bAyDHdAo5ZmKUqApH+UvutzvG7tccqqx+t1dvu6w15/mSOCTwG5zO/1X5a3quiH1qgZh6Ya7LsXl1/zA7Fc9gHpDotxzvWV8ExR5oqY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=PCdZ/Vg2; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="PCdZ/Vg2" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 198B41F000FF; Sat, 12 Sep 2026 19:32:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789241547; bh=aIclAUCwTaYb8GOE3gCRPrPEplMKJRQa6JLbWU/z9Mk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PCdZ/Vg2umRiYUnxiDKblxpWtMY920Iq79jH1hM4MFdHiRHmh0//5wzmmaFgKxmtC VvdEMmYdYa7B7iTW8Vd9E0ea0U6AmWyCDhixFvXMyQAPzVyMHWYsb5aPHq8GnxUcgK aKa8bpSk7aUCCMdyqYpFLBdK/o60Mp0d7oqNUPQA= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Ruoyu Wang , Ilya Maximets , Jakub Kicinski Subject: [PATCH 5.10 159/798] net: openvswitch: fix nf_connlabels leak in ovs_ct_init Date: Sat, 12 Sep 2026 08:56:27 +0200 Message-ID: <20260912065520.663336605@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260912065516.948645775@linuxfoundation.org> References: <20260912065516.948645775@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Ruoyu Wang commit f9de5db270a4c2641de87ee558c16a9bc6eb4cd8 upstream. ovs_ct_init() acquires a connlabels reference before initializing the conntrack limit state. If ovs_ct_limit_init() fails, its error is returned directly. The pernet core does not invoke the exit callback for the operation whose initialization failed, so ovs_ct_exit() cannot drop the reference. This leaves labels_used elevated when Open vSwitch pernet registration fails for an existing network namespace. Subsequent conntrack entries in that namespace may allocate label extensions even though Open vSwitch failed to register. Drop the connlabels reference before returning a conntrack limit initialization error. ovs_ct_limit_init() already releases its partial state, and the original error remains unchanged. This issue was found by a static analysis checker and confirmed by manual source review. Fixes: 11efd5cb04a1 ("openvswitch: Support conntrack zone limit") Cc: stable@vger.kernel.org Signed-off-by: Ruoyu Wang Reviewed-by: Ilya Maximets Link: https://patch.msgid.link/20260815151729.3757984-1-ruoyuw560@gmail.com Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman --- net/openvswitch/conntrack.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -2276,6 +2276,7 @@ int ovs_ct_init(struct net *net) { unsigned int n_bits = sizeof(struct ovs_key_ct_labels) * BITS_PER_BYTE; struct ovs_net *ovs_net = net_generic(net, ovs_net_id); + int err = 0; if (nf_connlabels_get(net, n_bits - 1)) { ovs_net->xt_label = false; @@ -2285,10 +2286,11 @@ int ovs_ct_init(struct net *net) } #if IS_ENABLED(CONFIG_NETFILTER_CONNCOUNT) - return ovs_ct_limit_init(net, ovs_net); -#else - return 0; + err = ovs_ct_limit_init(net, ovs_net); + if (err && ovs_net->xt_label) + nf_connlabels_put(net); #endif + return err; } void ovs_ct_exit(struct net *net)