From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 90AE24F68B0; Wed, 30 Sep 2026 15:42:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790782944; cv=none; b=gB7cPNbdfzJBy1XhDtrWWiNZF7TGrsuo5ucS2LFhUnUsmUjmwrTYEi+YVEtM5fCzK8pLYnrXI4fiXJpkDEdBCpqrUX5kF5RTD0HBMX5TRSVEPBpXI1dz9fxgxJlNE5rU2PxPb5VEu4l4jVL0cWUIAKgjQsp1gNlQyIKUIAYlJAg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790782944; c=relaxed/simple; bh=sI6m1eL09AbxWqHqAXJ9RCsV/GVtukuPKzHYuBEmBJU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fixg9keNpWfCI/QMGb1hyEtzqVQikVaZUDP95o9e0A1NQ8bksH3V8gDbchqaEsoALoTebSFhGNLxoZrI8LNI+aRj7Ksm1BYh0k/wkQ42NS749cRhFDlmgtmPtp9PcBdn4veMPfv71iUrCQ3J/qhAis3rsax4RB1/ww/H2iCHhww= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=TEUsr31r; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="TEUsr31r" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C8A061F000FF; Wed, 30 Sep 2026 15:42:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790782939; bh=NxF/mQP8aNOcGwMDogOgx9p/UWJUkPkOvXnHeoDa9Us=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TEUsr31rc6uL56ACZW0rCJBmqY2tX6Dlq5yh3AAHp7HhvSvj50K2RhgZ1kVAK1iPv 6lh1sbX+4NrN0ySS23lWYoCyCx2zWCZhbUAO3xXEfF4McoJU0wk1VvA7eBolysjLML zrHvt3Pgd7PNaMlFwxzflou+eklE+nfRn86MX9/Y= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Kyle Zeng , Julian Anastasov , Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 5.10 224/595] ipvs: fix reversed sequence option serialization Date: Wed, 30 Sep 2026 17:21:57 +0200 Message-ID: <20260930152352.545643212@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152347.700140858@linuxfoundation.org> References: <20260930152347.700140858@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Kyle Zeng [ Upstream commit b04578b74f2d3755548fe9e829e3b2a6c6f966a1 ] hton_seq() expects the host-order source first and the unaligned network-order destination second. The version 1 sync sender passes these arguments in reverse for both sequence blocks. This leaves 24 bytes of the kmalloc-backed message unwritten. It may disclose stale heap data and replace the live connection sequence state with values read from the buffer. Pass the connection sequence state as the source and the message payload as the destination for both blocks. Fixes: 986a07579533 ("IPVS: Backup, Change sending to Version 1 format") Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Kyle Zeng Acked-by: Julian Anastasov Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/netfilter/ipvs/ip_vs_sync.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c index 04ae99aacb853..bde57749a3fc5 100644 --- a/net/netfilter/ipvs/ip_vs_sync.c +++ b/net/netfilter/ipvs/ip_vs_sync.c @@ -748,9 +748,9 @@ void ip_vs_sync_conn(struct netns_ipvs *ipvs, struct ip_vs_conn *cp, int pkts) if (cp->flags & IP_VS_CONN_F_SEQ_MASK) { *(p++) = IPVS_OPT_SEQ_DATA; *(p++) = sizeof(struct ip_vs_sync_conn_options); - hton_seq((struct ip_vs_seq *)p, &cp->in_seq); + hton_seq(&cp->in_seq, (struct ip_vs_seq *)p); p += sizeof(struct ip_vs_seq); - hton_seq((struct ip_vs_seq *)p, &cp->out_seq); + hton_seq(&cp->out_seq, (struct ip_vs_seq *)p); p += sizeof(struct ip_vs_seq); } /* Handle pe data */ -- 2.53.0