From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 03CB35172E0; Wed, 30 Sep 2026 17:02:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790787753; cv=none; b=YjgD+LjrqtB9cMvo/o+jQcyPy3gwxRYC1PdzKECcG6sy51sFWnXrZrDhDR0wcPFRMdur4pACv+1NSRMb4rKOGejArFVLTyMROp+kr1eWW88sm4LY3CkbQBidpDMRTKhNVp181zvnxQQ5EvF5wV4KYsqwJ54f3Dg3w1Lhtst95D8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790787753; c=relaxed/simple; bh=jJtcv80MngCUvN4b7jIHur6hVsza9oZuuEvurWYVPsg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gO3ywtRUhxWNtciVcXcab42eRF/htRpv0A2IWRY18GiZLYqtTn5bLt9gxdnxNSbzPvR/cJv0bP58wVsoHIGroX2n7IgPCOwsmCAavYstlTeFwGzXq6dAA6QhEpDHY0uXrFvr668nscKCQzSXVSXwETdBDEZ9vDd0kRsHqw15EQY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=zC68Z1Wg; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="zC68Z1Wg" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5C1611F000FF; Wed, 30 Sep 2026 17:02:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790787751; bh=g1yWFlKt9Ml/o1Mk8JEUuIipP2lZTSDxfK/CjqWlgdY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=zC68Z1WgXvOUpLh6tDfagWO7TI1KMcoP7MBC4XQTkc0k5bIE1BCO/vHvjBqCqhZyx Se4Z5QM5iVUAK1BKAX4VkKiwwN+bWGadO6+ek2EyIwiaDeE9ybIOP3roTji2q7NAVk 9KRlBhJjq+Xlp8qdJQgqDAafy/IL45WfHOpA0B+0= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Axel Mierczuk , Ilya Maximets , Aaron Conole , Jakub Kicinski Subject: [PATCH 7.2 339/457] net: openvswitch: conntrack: fix helper UAF due to extensions realloc Date: Wed, 30 Sep 2026 17:27:24 +0200 Message-ID: <20260930152353.330573876@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152346.024115587@linuxfoundation.org> References: <20260930152346.024115587@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Ilya Maximets commit 1a4151e6be57b098b7a5ebfbde58585e83200cdc upstream. While calling the helpers, a raw pointer to the extensions area is wired into expectations list: -> nf_ct_helper() -> helper->help() -> nf_ct_expect_related_report() -> nf_ct_expect_insert() -> hlist_add_head_rcu(&exp->lnode, &master_help->expectations) In case the connection is not confirmed yet, more extensions can be added afterwards with *_ext_add() calls reallocating the extension space and leaving the now invalid pointer in the expectations list that is later accessed while removing the expectation. Make sure that helpers are called at the end after all the other extensions are already added. Note that the helper rejection now leaves the mark and labels set, but that's not different from how the NAT was handled before or how the mark and the labels were handled on confirmation failure. And there are no atomicity guarantees provided by the API anyway. Fixes: cae3a2627520 ("openvswitch: Allow attaching helpers to ct action") Cc: stable@vger.kernel.org Reported-by: Axel Mierczuk Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole Link: https://patch.msgid.link/20260921145655.3167436-4-i.maximets@ovn.org Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman --- net/openvswitch/conntrack.c | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -818,11 +818,14 @@ static int __ovs_ct_lookup(struct net *n } } - /* Call the helper only if: - * - nf_conntrack_in() was executed above ("!cached"), or - * - When committing an unconfirmed connection. + /* Call the helper only if nf_conntrack_in() was executed + * above ("!cached"). + * + * For unconfirmed connections it will be called later during + * commit as we need to have all the other extensions allocated + * before the call. */ - if ((nf_ct_is_confirmed(ct) ? !cached : info->commit)) { + if (nf_ct_is_confirmed(ct) && !cached) { int err = nf_ct_helper(skb, ct, ctinfo, info->family); err = verdict_to_errno(err); @@ -1026,6 +1029,14 @@ static int ovs_ct_commit(struct net *net return err; nf_conn_act_ct_ext_add(skb, ct, ctinfo); + + /* Call the helpers now. We couldn't do this before as + * all the extensions must be allocated before the call. + */ + err = nf_ct_helper(skb, ct, ctinfo, info->family); + err = verdict_to_errno(err); + if (err) + return err; } else if (IS_ENABLED(CONFIG_NF_CONNTRACK_LABELS) && labels_nonzero(&info->labels.mask)) { err = ovs_ct_set_labels(ct, key, &info->labels.value,