From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4D7A738DC66; Wed, 30 Sep 2026 18:14:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790792065; cv=none; b=Dgc2CSJ1YoGox4tpIJf9/POcgDlTwC5Pl9lZH25KACqUhXhXV55M17bJxVdgNeAZI7NIU2Ve2kyDX8Z+SoGM6DJf/DVN5q8KO4PCkzRTTeIF3TxwuVnDEEcJebNIqpFc87YSryCw6Es270RfZeX6F5IdWBcwGM63KonWysaW59U= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790792065; c=relaxed/simple; bh=xYVCg/8Efse6u/vQJKpwmIuY6AOF9tPjc357K3iS0qY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jK9vA6hW+ZMKDXOVoeNMWl39ZN229PoKtLmyPADEyvXcz+MbOBo5vBRe3/esJ3SZVYwuOQegmD6yASmg0F+YHcFIREMbeAPCiRUgPyZ2+5HAGkyJc8RRm7b7xAmwSGDwDWwMXtmmE+ShR08n53q7aKJk8ZIbouCakjlB7xllIw4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=RDy6xC6m; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="RDy6xC6m" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A601D1F000FF; Wed, 30 Sep 2026 18:14:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790792064; bh=HC/C8+J2Q96P6k3I3Z06yfuUkKGDkyHCxeYgyYG5CHQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RDy6xC6mqB/GYQQYx3hD8CJSNzupcaVicwxlUulKIvg+r+J3tWh7Tq2I5qwx5b/Gf 6zen5QK+UuQ0y3ua81KZK14/0Pd4YV3DnGvMhxBt7zt3ZBfr0+Z5FapBfp1Cdg8+Wg CeDGaSWXGB382ArlJAfER9FbtQI+MArmSAyi84YA= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Vega , Zhiling Zou , Ilya Maximets , Aaron Conole , Jakub Kicinski Subject: [PATCH 5.15 524/752] openvswitch: avoid reallocating confirmed conntrack labels Date: Wed, 30 Sep 2026 17:26:34 +0200 Message-ID: <20260930152409.594356794@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152358.131179731@linuxfoundation.org> References: <20260930152358.131179731@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.15-stable review patch. If anyone has any objections, please let me know. ------------------ From: Zhiling Zou commit 3f118c8217c109fd13ca61caa301d72c483897ef upstream. ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it. Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage. Fixes: c2ac66735870 ("openvswitch: Allow matching on conntrack label") Cc: stable@vger.kernel.org Reported-by: Vega Signed-off-by: Zhiling Zou Reviewed-by: Ilya Maximets Reviewed-by: Aaron Conole Link: https://patch.msgid.link/372fbb062b40ae6723684f55484be86ff0064f8e.1789218015.git.zhilinz@nebusec.ai Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman --- net/openvswitch/conntrack.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -357,7 +357,7 @@ static struct nf_conn_labels *ovs_ct_get struct nf_conn_labels *cl; cl = nf_ct_labels_find(ct); - if (!cl) { + if (!cl && !nf_ct_is_confirmed(ct)) { nf_ct_labels_ext_add(ct); cl = nf_ct_labels_find(ct); }