From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E5E2D4F93D0; Wed, 30 Sep 2026 16:45:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786709; cv=none; b=YVEspOpjm/DSO3MjutIvLdzhVY17si3ll6vunx/Ugrf0/OL7SGJamVTb/xdM6U3smWlcVQinb+GMiFofF/F3X2iPZbxxczt+HuBPbNWx+Ft+GE36tbPJN8zbOfSTb1Fbpqf1RWrQPZXp4s0YOJluAwJkSw5fxgG42jELpWfGSkQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786709; c=relaxed/simple; bh=NStkWqn31vCvOxN8uKuhpoYLnp953EUn2UZJGuGMY/I=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=aWt+M6qJKJVSjNmQTc+UyKuKvoStM0uw4fEN1d22T2bQffDBtocGq9J43wDuTOdq0t2vAEVs7w0GMJjfbh8arriwkQRDh5YptivRegfW+A9ixWoEP24kkeLz6f6wryBycyUtAdYHp34XsFn6l9RT94/gC0DbyP3zAuG+Wp1luEk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=afmr3/lC; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="afmr3/lC" Received: by smtp.kernel.org (Postfix) with ESMTPSA id F0A771F000FF; Wed, 30 Sep 2026 16:45:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790786707; bh=O4ouMO6kWvxokLOUhUWdTmwMUwo57POEqCV/gK0AxXg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=afmr3/lCWA2sz7K8jiORxz/Eew+jReNFBZVij7oMv2aA8s4Q0XrObfPBRgkfUXGYA 3PZHb/RCXd5umogNlO39wJaJSCTOD/91vVne2MyvG0p0dvDnJS6MSWxJQiPe7dYEPC aSayyz1yg9e/Rsp3f6ndhFJj8yduplC3kOrg1vDk= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Axel Mierczuk , Ilya Maximets , Aaron Conole , Jakub Kicinski Subject: [PATCH 6.1 956/982] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Date: Wed, 30 Sep 2026 17:28:12 +0200 Message-ID: <20260930152437.270543817@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152416.775402466@linuxfoundation.org> References: <20260930152416.775402466@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Ilya Maximets commit 26b2bd70d22457556e2fa01cbf1192cb1a94d619 upstream. In a case where skb with an unconfirmed ct entry gets cloned, we may end up committing both but with different sets of extensions. The series of events: 1. The first clone wants to commit and runs the helpers wiring up the extension pointer into the expectation list. 2. Then it looses the confirmation keeping the entry unconfirmed. 3. Second clone now wants to commit labels and adds the new extension for that breaking the pointer in the expectation list causing UAF on the destruction path later. While this is possible to trigger, there should be no practical network pipeline where committing both clones without modifications into the same zone is needed. So, let's just reset the entry in case for some reason we got an skb with a shared one during commit. This doesn't affect any known use cases, but avoids any potential problems with sharing and modification of the unconfirmed ct entry. The fixes tag points to the introduction of helpers, since that's the main UAF trigger for the sharing. Fixes: cae3a2627520 ("openvswitch: Allow attaching helpers to ct action") Cc: stable@vger.kernel.org Reported-by: Axel Mierczuk Signed-off-by: Ilya Maximets Reviewed-by: Aaron Conole Link: https://patch.msgid.link/20260921145655.3167436-2-i.maximets@ovn.org Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman --- include/net/netfilter/nf_conntrack.h | 5 +++++ net/openvswitch/conntrack.c | 12 ++++++++++++ 2 files changed, 17 insertions(+) --- a/include/net/netfilter/nf_conntrack.h +++ b/include/net/netfilter/nf_conntrack.h @@ -194,6 +194,11 @@ static inline void nf_ct_put(struct nf_c int nf_ct_l3proto_try_module_get(unsigned short l3proto); void nf_ct_l3proto_module_put(unsigned short l3proto); +static inline bool nf_ct_shared(const struct nf_conn *ct) +{ + return refcount_read(&ct->ct_general.use) > 1; +} + /* load module; enable/disable conntrack in this namespace */ int nf_ct_netns_get(struct net *net, u8 nfproto); void nf_ct_netns_put(struct net *net, u8 nfproto); --- a/net/openvswitch/conntrack.c +++ b/net/openvswitch/conntrack.c @@ -970,6 +970,18 @@ static int __ovs_ct_lookup(struct net *n enum ip_conntrack_info ctinfo; struct nf_conn *ct; + /* If the ct entry is not confirmed and shared with some other skb, + * e.g., a cloned one, we can't just modify it with the commit as we + * must not modify the extension set. Reset. + */ + if (cached && info->commit) { + ct = nf_ct_get(skb, &ctinfo); + if (ct && !nf_ct_is_confirmed(ct) && nf_ct_shared(ct)) { + nf_reset_ct(skb); + cached = false; + } + } + if (!cached) { struct nf_hook_state state = { .hook = NF_INET_PRE_ROUTING,