* [PATCH] ipvs: reject invalid states in connection template sync records
@ 2026-08-10 22:10 Kyle Zeng
2026-08-11 17:10 ` Julian Anastasov
0 siblings, 1 reply; 2+ messages in thread
From: Kyle Zeng @ 2026-08-10 22:10 UTC (permalink / raw)
To: netdev
Cc: Simon Horman, Julian Anastasov, Pablo Neira Ayuso,
Florian Westphal, Phil Sutter, David S. Miller, linux-kernel,
Kyle Zeng, stable
IPVS sync receivers validate protocol states before creating or updating a
connection. For connection templates, however, they only log states outside
the template state range and still store the value in the connection.
A template can be returned by ordinary connection lookup. TCP and SCTP then
use the invalid state as an index into their transition tables.
Reject invalid template states in both sync protocol versions before
looking up or modifying a connection. The version 1 path handles both
IPv4 and IPv6 records.
Fixes: 275411430f89 ("ipvs: add assured state for conn templates")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Kyle Zeng <kylebot@openai.com>
diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c
index 93038ab..6f0c2a4 100644
--- a/net/netfilter/ipvs/ip_vs_sync.c
+++ b/net/netfilter/ipvs/ip_vs_sync.c
@@ -1002,10 +1002,10 @@ static void ip_vs_process_message_v0(struct netns_ipvs *ipvs, const char *buffer
pp->name, state);
continue;
}
- } else {
- if (state >= IP_VS_CTPL_S_LAST)
- IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
- state);
+ } else if (state >= IP_VS_CTPL_S_LAST) {
+ IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
+ state);
+ continue;
}
ip_vs_conn_fill_param(ipvs, AF_INET, s->protocol,
@@ -1162,10 +1162,10 @@ static inline int ip_vs_proc_sync_conn(struct netns_ipvs *ipvs, __u8 *p, __u8 *m
retc = 40;
goto out;
}
- } else {
- if (state >= IP_VS_CTPL_S_LAST)
- IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n",
- state);
+ } else if (state >= IP_VS_CTPL_S_LAST) {
+ IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", state);
+ retc = 40;
+ goto out;
}
if (ip_vs_conn_fill_param_sync(ipvs, af, s, ¶m, pe_data,
pe_data_len, pe_name, pe_name_len)) {
--
2.53.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] ipvs: reject invalid states in connection template sync records
2026-08-10 22:10 [PATCH] ipvs: reject invalid states in connection template sync records Kyle Zeng
@ 2026-08-11 17:10 ` Julian Anastasov
0 siblings, 0 replies; 2+ messages in thread
From: Julian Anastasov @ 2026-08-11 17:10 UTC (permalink / raw)
To: Kyle Zeng
Cc: netdev, Simon Horman, Pablo Neira Ayuso, Florian Westphal,
Phil Sutter, David S. Miller, linux-kernel, stable, lvs-devel,
netfilter-devel
Hello,
On Mon, 10 Aug 2026, Kyle Zeng wrote:
> IPVS sync receivers validate protocol states before creating or updating a
> connection. For connection templates, however, they only log states outside
> the template state range and still store the value in the connection.
>
> A template can be returned by ordinary connection lookup. TCP and SCTP then
> use the invalid state as an index into their transition tables.
I guess, this is possible again due to sync. I'll
provide fix for this problem.
>
> Reject invalid template states in both sync protocol versions before
> looking up or modifying a connection. The version 1 path handles both
> IPv4 and IPv6 records.
>
> Fixes: 275411430f89 ("ipvs: add assured state for conn templates")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Kyle Zeng <kylebot@openai.com>
Looks good to me for the nf tree, thanks! Next time use
"nf" or "nf-next" tags for IPVS patches.
Acked-by: Julian Anastasov <ja@ssi.bg>
>
> diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c
> index 93038ab..6f0c2a4 100644
> --- a/net/netfilter/ipvs/ip_vs_sync.c
> +++ b/net/netfilter/ipvs/ip_vs_sync.c
> @@ -1002,10 +1002,10 @@ static void ip_vs_process_message_v0(struct netns_ipvs *ipvs, const char *buffer
> pp->name, state);
> continue;
> }
> - } else {
> - if (state >= IP_VS_CTPL_S_LAST)
> - IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
> - state);
> + } else if (state >= IP_VS_CTPL_S_LAST) {
> + IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
> + state);
> + continue;
> }
>
> ip_vs_conn_fill_param(ipvs, AF_INET, s->protocol,
> @@ -1162,10 +1162,10 @@ static inline int ip_vs_proc_sync_conn(struct netns_ipvs *ipvs, __u8 *p, __u8 *m
> retc = 40;
> goto out;
> }
> - } else {
> - if (state >= IP_VS_CTPL_S_LAST)
> - IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n",
> - state);
> + } else if (state >= IP_VS_CTPL_S_LAST) {
> + IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", state);
> + retc = 40;
> + goto out;
> }
> if (ip_vs_conn_fill_param_sync(ipvs, af, s, ¶m, pe_data,
> pe_data_len, pe_name, pe_name_len)) {
> --
> 2.53.0
Regards
--
Julian Anastasov <ja@ssi.bg>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-11 17:10 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 22:10 [PATCH] ipvs: reject invalid states in connection template sync records Kyle Zeng
2026-08-11 17:10 ` Julian Anastasov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox