From: Daehyeon Ko <4ncienth@gmail.com>
To: pablo@netfilter.org, fw@strlen.de
Cc: phil@nwl.cc, netfilter-devel@vger.kernel.org,
coreteam@netfilter.org, netdev@vger.kernel.org,
stable@vger.kernel.org, 4ncienth@gmail.com
Subject: [PATCH v2 net] netfilter: conntrack: reject nested ctnetlink master chains
Date: Sat, 3 Oct 2026 01:56:01 +0900 [thread overview]
Message-ID: <20261002165601.1754467-1-4ncienth@gmail.com> (raw)
In-Reply-To: <20261001180224.1018290-1-4ncienth@gmail.com>
Conntracks created through ctnetlink can reference another conntrack as
their master. Userspace can repeat this to build an unbounded chain whose
recursive destruction exhausts the kernel stack.
Stop the repeatable userspace paths. Reject a direct master that already
has a master, and reject NFQUEUE-attached expectations for such conntracks.
Keep regular ctnetlink and kernel helper expectations unchanged.
Fixes: 5faa1f4cb5a1 ("[NETFILTER]: nf_conntrack_netlink: add support to related connections")
Cc: stable@vger.kernel.org
Suggested-by: Florian Westphal <fw@strlen.de>
Suggested-by: Pablo Neira Ayuso <pablo@netfilter.org>
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
Changes in v2:
- Replace iterative destruction with the maintainer-requested creation-time
restrictions.
- Reject nested NFQUEUE-attached expectations while preserving regular
ctnetlink and kernel helper expectations.
Tested on net 71a77ab76e74 and exact v6.12.105. In both userns runs a
one-level master was accepted, 5,998 nested direct attempts returned
EOPNOTSUPP, and cleanup ended with nf_conntrack_count=0 without a crash.
A policy control also confirmed that terminal IPCTNL_MSG_EXP_NEW remains
accepted on a related master. A real iptables NFQUEUE/NFQA_EXP control
created one expectation before the patch and none after it. The related
object is W=1 warning-free. The netdev allyesconfig and allmodconfig W=1
full builds were not run.
net/netfilter/nf_conntrack_netlink.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntrack_netlink.c
index 4e5d7c70143683..c68e79d1ac87b9 100644
--- a/net/netfilter/nf_conntrack_netlink.c
+++ b/net/netfilter/nf_conntrack_netlink.c
@@ -2359,6 +2359,11 @@ ctnetlink_create_conntrack(struct net *net,
goto err2;
}
master_ct = nf_ct_tuplehash_to_ctrack(master_h);
+ if (master_ct->master) {
+ nf_ct_put(master_ct);
+ err = -EOPNOTSUPP;
+ goto err2;
+ }
__set_bit(IPS_EXPECTED_BIT, &ct->status);
ct->master = master_ct;
}
@@ -2864,6 +2869,9 @@ ctnetlink_glue_attach_expect(const struct nlattr *attr, struct nf_conn *ct,
struct nf_conntrack_expect *exp;
int err;
+ if (ct->master)
+ return -EOPNOTSUPP;
+
err = nla_parse_nested_deprecated(cda, CTA_EXPECT_MAX, attr,
exp_nla_policy, NULL);
if (err < 0)
--
2.55.0
next prev parent reply other threads:[~2026-10-02 16:56 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 18:02 [PATCH net] netfilter: conntrack: avoid recursive master destruction Daehyeon Ko
2026-10-01 19:19 ` Florian Westphal
2026-10-02 5:39 ` Daehyeon Ko
2026-10-02 9:56 ` Pablo Neira Ayuso
2026-10-02 9:55 ` Pablo Neira Ayuso
2026-10-02 9:55 ` Pablo Neira Ayuso
2026-10-02 16:56 ` Daehyeon Ko [this message]
2026-10-02 16:58 ` [PATCH v2 net] netfilter: conntrack: reject nested ctnetlink master chains netdev-bot+sinfo
2026-10-02 17:35 ` Florian Westphal
2026-10-06 7:57 ` netdev-bot+sashiko
2026-10-07 1:33 ` Daehyeon Ko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002165601.1754467-1-4ncienth@gmail.com \
--to=4ncienth@gmail.com \
--cc=coreteam@netfilter.org \
--cc=fw@strlen.de \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox