From: Daehyeon Ko <4ncienth@gmail.com>
To: pablo@netfilter.org, fw@strlen.de
Cc: phil@nwl.cc, netfilter-devel@vger.kernel.org,
coreteam@netfilter.org, netdev@vger.kernel.org,
stable@vger.kernel.org, 4ncienth@gmail.com
Subject: [PATCH net v3] netfilter: conntrack: avoid recursive master destruction
Date: Wed, 7 Oct 2026 10:48:02 +0900 [thread overview]
Message-ID: <20261007014802.2615503-1-4ncienth@gmail.com> (raw)
A conntrack holds a reference to its master. Userspace can build an
unbounded acyclic chain through ctnetlink. Expectation producers can do the
same: an nft ct expectation can attach its helper to an unconfirmed
expected child and arm the next expectation with that child as master. The
H.323 Q.931 helper can also propagate itself through call-forwarding
expectations.
When only child-held references remain, destroying the leaf calls
nf_ct_put() on its master. If that was the final reference, nf_ct_put()
recurses into nf_ct_destroy(). Repeating this at each level exhausts the
task stack and panics.
Nested expectations are existing helper semantics, and CTA_TUPLE_MASTER
was introduced for conntrackd state replication. Avoid per-producer
restrictions. Decrement the master's refcount directly, then free the
current conntrack. If the refcount reached zero, continue destroying the
master in the same invocation. This preserves existing constructors while
bounding stack use.
Fixes: 5faa1f4cb5a1 ("[NETFILTER]: nf_conntrack_netlink: add support to related connections")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/179127347858.434549.11821822167265441355@kernel.org
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
v3:
- restore iterative destruction after Sashiko identified nft expectation
paths that bypass v2
- document conntrackd compatibility and expectation producers
- do not carry Florian's v2 Reviewed-by to the changed patch
v2: https://patch.msgid.link/20261002165601.1754467-1-4ncienth@gmail.com
- replace v1 with ctnetlink entry-point restrictions
v1: https://patch.msgid.link/20261001180224.1018290-1-4ncienth@gmail.com
The source reproducer remains available privately on request. V3 has the same
code and stable patch-id 033ffbf1094d as v1. Code-identical earlier net and
exact v6.12.105 6,000-entry userns runs reclaimed every conntrack without a
crash marker. On fresh net 0984ebc63179, nf_conntrack_core.o builds W=1 clean.
The patch applies to current net, Torvalds, net-next, linux-next, v7.3-rc5 and
v6.12.105. Strict checkpatch is clean. allyesconfig and allmodconfig W=1 were
not run.
net/netfilter/nf_conntrack_core.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index d0d9e5ea84a095..0ce6141b3dfd70 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -592,6 +592,10 @@ static void warn_on_keymap_list_leak(const struct net *net)
void nf_ct_destroy(struct nf_conntrack *nfct)
{
struct nf_conn *ct = (struct nf_conn *)nfct;
+ struct nf_conn *master;
+ bool destroy_master;
+
+again:
WARN_ON(refcount_read(&nfct->use) != 0);
@@ -610,10 +614,17 @@ void nf_ct_destroy(struct nf_conntrack *nfct)
*/
nf_ct_remove_expectations(ct);
- if (ct->master)
- nf_ct_put(ct->master);
+ master = ct->master;
+ destroy_master = master &&
+ refcount_dec_and_test(&master->ct_general.use);
nf_conntrack_free(ct);
+
+ if (destroy_master) {
+ ct = master;
+ nfct = &ct->ct_general;
+ goto again;
+ }
}
EXPORT_SYMBOL(nf_ct_destroy);
--
2.55.0
next reply other threads:[~2026-10-07 1:48 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 1:48 Daehyeon Ko [this message]
2026-10-07 1:49 ` [PATCH net v3] netfilter: conntrack: avoid recursive master destruction netdev-bot+sinfo
2026-10-07 8:48 ` Florian Westphal
2026-10-07 10:32 ` Pablo Neira Ayuso
2026-10-07 11:26 ` Florian Westphal
2026-10-07 11:45 ` Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007014802.2615503-1-4ncienth@gmail.com \
--to=4ncienth@gmail.com \
--cc=coreteam@netfilter.org \
--cc=fw@strlen.de \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox