From: Pablo Neira Ayuso <pablo@netfilter.org>
To: netfilter-devel@vger.kernel.org
Cc: davem@davemloft.net, netdev@vger.kernel.org, kuba@kernel.org,
pabeni@redhat.com, edumazet@google.com, horms@kernel.org,
fw@strlen.de, ja@ssi.bg
Subject: [PATCH net 0/7] Netfilter/IPVS fixes for net
Date: Thu, 10 Sep 2026 00:18:37 +0200 [thread overview]
Message-ID: <20260909221844.1650275-1-pablo@netfilter.org> (raw)
Hi,
The following patchset provides fixes for Netfilter/IPVS:
1) Fix KMSAN reports an uninit-value in nf_nat_setup_info() for netmap,
from Theodor Arsenij Larionov Trichkine.
2) Restrict deletion of netdevice in basechain and flowtable to exact
matching only, from Fernando F. Mancera.
3) Fix nf_nat_register_fn() error path allowing for a memleak.
4) Revalidate ihl before calling icmp_send() in IPVS,
from Julian Anastasov.
5) Hold reference on ct until flow is released to address, otherwise
access to release ct->ext or different ct due to typesafe RCU
semantics.
6) Use kzalloc_obj() to allocate timer object in xt_IDLETIMER as
reported by sashiko to address uninitialized access.
7) Hold reference on module during netlink for cttimeout, cthelper
ctnetlink and nfnetlink_acct.
Please, pull these changes from:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-26-09-10
Thanks.
----------------------------------------------------------------
The following changes since commit 1b8e56030d52cd3e52c9ad4df1985ad0440be67d:
Merge tag 'nf-26-09-07' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf (2026-09-08 13:53:17 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-26-09-10
for you to fetch changes up to c56f665eeaf77cd19f0a09c8fa7628b744d5918d:
netfilter: hold reference on module during netlink dump (2026-09-09 23:15:36 +0200)
----------------------------------------------------------------
netfilter pull request 26-09-10
----------------------------------------------------------------
Fernando Fernandez Mancera (1):
netfilter: nf_tables: fix device name and prefix match in hook lookup
Julian Anastasov (1):
ipvs: revalidate ihl before icmp_send
Pablo Neira Ayuso (4):
netfilter: nf_nat: unregister and release hooks on error
netfilter: flowtable: hold reference on ct until flow is released
netfilter: xt_IDLETIMER: allocate timer with kzalloc()
netfilter: hold reference on module during netlink dump
Theodor Arsenij Larionov Trichkine (1):
netfilter: nft_nat: fully initialise new_addr in netmap setup
net/netfilter/ipset/ip_set_core.c | 1 +
net/netfilter/ipvs/ip_vs_core.c | 9 ++++++-
net/netfilter/nf_conntrack_netlink.c | 7 ++++++
net/netfilter/nf_flow_table_core.c | 11 +++++++--
net/netfilter/nf_nat_core.c | 46 +++++++++++++++++++++++-------------
net/netfilter/nf_tables_api.c | 22 ++++++++++-------
net/netfilter/nfnetlink_acct.c | 1 +
net/netfilter/nfnetlink_cthelper.c | 1 +
net/netfilter/nfnetlink_cttimeout.c | 1 +
net/netfilter/nft_nat.c | 2 +-
net/netfilter/xt_IDLETIMER.c | 2 +-
11 files changed, 73 insertions(+), 30 deletions(-)
next reply other threads:[~2026-09-09 22:18 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 22:18 Pablo Neira Ayuso [this message]
2026-09-09 22:18 ` [PATCH net 1/7] netfilter: nft_nat: fully initialise new_addr in netmap setup Pablo Neira Ayuso
2026-09-09 22:18 ` [PATCH net 2/7] netfilter: nf_tables: fix device name and prefix match in hook lookup Pablo Neira Ayuso
2026-09-09 22:18 ` [PATCH net 3/7] netfilter: nf_nat: unregister and release hooks on error Pablo Neira Ayuso
2026-09-11 0:46 ` Jakub Kicinski
2026-09-09 22:18 ` [PATCH net 4/7] ipvs: revalidate ihl before icmp_send Pablo Neira Ayuso
2026-09-11 0:46 ` Jakub Kicinski
2026-09-11 9:56 ` Julian Anastasov
2026-09-09 22:18 ` [PATCH net 5/7] netfilter: flowtable: hold reference on ct until flow is released Pablo Neira Ayuso
2026-09-09 22:18 ` [PATCH net 6/7] netfilter: xt_IDLETIMER: allocate timer with kzalloc() Pablo Neira Ayuso
2026-09-11 0:46 ` Jakub Kicinski
2026-09-09 22:18 ` [PATCH net 7/7] netfilter: hold reference on module during netlink dump Pablo Neira Ayuso
2026-09-11 0:46 ` Jakub Kicinski
2026-09-11 0:49 ` [PATCH net 0/7] Netfilter/IPVS fixes for net Jakub Kicinski
-- strict thread matches above, loose matches on Subject: below --
2022-11-02 18:46 Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909221844.1650275-1-pablo@netfilter.org \
--to=pablo@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=horms@kernel.org \
--cc=ja@ssi.bg \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox