Linux Netfilter development
 help / color / mirror / Atom feed
From: Florian Westphal <fw@strlen.de>
To: <netfilter-devel@vger.kernel.org>
Cc: Florian Westphal <fw@strlen.de>
Subject: [PATCH nf v3 0/6] netfilter: harden conntrack vs ingress pipeline rewrites
Date: Fri, 18 Sep 2026 16:58:03 +0200	[thread overview]
Message-ID: <20260918145809.12938-1-fw@strlen.de> (raw)

v3: more LLM comments.  Only changes are in patches 1, 5 and 6.
v2: address LLM comments.  Only changes are in patches 1 and 6.

netfilter is very allergic to packets changing while they are within the
processing pipeline.

- we rely on ip/ipv6 stack to check ip header integrity, later
  parts of conntrack, e.g. helpers, rely on conntrack to have
  sanity-checked e.g. th->doff.

- parts that bypass inet (e.g. bridge) replicate those sanity
  checks on l3 headers.

- Other hardening changes to nf_queue and nft_payload.c have clamped
  down on the ability to mangle packet in arbitary ways in-between
  hooks.

Another remaining problem is conntrack itself: if nf_conntrack_in finds
the skb already has an nf_conn attached, no further checks are done.

This isn't correct anymore, such nf_conn could have been attached by
output hook (loopback case) or tc conntrack action.  In between those
mangling is possible.  This patchset aims to add sanity checks for this.

1) Validate skb->_nfct against current L3/L4 headers from nf_conntrack_in().
Drop stale conntrack references and trigger re-lookups if mismatches occur.

2) Refactor nf_confirm() logic into separate functions for protocol offset
determination and helper calls.

3) Verify L4 protocol matches the helper's expected protocol before calling a
conntrack helper. Skip IPv4 fragments and packets without payload. Update
nft_ct to set the L4 protocol in newly allocated helpers.

4) Replace open-coded conntrack helper invocation with nf_ct_call_helper().
Add checks to ensure the helper can process packets.  This also reduces
copypaste with tc and ovs.

5) Harden nf_conntrack helper invocation via tuple revalidation. Verify
packet tuples match connection tracking entries. Check for sane TCP
headers in TCP traffic.

6) Validate timeout object protocols against the conntrack tuple protocol
before attachment. Prevent potential out-of-bounds reads caused by
protocol state mismatches.

Earlier attempt to fix offenders instead:
 https://lore.kernel.org/netdev/20260819204210.23722-1-fw@strlen.de/

Florian Westphal (6):
  netfilter: nf_conntrack: validate skb->_nfct and packet headers
  netfilter: nf_conntrack: refactor helper call logic in nf_confirm()
  netfilter: nf_conntrack: verify L4 protocol before calling helper
  netfilter: conntrack: replace open-coded helper invocation
  netfilter: nf_conntrack: harden helper invocation with tuple
    revalidation
  netfilter: nft_ct: validate timeout object protocol

 include/net/netfilter/nf_conntrack_helper.h |   2 +
 net/netfilter/nf_conntrack_core.c           | 115 ++++++++++++-
 net/netfilter/nf_conntrack_ovs.c            |  53 +-----
 net/netfilter/nf_conntrack_proto.c          | 173 ++++++++++++++++----
 net/netfilter/nft_ct.c                      |  45 +++--
 5 files changed, 283 insertions(+), 105 deletions(-)

-- 
2.55.0


             reply	other threads:[~2026-09-18 15:39 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18 14:58 Florian Westphal [this message]
2026-09-18 14:58 ` [PATCH v3 nf 1/6] netfilter: nf_conntrack: validate skb->_nfct and packet headers Florian Westphal
2026-09-18 14:58 ` [PATCH v3 nf 2/6] netfilter: nf_conntrack: refactor helper call logic in nf_confirm() Florian Westphal
2026-09-18 14:58 ` [PATCH v3 nf 3/6] netfilter: nf_conntrack: verify L4 protocol before calling helper Florian Westphal
2026-09-18 14:58 ` [PATCH v3 nf 4/6] netfilter: conntrack: replace open-coded helper invocation Florian Westphal
2026-09-18 14:58 ` [PATCH v3 nf 5/6] netfilter: nf_conntrack: harden helper invocation with tuple revalidation Florian Westphal
2026-09-18 14:58 ` [PATCH v3 nf 6/6] netfilter: nft_ct: validate timeout object protocol Florian Westphal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918145809.12938-1-fw@strlen.de \
    --to=fw@strlen.de \
    --cc=netfilter-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox