From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C16AE4071E5 for ; Mon, 24 Aug 2026 12:12:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787573574; cv=none; b=RcJS+2YXUOfZye0UEC/TJr/+xvwI/J2jmvV50Dq2v8cCUpKJOuvq9/pMnK1sf/cc2SUJmZ4xp55DMGu86Ttgso5wzlr6pkSql+HI2E5YbRtuCSM0BHgtX8Bb07FPg4PlMneokzd6pzf9VbL0VLSZP7+A2ymCv58TzavZYS/G6zk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787573574; c=relaxed/simple; bh=qTuo0XGpd3/TJoBr7VlydNUS5gAgjPvXjtLTX//eAj0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=F1CCQMaF9ksWdl3iFyXff433eN5eGVHCzLJBkZOMRv+zbhG7bLVXGfJ738V27GoofYUT8a5PvzvzbwqVvzLBNwrRkj1mxePa1Mvmk3qdJUMubGU5CkYEo9dKuW7iwa4Zj/jMDrBtQWQ716jHks+zYE8Klh95SHCFMCGd+APB8To= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=dNKg45UB; arc=none smtp.client-ip=209.85.214.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="dNKg45UB" Received: by mail-pl1-f169.google.com with SMTP id d9443c01a7336-2cecdc24b1cso3279105ad.1 for ; Mon, 24 Aug 2026 05:12:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787573572; x=1788178372; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Y0ppQhbiQcCeg1OqwKrv6XM0T1yzd97yREoqT41AZzU=; b=dNKg45UBwquvACLINh3/RMXrzf4oSej41PPI3JJj5vaZgrYeloEC/zX6biqvwbfN4V /35WCX8AuyFZGh4Dj0Qd7Zzx5ljA5HrUAzSax5pQMj4Zo9FGaiQcPAAZgQWhYl7iuoGZ /YLcSLe+VuZ82vJGSI3aMV0OGGYXAMMigDmoTlTLVBD7Ej1TIuPLPy5YXELoxte4YqjC m1tJjYcoIb1PHwr17zYtqPiQGA2fGCE1pJrO2ks9WZ4lrX9IWD+GbDKM/J2GpuRy94bY p5smS55RvvU647vD3qoOQqLl7nCTbhtoZyHs4MQVq1pcNiimRYUPytvt2ztg9m6tsz0g OUGg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787573572; x=1788178372; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Y0ppQhbiQcCeg1OqwKrv6XM0T1yzd97yREoqT41AZzU=; b=Gkuyr+rPkaGuZmSLyNMUp+He9xnecCrUVeQ0Da8bRwFSlyp86fsfVeg5fv5WOdMKb5 B67rPdCG5BbJnjFU6iTw40s+YgcV6DIA7j7K7rRJY+Aj0rfIsBfwzzP3DgyZEGRzELu0 22YUfAmOTGXB9Fq9HbW9q/2zcmv+Epvkz0rL9jboSnG0P7VHrG649/yES4+4xZe1e3uo AXoS6SGnDfuFnnZccXHlYKmXzvtEHfbmdshw1FVZXAZQuM9Hl9G58USQZR3MC7b7OPnk dzOe2xoie3nyvyUrGR7qXuc9xpGHmWdIL0qjv3S4zS+TisHbuquIOrtyBnMKJl7bPFit G3fQ== X-Forwarded-Encrypted: i=1; AHgh+RqnH/Lkh0tafz1+8+BEQtthQ2waCtLuAeEaCTQwRgt7rdk1cRyyNIJmm5U7uvmBvNr0SSx5WLGkvbVYfa8=@vger.kernel.org X-Gm-Message-State: AFuF++nyZzBfTF931br7xUokkVfHYbf/7aGYhRZwg6jzsN2O0jS3sx1j KsM2jXGKbSmWtWFYazMqXfLwHsE4VlTauUdCey7C5929KjN1KIeyaOI0GUTvEF+FhXDbIg== X-Gm-Gg: AR+sD11KGf6XfUIZ8lN8IhGX+2K2okpZDfJ9eLnN0EWhfJD31Xii8sHcfdyKSXo6UAF wMWBeh0xoSkValRq8YOIvFbfvjw19XfLXc7FwGhh+/YaesjIpLPUOa3a++Ty2gj9ATJyISUvCqH i33PKmfonoq2/PRFF5C7AIuGx+I8kF/WQt5RKlQaTMxnfMaqb+XqJ5eDeEU0rbY5DaxDVDXkhqY 3G6ysgU68l/eFIqytFEVSErUthLuTrj5OsHNN+8p9P+R0tDEaboOi3jSjAqL32hJ/BD+LwIJMUJ vSl6btmW6e2yKfYrkcn2L1yjFipYLeVJrvQyvCRDvrbm1bwo3l/8H0d3HMVO+VtyV3c31ay5WTt b7ldQR4KsWVFsR69C0GXq3Q6JY8idkiz9sbSa6fqgb9yhrJIwQx/85PI7SQybC3TOsdRGHUIwQS ijFMZFw29kPrOsAzg4bVzlCUjrY6ATwd4q3a13yVSkrfZlOIRcaozVJa7Sm+Y3z99M2wbQP5ufv GHqQ2s4SWXrrylAz8CP1xEMlNcDRjmamwPUFM+Snu1ShKzQHcTps78= X-Received: by 2002:a17:903:3b84:b0:2cc:f4d4:29a0 with SMTP id d9443c01a7336-2d64b0a908emr230320855ad.3.1787573571971; Mon, 24 Aug 2026 05:12:51 -0700 (PDT) Received: from localhost.localdomain (45.78.65.84.16clouds.com. [45.78.65.84]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3280d116cb1sm16516298eec.10.2026.08.24.05.12.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 05:12:51 -0700 (PDT) From: Chengfeng Ye To: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman Cc: netfilter-devel@vger.kernel.org, coreteam@netfilter.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Chengfeng Ye , stable@vger.kernel.org Subject: [PATCH net] netfilter: cttimeout: prevent UAF during module unload Date: Mon, 24 Aug 2026 20:12:38 +0800 Message-ID: <20260824121238.205812-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit nf_ct_set_timeout() protects the timeout hook dereference and policy lookup with rcu_read_lock(). cttimeout_exit(), however, unregisters the per-net operations before it clears the hook. This allows the following interleaving: CPU 0 CPU 1 cttimeout_exit() nf_ct_set_timeout() unregister_pernet_subsys() rcu_read_lock() kfree(pernet) h = nf_ct_timeout_hook h->timeout_find_get() nfct_timeout_pernet() The hook still points to ctnl_timeout_find_get() when CPU 1 looks up the already freed per-net timeout list. KASAN reported: BUG: KASAN: slab-use-after-free in ctnl_timeout_find_get Read of size 8 by task poc/90 Call Trace: ctnl_timeout_find_get+0x271/0x2a0 [nfnetlink_cttimeout] nf_ct_set_timeout+0x7b/0x3c0 xt_ct_tg_check+0x724/0xb20 xt_check_target+0x234/0xa90 do_ipt_set_ctl+0x570/0x1270 Allocated by task 89: __kmalloc_noprof+0x16e/0x460 ops_init+0x6d/0x420 register_pernet_operations+0x2f6/0x670 Freed by task 91: kfree+0x131/0x390 ops_undo_list+0x3d4/0x730 unregister_pernet_operations+0x232/0x490 unregister_pernet_subsys+0x1c/0x30 cttimeout_exit+0x52/0x970 [nfnetlink_cttimeout] Clear the hook and wait for existing readers before unregistering the per-net operations. This blocks new policy lookups and ensures readers that observed the hook finish before the per-net storage is freed. Fixes: ebfbe67568a7 ("netfilter: cttimeout: use net_generic infra") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- net/netfilter/nfnetlink_cttimeout.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/netfilter/nfnetlink_cttimeout.c b/net/netfilter/nfnetlink_cttimeout.c index 66c2016f6049..132c02ac7c4e 100644 --- a/net/netfilter/nfnetlink_cttimeout.c +++ b/net/netfilter/nfnetlink_cttimeout.c @@ -652,9 +652,9 @@ static void __exit cttimeout_exit(void) { nfnetlink_subsys_unregister(&cttimeout_subsys); - unregister_pernet_subsys(&cttimeout_ops); RCU_INIT_POINTER(nf_ct_timeout_hook, NULL); synchronize_net(); + unregister_pernet_subsys(&cttimeout_ops); } module_init(cttimeout_init); -- 2.43.0