From: Chengfeng Ye <nicoyip.dev@gmail.com>
To: Pablo Neira Ayuso <pablo@netfilter.org>,
Florian Westphal <fw@strlen.de>, Phil Sutter <phil@nwl.cc>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>
Cc: netfilter-devel@vger.kernel.org, coreteam@netfilter.org,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
Chengfeng Ye <nicoyip.dev@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH net v2] netfilter: flowtable: flush delete work after final GC
Date: Mon, 28 Sep 2026 00:32:48 +0800 [thread overview]
Message-ID: <20260927163248.1002656-1-nicoyip.dev@gmail.com> (raw)
nf_flow_table_free() can return while delete work still holds a pointer to
the flowtable. Its caller can then free the flowtable before the worker
accesses it, causing a use-after-free.
nf_flow_offload_del() sets NF_FLOW_HW_DYING only after allocating the work
item. If this GFP_ATOMIC allocation fails during the first teardown GC
pass, the flow remains eligible for deletion in the final GC pass inside
nf_flow_table_offload_flush_cleanup(). That pass runs after the delete
workqueue has been flushed, so a successful retry queues work which is
not waited for:
teardown worker delete worker
first GC: work allocation fails
NF_FLOW_HW_DYING remains clear
flush delete workqueue
final GC: allocation succeeds
queue FLOW_CLS_DESTROY work
destroy rhashtable
free flowtable
access offload->flowtable
Flush the delete workqueue again after the final GC to complete this work
before the flowtable can be freed. All flows have already been marked for
teardown, so this GC pass only queues delete work, and the delete worker
does not queue further offload work.
KASAN reported:
BUG: KASAN: slab-use-after-free in flow_offload_work_handler+0xbe8/0xe30
Read of size 8 at addr ffff888109c9fd98 by task kworker/u16:3/397
Workqueue: nf_ft_offload_del flow_offload_work_handler
Call Trace:
flow_offload_work_handler+0xbe8/0xe30
process_one_work+0x63a/0x1070
worker_thread+0x45b/0xd10
Allocated by task 87:
nf_tables_newflowtable+0x5d0/0x22f0
nfnetlink_rcv_batch+0x1396/0x1d00
Freed by task 11:
kfree+0x131/0x3c0
nf_tables_trans_destroy_work+0xb26/0xeb0
process_one_work+0x63a/0x1070
Last potentially related work creation:
__queue_work+0x68e/0x1030
flow_offload_del+0x74c/0xad0
nf_flow_offload_gc_step+0x264/0x8e0
nf_flow_table_gc_run+0xcd/0x150
nf_flow_table_offload_flush_cleanup+0x5c/0x70
nf_flow_table_free+0x280/0x350
nf_tables_flowtable_destroy+0x71/0x270
Fixes: c921ffe85333 ("netfilter: flowtable: Fix flushing of offloaded flows on free")
Cc: stable@vger.kernel.org
Assisted-by: GPT-6-Astra
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
Changes in v2:
- Rebase onto current mainline; the independently revalidated one-line fix
is unchanged from v1.
v1: https://lore.kernel.org/r/20260824115829.205118-1-nicoyip.dev@gmail.com/
net/netfilter/nf_flow_table_offload.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/netfilter/nf_flow_table_offload.c b/net/netfilter/nf_flow_table_offload.c
index 6757fd89c1f1..728220ba3882 100644
--- a/net/netfilter/nf_flow_table_offload.c
+++ b/net/netfilter/nf_flow_table_offload.c
@@ -1172,6 +1172,7 @@ void nf_flow_table_offload_flush_cleanup(struct nf_flowtable *flowtable)
if (nf_flowtable_hw_offload(flowtable)) {
flush_workqueue(nf_flow_offload_del_wq);
nf_flow_table_gc_run(flowtable);
+ flush_workqueue(nf_flow_offload_del_wq);
}
}
--
2.43.0
reply other threads:[~2026-09-27 16:32 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260927163248.1002656-1-nicoyip.dev@gmail.com \
--to=nicoyip.dev@gmail.com \
--cc=coreteam@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®