From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C3B01499F2E for ; Wed, 23 Sep 2026 12:35:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790166936; cv=none; b=cG0IXOa1FXogjQ/ZjJv3nTeNhA4dTWyp0A5QYyWuEPdqmKPVxjQWS0UAXcPY3yXsR1FrfpJCS5c31YtQfwb5zz3dwsKYBScr+TZkPV7zo0lj0r9bfwz1K6fj3cdhcgHX3/G5GJ3KOztlnybtcwAd522LKP45DU+oqDm2iWikRNI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790166936; c=relaxed/simple; bh=x7Apl9ihKaoaWZi5tsiyj9XdsN5NTj65ZbJChWnAXUw=; h=From:To:Cc:Subject:In-Reply-To:References:Date:Message-ID: MIME-Version:Content-Type; b=rVRZcEIWzl+CbeZ4QVMT7QW00Djh5KOa2lSjKeBBHocQ7w3X12QceZ7vMBXtSE7f3Wrez+gG7eC3KAaebl1aK+z9wPjOGlXCtSJMP7KNdrXlTDDrdnpwzOS4hExB0VoaPPpUz/Dmw9l3oAL1S2reMxExoCqwQxoY44aiWaJwov0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Uklwd6d0; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=a60OyogU; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Uklwd6d0"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="a60OyogU" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790166933; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=UDQWN+qvZeX1gaIgZOYdsKlCuMncX8rgK5IP5SLXF5I=; b=Uklwd6d0eRA+Eyy2vAggML6T0CSrcFOyGz/uLDNGkTBXEtKvXHVdxMzfrbcAJJ8MZsKS4o nbB5R+KH1+FMPRg61ri+N7lC6HmQ1KtlRDnY5WQSlRuguud2ZTNpS/mmBVrJSYlm+ehv84 VqzDyxgzwJwRVtOkWI4iLvyS0EFne7w= Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-124-dF0HPRydOSSJonf9mFpc1Q-1; Wed, 23 Sep 2026 08:35:31 -0400 X-MC-Unique: dF0HPRydOSSJonf9mFpc1Q-1 X-Mimecast-MFC-AGG-ID: dF0HPRydOSSJonf9mFpc1Q_1790166930 Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-49e6b5c5f44so12544225e9.2 for ; Wed, 23 Sep 2026 05:35:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1790166930; x=1790771730; darn=vger.kernel.org; h=content-type:mime-version:user-agent:message-id:date:references :in-reply-to:subject:cc:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=UDQWN+qvZeX1gaIgZOYdsKlCuMncX8rgK5IP5SLXF5I=; b=a60OyogUZ+HcW76z3sOpzu0sYxAgSCaskaeDeHAHgy3uDs6dg3MVYweUmRazLxr3rR ky25sj+3BYPckeFqZ9/ZZAv+9ODycMinEgwZb6RqHSNr2d50qhNyYAOmje8D4d5e6LrC XuU6GKQkOPeiN7oSjzbhmnI/IPU1710iM0z+X6+0pTw6gT5HIQonOsxQM8KXSG/8+354 V6kpUuxqqeazPwnWB9C3OuRTFGCscX+sDk0vtTg6UdjNkgVN3ucskiq9xdNUDZHd162i hR19Gxv3BEd/vld7hxOsrMoW5mQlRZVo5whjeLwaclQf+DYVVCiy4YqU9fpKCczVboiL LhdA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790166930; x=1790771730; h=content-type:mime-version:user-agent:message-id:date:references :in-reply-to:subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=UDQWN+qvZeX1gaIgZOYdsKlCuMncX8rgK5IP5SLXF5I=; b=wMqTmoJZDPtnjpXcARWcYYxAMdo9XE9OwUalL67u/ngVJ/s1KiyzsnZvTrRgibvGK6 LURYsOI4p3UmpjseUU/NfdScQJu50Eopb6G5bjADZBiR8StHyEcJ0rq+XDryuK9gD2AF BkqUJnXEgzMw9nhf0tO7Ptza8g070F9BnBFuGyxgrCc1xtsWpETZDeqnGDxp849zmfIT XYEWarVe2dmZ0YlAK8Ub0bDKYFdBJPAUw3S5nqXUZP2jE0qcv3lODTQl1Wk9P1mUkAHv ZrFJR2/GfNc3a0G8TjSYMV9yAwRHadd2wY0URi3Tnp7OgzmFE2MwlL9mry9M3W7unVYn GWrQ== X-Forwarded-Encrypted: i=1; AKwUvByOVxhJHD+aI+BTbYicozhVcdu3GOGYHxiSBGmEAzFh7wBlkc6W0gOkk3gbIkY5IJxs/Hpo9sBzjQEIAmo=@vger.kernel.org X-Gm-Message-State: AFuF++m3KkeV0V66Lqrpx4nxpxz3pc9NiOjuqhGuehoPq7NH98awM9RA UhEAFoTP0g48ueHsqIY3uaeRyFp5HHG4Ge2C+ql7dCF4zKC3BeYFtsAVXBVrfAW4oZM46pMtSWn 31MmP7m82SdliMdp60g4QnFHDhrLuBY/kvhpCPKFzzyAlKIBU+VTX1qGWY0sL2oU4mQ== X-Gm-Gg: AYBFou0Wi20unoMfzFvcAvgPny2eA0kygB7saf9fxGoABF5poNRARHgXkBlFG3Qzd9L /NuT8Da2P2vp1UYRAnKW7zHFqE5S3l9Da+PrCO9thNqOu+fgrpUU9Lj2CNFpxGQb1UmlzsiDHto eAOlqTxlunk5wvl43df0BUcWUHTSVWrCAvm2iRxfDyIgDgGPQrddBznar9MTu8Pxs4e0QUDedQF 7uKlcPVHYGTF3ggDFt1wlTPSvDoJXXnrSsnCf1BM8zOt4RN6VOSlYx51GSVNFPlWFpFEQEeDujT tLXr32I3AzqIETKOLEMWQs/JTqZ8nn5GV7OasnQ9FyfaywwwVTs+y8S/2JHf1/JyZtTXTppwhom G8q3ATdKK7zBjTLbR2TMr2ZYgemW8ixSzWqxbM3U= X-Received: by 2002:a05:600d:1:b0:49f:e3d4:4c1f with SMTP id 5b1f17b1804b1-49fe3d44c52mr16737145e9.8.1790166930505; Wed, 23 Sep 2026 05:35:30 -0700 (PDT) X-Received: by 2002:a05:600d:1:b0:49f:e3d4:4c1f with SMTP id 5b1f17b1804b1-49fe3d44c52mr16736585e9.8.1790166930125; Wed, 23 Sep 2026 05:35:30 -0700 (PDT) Received: from aconole-thinkpadt14gen4.rmtusnh.csb ([216.212.25.12]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fde1ccb90sm75125185e9.6.2026.09.23.05.35.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 05:35:29 -0700 (PDT) From: Aaron Conole To: Ilya Maximets Cc: netdev@vger.kernel.org, Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Eelco Chaudron , Jamal Hadi Salim , Jiri Pirko , Xin Long , Marcelo Ricardo Leitner , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, dev@openvswitch.org, stable@vger.kernel.org, Axel Mierczuk Subject: Re: [PATCH net 6/6] net/sched: act_ct: fix helper UAF due to extensions realloc In-Reply-To: <20260921145655.3167436-7-i.maximets@ovn.org> (Ilya Maximets's message of "Mon, 21 Sep 2026 16:55:48 +0200") References: <20260921145655.3167436-1-i.maximets@ovn.org> <20260921145655.3167436-7-i.maximets@ovn.org> Date: Wed, 23 Sep 2026 08:35:26 -0400 Message-ID: User-Agent: Gnus/5.13 (Gnus v5.13) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain Ilya Maximets writes: > While calling the helpers, a raw pointer to the extensions area is > wired into expectations list: > > -> nf_ct_helper() > -> helper->help() > -> nf_ct_expect_related_report() > -> nf_ct_expect_insert() > -> hlist_add_head_rcu(&exp->lnode, &master_help->expectations) > > In case the connection is not confirmed yet, more extensions can be > added afterwards with *_ext_add() calls reallocating the extension > space and leaving the now invalid pointer in the expectations list > that is later accessed while removing the expectation. > > Make sure that helpers are called at the end after all the other > extensions are already added. > > Note that the helper rejection now leaves the mark and labels set, > but that's not different from how the NAT was handled before or how > the mark and the labels were handled on confirmation failure. And > there are no atomicity guarantees provided by the API anyway. > > Fixes: a21b06e73191 ("net: sched: add helper support in act_ct") > Cc: stable@vger.kernel.org > Reported-by: Axel Mierczuk > Signed-off-by: Ilya Maximets > --- Reviewed-by: Aaron Conole