Thread (2 messages) flat view 2 messages, 2 authors, 29d ago

Re: [PATCH] netfilter: nft_ct: validate timeout object protocol

From: Florian Westphal <fw@strlen.de>
Date: 2026-08-10 22:21:18
Also in: netfilter-devel

Kyle Zeng [off-list ref] wrote:
nft_ct_timeout_obj_eval() only compares the timeout object protocol with
packet metadata. A packet header can be changed after conntrack attaches
an entry, so this metadata does not necessarily describe the entry.
I think all of these patches are wrong.  *How* can a packet header
change?  And if so, why is it enough to compare with the ct?

And why is that enough to somehow make it safe?

Are you going to add checks everywhere?
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help