Thread (4 messages) flat view 4 messages, 2 authors, 2d ago

Re: [PATCH net v5 1/1] openvswitch: Fix CT limit teardown use-after-free

From: Ilya Maximets <i.maximets@ovn.org>
Date: 2026-08-11 20:46:06
Also in: lkml

On 8/11/26 4:02 PM, Ilya Maximets wrote:
On 8/11/26 11:55 AM, Yuqi Xu wrote:
quoted
Packet processing uses CT limit state under RCU, while netns teardown
frees that state under ovs_mutex. The CT limit pointer was neither removed
from readers nor protected by a grace period, allowing packet processing to
dereference the freed state.

An unprivileged user can trigger this bug from a user and network
namespace, causing a slab-use-after-free in ovs_ct_execute() when the
netns is torn down.

Publish the CT limit pointer through RCU, remove it before teardown, and
wait for readers before freeing its contents. Keep ovs_mutex around
individual CT limit updates, and use the RCU read-side lock while GET
traverses the RCU-protected limit lists.

Fixes: 11efd5cb04a1 ("openvswitch: Support conntrack zone limit")
Cc: stable@vger.kernel.org
Reported-by: Vega <redacted>
Link: https://lore.kernel.org/all/cover.1784711445.git.xuyuqiabc@gmail.com (local)
Assisted-by: Codex:GPT-5.4
Co-developed-by: Nan Li <redacted>
Signed-off-by: Nan Li <redacted>
Signed-off-by: Yuqi Xu <redacted>
Reviewed-by: Ren Wei <redacted>
---
Changes in v5:

- Remove unreachable command-path NULL handling because netlink sockets
  keep their network namespaces alive while requests are processed.
Please, add a note to the commit message on why the NULL checks are not
necessary for the code invoked from netlink handlers.  Otherwise, LGTM.
May be also worth explicitly calling out the synchronization while holding
the mutex.  It can be avoided, but should likely be a separate change.
Best regards, Ilya Maximets.
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help