Use AlmaLinux OS secure boot cert
Enable Btrfs support for all kernel variants
af_unix: set gc_in_progress to true in unix_gc() {CVE-2026-53361}
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
gve: update QPL page registration logic to honor max_registered_pages (backport from upstream)
gve: enable reading max ring size from the device in DQO-QPL mode (backport from upstream)
58 lines
2.1 KiB
Diff
58 lines
2.1 KiB
Diff
From bb3bbb9f38362d2f5f47f38b354cc935cadea8ec Mon Sep 17 00:00:00 2001
|
|
From: Florian Westphal <fwestpha@redhat.com>
|
|
Date: Wed, 13 May 2026 17:10:08 +0200
|
|
Subject: [PATCH] netfilter: nft_set_hash: fix get operation on big endian
|
|
|
|
JIRA: https://redhat.atlassian.net/browse/RHEL-168848
|
|
Upstream Status: commit 2f635adbe264
|
|
|
|
commit 2f635adbe2642d398a0be3ab245accd2987be0c3
|
|
Author: Florian Westphal <fw@strlen.de>
|
|
Date: Tue Jan 27 20:13:45 2026 +0100
|
|
|
|
netfilter: nft_set_hash: fix get operation on big endian
|
|
|
|
tests/shell/testcases/packetpath/set_match_nomatch_hash_fast
|
|
fails on big endian with:
|
|
|
|
Error: Could not process rule: No such file or directory
|
|
reset element ip test s { 244.147.90.126 }
|
|
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
|
Fatal: Cannot fetch element "244.147.90.126"
|
|
|
|
... because the wrong bucket is searched, jhash() and jhash1_word are
|
|
not interchangeable on big endian.
|
|
|
|
Fixes: 3b02b0adc242 ("netfilter: nft_set_hash: fix lookups with fixed size hash on big endian")
|
|
Signed-off-by: Florian Westphal <fw@strlen.de>
|
|
|
|
Signed-off-by: Florian Westphal <fwestpha@redhat.com>
|
|
|
|
diff --git a/net/netfilter/nft_set_hash.c b/net/netfilter/nft_set_hash.c
|
|
index ba01ce7..739b992 100644
|
|
--- a/net/netfilter/nft_set_hash.c
|
|
+++ b/net/netfilter/nft_set_hash.c
|
|
@@ -619,15 +619,20 @@ static struct nft_elem_priv *
|
|
nft_hash_get(const struct net *net, const struct nft_set *set,
|
|
const struct nft_set_elem *elem, unsigned int flags)
|
|
{
|
|
+ const u32 *key = (const u32 *)&elem->key.val;
|
|
struct nft_hash *priv = nft_set_priv(set);
|
|
u8 genmask = nft_genmask_cur(net);
|
|
struct nft_hash_elem *he;
|
|
u32 hash;
|
|
|
|
- hash = jhash(elem->key.val.data, set->klen, priv->seed);
|
|
+ if (set->klen == 4)
|
|
+ hash = jhash_1word(*key, priv->seed);
|
|
+ else
|
|
+ hash = jhash(key, set->klen, priv->seed);
|
|
+
|
|
hash = reciprocal_scale(hash, priv->buckets);
|
|
hlist_for_each_entry_rcu(he, &priv->table[hash], node) {
|
|
- if (!memcmp(nft_set_ext_key(&he->ext), elem->key.val.data, set->klen) &&
|
|
+ if (!memcmp(nft_set_ext_key(&he->ext), key, set->klen) &&
|
|
nft_set_elem_active(&he->ext, genmask))
|
|
return &he->priv;
|
|
}
|