Use AlmaLinux OS secure boot cert
Enable Btrfs support for all kernel variants
af_unix: set gc_in_progress to true in unix_gc() {CVE-2026-53361}
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
gve: update QPL page registration logic to honor max_registered_pages (backport from upstream)
gve: enable reading max ring size from the device in DQO-QPL mode (backport from upstream)
81 lines
2.7 KiB
Diff
81 lines
2.7 KiB
Diff
From b79e7ff0af28845109dc3fcd964751f0391ceebf Mon Sep 17 00:00:00 2001
|
|
From: Florian Westphal <fwestpha@redhat.com>
|
|
Date: Wed, 13 May 2026 17:20:53 +0200
|
|
Subject: [PATCH] netfilter: nft_ct: fix use-after-free in timeout object
|
|
destroy
|
|
|
|
JIRA: https://redhat.atlassian.net/browse/RHEL-168848
|
|
Upstream Status: commit f8dca15a1b19
|
|
|
|
commit f8dca15a1b190787bbd03285304b569631160eda
|
|
Author: Tuan Do <tuan@calif.io>
|
|
Date: Fri Apr 3 00:33:17 2026 -0700
|
|
|
|
netfilter: nft_ct: fix use-after-free in timeout object destroy
|
|
|
|
nft_ct_timeout_obj_destroy() frees the timeout object with kfree()
|
|
immediately after nf_ct_untimeout(), without waiting for an RCU grace
|
|
period. Concurrent packet processing on other CPUs may still hold
|
|
RCU-protected references to the timeout object obtained via
|
|
rcu_dereference() in nf_ct_timeout_data().
|
|
|
|
Add an rcu_head to struct nf_ct_timeout and use kfree_rcu() to defer
|
|
freeing until after an RCU grace period, matching the approach already
|
|
used in nfnetlink_cttimeout.c.
|
|
|
|
KASAN report:
|
|
BUG: KASAN: slab-use-after-free in nf_conntrack_tcp_packet+0x1381/0x29d0
|
|
Read of size 4 at addr ffff8881035fe19c by task exploit/80
|
|
|
|
Call Trace:
|
|
nf_conntrack_tcp_packet+0x1381/0x29d0
|
|
nf_conntrack_in+0x612/0x8b0
|
|
nf_hook_slow+0x70/0x100
|
|
__ip_local_out+0x1b2/0x210
|
|
tcp_sendmsg_locked+0x722/0x1580
|
|
__sys_sendto+0x2d8/0x320
|
|
|
|
Allocated by task 75:
|
|
nft_ct_timeout_obj_init+0xf6/0x290
|
|
nft_obj_init+0x107/0x1b0
|
|
nf_tables_newobj+0x680/0x9c0
|
|
nfnetlink_rcv_batch+0xc29/0xe00
|
|
|
|
Freed by task 26:
|
|
nft_obj_destroy+0x3f/0xa0
|
|
nf_tables_trans_destroy_work+0x51c/0x5c0
|
|
process_one_work+0x2c4/0x5a0
|
|
|
|
Fixes: 7e0b2b57f01d ("netfilter: nft_ct: add ct timeout support")
|
|
Cc: stable@vger.kernel.org
|
|
Signed-off-by: Tuan Do <tuan@calif.io>
|
|
Signed-off-by: Florian Westphal <fw@strlen.de>
|
|
|
|
Signed-off-by: Florian Westphal <fwestpha@redhat.com>
|
|
|
|
diff --git a/include/net/netfilter/nf_conntrack_timeout.h b/include/net/netfilter/nf_conntrack_timeout.h
|
|
index 9fdaba9..3a66d4a 100644
|
|
--- a/include/net/netfilter/nf_conntrack_timeout.h
|
|
+++ b/include/net/netfilter/nf_conntrack_timeout.h
|
|
@@ -14,6 +14,7 @@
|
|
struct nf_ct_timeout {
|
|
__u16 l3num;
|
|
const struct nf_conntrack_l4proto *l4proto;
|
|
+ struct rcu_head rcu;
|
|
char data[];
|
|
};
|
|
|
|
diff --git a/net/netfilter/nft_ct.c b/net/netfilter/nft_ct.c
|
|
index 6f2ae7c..d0090d0 100644
|
|
--- a/net/netfilter/nft_ct.c
|
|
+++ b/net/netfilter/nft_ct.c
|
|
@@ -1018,7 +1018,7 @@ static void nft_ct_timeout_obj_destroy(const struct nft_ctx *ctx,
|
|
|
|
nf_ct_untimeout(ctx->net, timeout);
|
|
nf_ct_netns_put(ctx->net, ctx->family);
|
|
- kfree(priv->timeout);
|
|
+ kfree_rcu(priv->timeout, rcu);
|
|
}
|
|
|
|
static int nft_ct_timeout_obj_dump(struct sk_buff *skb,
|