No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Pablo Neira Ayuso b09e6ccf0d netfilter: nf_tables: double hook unregistration in netns path
commit f9a43007d3f7ba76d5e7f9421094f00f2ef202f8 upstream.

__nft_release_hooks() is called from pre_netns exit path which
unregisters the hooks, then the NETDEV_UNREGISTER event is triggered
which unregisters the hooks again.

[  565.221461] WARNING: CPU: 18 PID: 193 at net/netfilter/core.c:495 __nf_unregister_net_hook+0x247/0x270
[...]
[  565.246890] CPU: 18 PID: 193 Comm: kworker/u64:1 Tainted: G            E     5.18.0-rc7+ #27
[  565.253682] Workqueue: netns cleanup_net
[  565.257059] RIP: 0010:__nf_unregister_net_hook+0x247/0x270
[...]
[  565.297120] Call Trace:
[  565.300900]  <TASK>
[  565.304683]  nf_tables_flowtable_event+0x16a/0x220 [nf_tables]
[  565.308518]  raw_notifier_call_chain+0x63/0x80
[  565.312386]  unregister_netdevice_many+0x54f/0xb50

Unregister and destroy netdev hook from netns pre_exit via kfree_rcu
so the NETDEV_UNREGISTER path see unregistered hooks.

Fixes: 767d1216bff8 ("netfilter: nftables: fix possible UAF over chains from packet path in netns")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-11-28 16:50:23 +00:00
arch parisc/pgtable: Do not drop upper 5 address bits of physical address 2023-11-28 16:50:20 +00:00
block
certs
crypto crypto: pcrypt - Fix hungtask for PADATA_RESET 2023-11-28 16:50:14 +00:00
Documentation firmware: ti_sci: Replace HTTP links with HTTPS ones 2023-11-20 10:30:12 +01:00
drivers drm/amdgpu: fix error handling in amdgpu_bo_list_get() 2023-11-28 16:50:22 +00:00
fs ext4: remove gdb backup copy for meta bg in setup_new_flex_group_blocks 2023-11-28 16:50:21 +00:00
include netfilter: nf_tables: fix memleak when more than 255 elements expired 2023-11-28 16:50:23 +00:00
init
ipc
kernel tracing: Have trace_event_file have ref counters 2023-11-28 16:50:22 +00:00
lib kobject: Fix slab-out-of-bounds in fill_kobj_path() 2023-11-08 11:23:38 +01:00
LICENSES
mm mm/cma: use nth_page() in place of direct struct page manipulation 2023-11-28 16:50:19 +00:00
net netfilter: nf_tables: double hook unregistration in netns path 2023-11-28 16:50:23 +00:00
samples
scripts randstruct: Fix gcc-plugin performance mode to stay in group 2023-11-28 16:50:17 +00:00
security ima: rework CONFIG_IMA dependency block 2023-10-10 21:46:46 +02:00
sound ALSA: hda/realtek - Enable internal speaker of ASUS K6500ZC 2023-11-28 16:50:20 +00:00
tools tools/power/turbostat: Fix a knl bug 2023-11-28 16:50:17 +00:00
usr
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile Linux 5.4.261 2023-11-20 10:30:17 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.