mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 20:54:03 +02:00
netfilter: flowtable: hold reference on ct until flow is released
nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe
semantics also allow to refer to the wrong conntrack from the flowtable
datapath. Hold reference on ct until flow is released after rcu grace
period.
Add rcu_barrier() on module exit path, to ensure pending flow entries
are release before module goes away.
Fixes: 0ff90b6c20 ("netfilter: nf_flow_offload: fix use-after-free and a resource leak")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
cbdd39ce42
commit
e75a9fa1d4
|
|
@ -258,6 +258,14 @@ static void flow_offload_route_release(struct flow_offload *flow)
|
|||
nft_flow_dst_release(flow, FLOW_OFFLOAD_DIR_REPLY);
|
||||
}
|
||||
|
||||
static void flow_offload_free_rcu(struct rcu_head *rcu_head)
|
||||
{
|
||||
struct flow_offload *flow = container_of(rcu_head, struct flow_offload, rcu_head);
|
||||
|
||||
nf_ct_put(flow->ct);
|
||||
kfree(flow);
|
||||
}
|
||||
|
||||
void flow_offload_free(struct flow_offload *flow)
|
||||
{
|
||||
switch (flow->type) {
|
||||
|
|
@ -267,8 +275,7 @@ void flow_offload_free(struct flow_offload *flow)
|
|||
default:
|
||||
break;
|
||||
}
|
||||
nf_ct_put(flow->ct);
|
||||
kfree_rcu(flow, rcu_head);
|
||||
call_rcu(&flow->rcu_head, flow_offload_free_rcu);
|
||||
}
|
||||
EXPORT_SYMBOL_GPL(flow_offload_free);
|
||||
|
||||
|
|
@ -854,6 +861,7 @@ static int __init nf_flow_table_module_init(void)
|
|||
|
||||
static void __exit nf_flow_table_module_exit(void)
|
||||
{
|
||||
rcu_barrier();
|
||||
nf_flow_table_offload_exit();
|
||||
unregister_pernet_subsys(&nf_flow_table_net_ops);
|
||||
kmem_cache_destroy(flow_offload_cachep);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user