linux/net/xfrm
Jakub Kicinski 50720728b1 ipsec-2026-08-18
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEH7ZpcWbFyOOp6OJbrB3Eaf9PW7cFAmqEJIUACgkQrB3Eaf9P
 W7eUHRAAhUaCftYnbSKKcvB8DgDysrRRFOieJ5ucqyYWCc51/O8bQWspzvFd2fiP
 cq7KLubREyGD8FqMNwl94J2zTW7awrGWyNkiA0TwNouOWIM5yu4eg7aZ1+edOMrx
 FF15HM8Q4DNgfHGdNYZKzRzP+72qLNEY92o6nbDYQUZmB33tFjic44+7Vphhjwb3
 t/GulrwfA8M/98oDgmzqwxSIz+/5E+kXSqLouD/vCMXPbdDv0m1xW2iNPHkU+Bom
 Kk6WNlcPwJWmpM5mfaWP4C2T1reJnyi99MorBco69PrGFhCVxBftQO08qGaE5EeR
 YbNNrvPKs7mcCqnwfhDObKz8GdkPIvt79p/UKQjardN1ts/aU5N8CD4bwSzMHWep
 dmz3j9sydtQom+YXYxAgr50DKpyZKOS7abQou4jTmwTz5/fAHVSPzfzE7aSJpE6o
 Df9gW7cGmAs4KSeQaHotEBOR790AedwG1bHdn7C/KqOdd4e8IwzC+6ZLNjzlrC/f
 ZtwN64Ct8uChIs6A+SAnzD+C7SEP8k0A/MFOwbf+Ov5kYLkzFYL/JudB4eK437kQ
 K+VcZj/jrs3aBqZm5Y/O5PlK4/Bpa04XJamK2cG9la5RGked4VWSffSd9NQIg07t
 2Lct15Qe7K9aJrLkXA92Qbjkmhq92RKqVCJ7ylgkwW1cRm5FxDc=
 =wXnr
 -----END PGP SIGNATURE-----

Merge tag 'ipsec-2026-08-18' of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec

Steffen Klassert says:

====================
pull request (net): ipsec 2026-08-18

1) xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
   Tighten the secpath-depth check so a full chain can't write
   past xvec[].

2) Add and revert "esp: do not unref managed frag pages in esp_ssg_unref()"
   The patch does not fully fully resolve the issue, a corrected version
   will follow.

3) xfrm: espintcp: fix UAF during close
   Synchronize espintcp close with the xfrm_trans_reinject work
   queue so the freed socket message isn't dereferenced again.

4) xfrm: drop ESP-in-TCP packets with no ingress device
   Drop queued ESP-in-TCP records whose saved ingress device has
   gone away, avoiding a NULL device deref in the XFRM input path.

5) xfrm: avoid lock inversion in nat keepalive work
   Split the NAT keepalive walk into a reference-collection phase
   and a per-state lock phase to break the AB-BA with state removal.
   This patch has some issues that are fixed with a followup patch.

6) xfrm: Fix skb double-free in xfrm_dev_direct_output()
   Stop freeing the skb unconditionally in xfrm_dev_direct_output(),
   letting local_out()'s result indicate when ownership has moved on.

7) xfrm: ah6: validate routing header segments_left
   Validate the segments_left/hdrlen invariant before rearranging
   the routing-header addresses, avoiding an OOB memmove on
   malformed HDRINCL packets.

8) xfrm: fix xfrm_state_construct() auth-trunc leak
   Detect an already-attached auth-trunc allocation by the pointer
   rather than inferring it from the algorithm id, so a prior
   attach isn't overwritten and lost.

9) xfrm: bound nat keepalive state collection
   Replace the per-state allocation in the NAT keepalive walk
   with a fixed-size batch that drains under BH-disabled locking
   and resumes from the cursor, bounding the worker's memory.

* tag 'ipsec-2026-08-18' of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec:
  xfrm: bound nat keepalive state collection
  Revert "esp: do not unref managed frag pages in esp_ssg_unref()"
  xfrm: fix xfrm_state_construct() auth-trunc leak
  xfrm: ah6: validate routing header segments_left
  xfrm: Fix skb double-free in xfrm_dev_direct_output()
  xfrm: avoid lock inversion in nat keepalive work
  xfrm: drop ESP-in-TCP packets with no ingress device
  xfrm: espintcp: fix UAF during close
  esp: do not unref managed frag pages in esp_ssg_unref()
  xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
====================

Link: https://patch.msgid.link/20260818092920.653034-1-steffen.klassert@secunet.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-08-20 11:38:14 -07:00
..
espintcp.c xfrm: drop ESP-in-TCP packets with no ingress device 2026-07-20 12:24:33 +02:00
Kconfig pfkey: Deprecate pfkey 2025-10-30 09:03:12 +01:00
Makefile xfrm: iptfs: add new iptfs xfrm mode impl 2024-12-05 10:01:35 +01:00
trace_iptfs.h xfrm: iptfs: add tracepoint functionality 2024-12-05 10:02:36 +01:00
xfrm_algo.c xfrm: Drop support for HMAC-RIPEMD-160 2026-04-07 10:47:58 +02:00
xfrm_compat.c xfrm: add XFRM_MSG_MIGRATE_STATE for single SA migration 2026-06-04 12:22:47 +02:00
xfrm_device.c xfrm: cache the offload ifindex for netlink dumps 2026-07-02 09:12:58 +02:00
xfrm_hash.c mm: remove include/linux/bootmem.h 2018-10-31 08:54:16 -07:00
xfrm_hash.h xfrm: add state hashtable keyed by seq 2021-05-14 13:52:01 +02:00
xfrm_inout.h xfrm: move xfrm4_extract_header to common helper 2020-05-06 09:40:08 +02:00
xfrm_input.c xfrm: Fix dev use-after-free in xfrm async resumption 2026-06-12 08:39:59 +02:00
xfrm_interface_bpf.c bpf: treewide: Annotate BPF kfuncs in BTF 2024-01-31 20:40:56 -08:00
xfrm_interface_core.c xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink 2026-06-17 16:01:53 -07:00
xfrm_ipcomp.c xfrm: ipcomp: Free destination pages on acomp errors 2026-05-11 10:34:35 +02:00
xfrm_iptfs.c xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() 2026-07-06 08:29:07 +02:00
xfrm_nat_keepalive.c ipsec-2026-08-18 2026-08-20 11:38:14 -07:00
xfrm_output.c xfrm: Fix skb double-free in xfrm_dev_direct_output() 2026-07-23 10:07:21 +02:00
xfrm_policy.c xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert 2026-07-06 08:30:02 +02:00
xfrm_proc.c xfrm: snmp: do not use SNMP_MIB_SENTINEL anymore 2025-09-08 18:06:21 -07:00
xfrm_replay.c ipsec-2025-01-27 2025-01-27 15:15:12 -08:00
xfrm_state_bpf.c bpf: xfrm: drop dead NULL check in bpf_xdp_get_xfrm_state() 2026-01-02 12:04:29 -08:00
xfrm_state.c xfrm: clear mode callbacks after failed mode setup 2026-07-06 08:29:06 +02:00
xfrm_sysctl.c net: Const qualify ctl_tables that kmemdup unconditionally 2026-08-13 13:12:24 +02:00
xfrm_user.c xfrm: fix xfrm_state_construct() auth-trunc leak 2026-07-28 10:48:18 +02:00