mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEH7ZpcWbFyOOp6OJbrB3Eaf9PW7cFAmqEJIUACgkQrB3Eaf9P W7eUHRAAhUaCftYnbSKKcvB8DgDysrRRFOieJ5ucqyYWCc51/O8bQWspzvFd2fiP cq7KLubREyGD8FqMNwl94J2zTW7awrGWyNkiA0TwNouOWIM5yu4eg7aZ1+edOMrx FF15HM8Q4DNgfHGdNYZKzRzP+72qLNEY92o6nbDYQUZmB33tFjic44+7Vphhjwb3 t/GulrwfA8M/98oDgmzqwxSIz+/5E+kXSqLouD/vCMXPbdDv0m1xW2iNPHkU+Bom Kk6WNlcPwJWmpM5mfaWP4C2T1reJnyi99MorBco69PrGFhCVxBftQO08qGaE5EeR YbNNrvPKs7mcCqnwfhDObKz8GdkPIvt79p/UKQjardN1ts/aU5N8CD4bwSzMHWep dmz3j9sydtQom+YXYxAgr50DKpyZKOS7abQou4jTmwTz5/fAHVSPzfzE7aSJpE6o Df9gW7cGmAs4KSeQaHotEBOR790AedwG1bHdn7C/KqOdd4e8IwzC+6ZLNjzlrC/f ZtwN64Ct8uChIs6A+SAnzD+C7SEP8k0A/MFOwbf+Ov5kYLkzFYL/JudB4eK437kQ K+VcZj/jrs3aBqZm5Y/O5PlK4/Bpa04XJamK2cG9la5RGked4VWSffSd9NQIg07t 2Lct15Qe7K9aJrLkXA92Qbjkmhq92RKqVCJ7ylgkwW1cRm5FxDc= =wXnr -----END PGP SIGNATURE----- Merge tag 'ipsec-2026-08-18' of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec Steffen Klassert says: ==================== pull request (net): ipsec 2026-08-18 1) xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full Tighten the secpath-depth check so a full chain can't write past xvec[]. 2) Add and revert "esp: do not unref managed frag pages in esp_ssg_unref()" The patch does not fully fully resolve the issue, a corrected version will follow. 3) xfrm: espintcp: fix UAF during close Synchronize espintcp close with the xfrm_trans_reinject work queue so the freed socket message isn't dereferenced again. 4) xfrm: drop ESP-in-TCP packets with no ingress device Drop queued ESP-in-TCP records whose saved ingress device has gone away, avoiding a NULL device deref in the XFRM input path. 5) xfrm: avoid lock inversion in nat keepalive work Split the NAT keepalive walk into a reference-collection phase and a per-state lock phase to break the AB-BA with state removal. This patch has some issues that are fixed with a followup patch. 6) xfrm: Fix skb double-free in xfrm_dev_direct_output() Stop freeing the skb unconditionally in xfrm_dev_direct_output(), letting local_out()'s result indicate when ownership has moved on. 7) xfrm: ah6: validate routing header segments_left Validate the segments_left/hdrlen invariant before rearranging the routing-header addresses, avoiding an OOB memmove on malformed HDRINCL packets. 8) xfrm: fix xfrm_state_construct() auth-trunc leak Detect an already-attached auth-trunc allocation by the pointer rather than inferring it from the algorithm id, so a prior attach isn't overwritten and lost. 9) xfrm: bound nat keepalive state collection Replace the per-state allocation in the NAT keepalive walk with a fixed-size batch that drains under BH-disabled locking and resumes from the cursor, bounding the worker's memory. * tag 'ipsec-2026-08-18' of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec: xfrm: bound nat keepalive state collection Revert "esp: do not unref managed frag pages in esp_ssg_unref()" xfrm: fix xfrm_state_construct() auth-trunc leak xfrm: ah6: validate routing header segments_left xfrm: Fix skb double-free in xfrm_dev_direct_output() xfrm: avoid lock inversion in nat keepalive work xfrm: drop ESP-in-TCP packets with no ingress device xfrm: espintcp: fix UAF during close esp: do not unref managed frag pages in esp_ssg_unref() xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full ==================== Link: https://patch.msgid.link/20260818092920.653034-1-steffen.klassert@secunet.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
||
|---|---|---|
| .. | ||
| espintcp.c | ||
| Kconfig | ||
| Makefile | ||
| trace_iptfs.h | ||
| xfrm_algo.c | ||
| xfrm_compat.c | ||
| xfrm_device.c | ||
| xfrm_hash.c | ||
| xfrm_hash.h | ||
| xfrm_inout.h | ||
| xfrm_input.c | ||
| xfrm_interface_bpf.c | ||
| xfrm_interface_core.c | ||
| xfrm_ipcomp.c | ||
| xfrm_iptfs.c | ||
| xfrm_nat_keepalive.c | ||
| xfrm_output.c | ||
| xfrm_policy.c | ||
| xfrm_proc.c | ||
| xfrm_replay.c | ||
| xfrm_state_bpf.c | ||
| xfrm_state.c | ||
| xfrm_sysctl.c | ||
| xfrm_user.c | ||