* [PATCH net] ipvs: fix protocol data lifetime during namespace teardown
@ 2026-09-27 6:24 Chengfeng Ye
2026-09-30 17:21 ` Julian Anastasov
0 siblings, 1 reply; 2+ messages in thread
From: Chengfeng Ye @ 2026-09-27 6:24 UTC (permalink / raw)
To: Simon Horman, Julian Anastasov, Pablo Neira Ayuso,
Florian Westphal, Phil Sutter, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Hans Schillstrom
Cc: netdev, lvs-devel, netfilter-devel, coreteam, linux-kernel,
Chengfeng Ye, stable
IPVS frees its per-net protocol data before control cleanup cancels
defense work and unregisters the sysctl table. A defense worker can load
a protocol data pointer, then namespace cleanup can unlink and free that
object before the worker dereferences pd->pp or pd->next. The worker's
securetcp_lock does not serialize with protocol cleanup. A concurrent
defense-mode sysctl write can reach the same timeout update path.
KASAN reported:
BUG: KASAN: slab-use-after-free in ip_vs_protocol_timeout_change
Workqueue: events_long defense_work_handler
Call Trace:
ip_vs_protocol_timeout_change+0x1b4/0x1e0
update_defense_level+0x63e/0xd80
defense_work_handler+0x1e/0xc0
Allocated by task 125:
ip_vs_protocol_net_init+0xda/0x2f0
__ip_vs_init+0x16b/0x240
setup_net+0xfc/0x310
Freed by task 12:
ip_vs_protocol_net_cleanup+0x1d6/0x2e0
__ip_vs_cleanup_batch+0x7d/0x100
cleanup_net+0x38c/0x770
Run control cleanup before protocol cleanup so that defense work and
active sysctl handlers have finished before their protocol data is freed.
Initialize protocols before exposing the control interface, and unwind
in reverse order, to enforce the same lifetime on initialization failure.
Protocol initialization and exit do not depend on control state.
Fixes: 9330419d9aa4 ("IPVS: netns, use ip_vs_proto_data as param.")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
net/netfilter/ipvs/ip_vs_core.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
index fd503f0efb57..8a3c880fdb26 100644
--- a/net/netfilter/ipvs/ip_vs_core.c
+++ b/net/netfilter/ipvs/ip_vs_core.c
@@ -2502,12 +2502,12 @@ static int __net_init __ip_vs_init(struct net *net)
if (ip_vs_estimator_net_init(ipvs) < 0)
goto estimator_fail;
- if (ip_vs_control_net_init(ipvs) < 0)
- goto control_fail;
-
if (ip_vs_protocol_net_init(ipvs) < 0)
goto protocol_fail;
+ if (ip_vs_control_net_init(ipvs) < 0)
+ goto control_fail;
+
if (ip_vs_app_net_init(ipvs) < 0)
goto app_fail;
@@ -2527,10 +2527,10 @@ static int __net_init __ip_vs_init(struct net *net)
conn_fail:
ip_vs_app_net_cleanup(ipvs);
app_fail:
- ip_vs_protocol_net_cleanup(ipvs);
-protocol_fail:
ip_vs_control_net_cleanup(ipvs);
control_fail:
+ ip_vs_protocol_net_cleanup(ipvs);
+protocol_fail:
ip_vs_estimator_net_cleanup(ipvs);
estimator_fail:
net->ipvs = NULL;
@@ -2547,8 +2547,8 @@ static void __net_exit __ip_vs_cleanup_batch(struct list_head *net_list)
ipvs = net_ipvs(net);
ip_vs_conn_net_cleanup(ipvs);
ip_vs_app_net_cleanup(ipvs);
- ip_vs_protocol_net_cleanup(ipvs);
ip_vs_control_net_cleanup(ipvs);
+ ip_vs_protocol_net_cleanup(ipvs);
ip_vs_estimator_net_cleanup(ipvs);
IP_VS_DBG(2, "ipvs netns %d released\n", ipvs->gen);
net->ipvs = NULL;
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH net] ipvs: fix protocol data lifetime during namespace teardown
2026-09-27 6:24 [PATCH net] ipvs: fix protocol data lifetime during namespace teardown Chengfeng Ye
@ 2026-09-30 17:21 ` Julian Anastasov
0 siblings, 0 replies; 2+ messages in thread
From: Julian Anastasov @ 2026-09-30 17:21 UTC (permalink / raw)
To: Chengfeng Ye
Cc: Simon Horman, Pablo Neira Ayuso, Florian Westphal, Phil Sutter,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Hans Schillstrom, netdev, lvs-devel, netfilter-devel, coreteam,
linux-kernel, stable
Hello,
On Sun, 27 Sep 2026, Chengfeng Ye wrote:
> IPVS frees its per-net protocol data before control cleanup cancels
> defense work and unregisters the sysctl table. A defense worker can load
> a protocol data pointer, then namespace cleanup can unlink and free that
> object before the worker dereferences pd->pp or pd->next. The worker's
> securetcp_lock does not serialize with protocol cleanup. A concurrent
> defense-mode sysctl write can reach the same timeout update path.
>
> KASAN reported:
>
> BUG: KASAN: slab-use-after-free in ip_vs_protocol_timeout_change
> Workqueue: events_long defense_work_handler
> Call Trace:
> ip_vs_protocol_timeout_change+0x1b4/0x1e0
> update_defense_level+0x63e/0xd80
> defense_work_handler+0x1e/0xc0
> Allocated by task 125:
> ip_vs_protocol_net_init+0xda/0x2f0
> __ip_vs_init+0x16b/0x240
> setup_net+0xfc/0x310
> Freed by task 12:
> ip_vs_protocol_net_cleanup+0x1d6/0x2e0
> __ip_vs_cleanup_batch+0x7d/0x100
> cleanup_net+0x38c/0x770
>
> Run control cleanup before protocol cleanup so that defense work and
> active sysctl handlers have finished before their protocol data is freed.
> Initialize protocols before exposing the control interface, and unwind
> in reverse order, to enforce the same lifetime on initialization failure.
> Protocol initialization and exit do not depend on control state.
>
> Fixes: 9330419d9aa4 ("IPVS: netns, use ip_vs_proto_data as param.")
> Cc: stable@vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Patch looks good to me for the nf tree, thanks!
Acked-by: Julian Anastasov <ja@ssi.bg>
If you want to change the order of ip_vs_protocol_init()
and ip_vs_control_init() in ip_vs_init() for consistency, you
have to send another version or a nf-next patch.
> ---
> net/netfilter/ipvs/ip_vs_core.c | 12 ++++++------
> 1 file changed, 6 insertions(+), 6 deletions(-)
>
> diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
> index fd503f0efb57..8a3c880fdb26 100644
> --- a/net/netfilter/ipvs/ip_vs_core.c
> +++ b/net/netfilter/ipvs/ip_vs_core.c
> @@ -2502,12 +2502,12 @@ static int __net_init __ip_vs_init(struct net *net)
> if (ip_vs_estimator_net_init(ipvs) < 0)
> goto estimator_fail;
>
> - if (ip_vs_control_net_init(ipvs) < 0)
> - goto control_fail;
> -
> if (ip_vs_protocol_net_init(ipvs) < 0)
> goto protocol_fail;
>
> + if (ip_vs_control_net_init(ipvs) < 0)
> + goto control_fail;
> +
> if (ip_vs_app_net_init(ipvs) < 0)
> goto app_fail;
>
> @@ -2527,10 +2527,10 @@ static int __net_init __ip_vs_init(struct net *net)
> conn_fail:
> ip_vs_app_net_cleanup(ipvs);
> app_fail:
> - ip_vs_protocol_net_cleanup(ipvs);
> -protocol_fail:
> ip_vs_control_net_cleanup(ipvs);
> control_fail:
> + ip_vs_protocol_net_cleanup(ipvs);
> +protocol_fail:
> ip_vs_estimator_net_cleanup(ipvs);
> estimator_fail:
> net->ipvs = NULL;
> @@ -2547,8 +2547,8 @@ static void __net_exit __ip_vs_cleanup_batch(struct list_head *net_list)
> ipvs = net_ipvs(net);
> ip_vs_conn_net_cleanup(ipvs);
> ip_vs_app_net_cleanup(ipvs);
> - ip_vs_protocol_net_cleanup(ipvs);
> ip_vs_control_net_cleanup(ipvs);
> + ip_vs_protocol_net_cleanup(ipvs);
> ip_vs_estimator_net_cleanup(ipvs);
> IP_VS_DBG(2, "ipvs netns %d released\n", ipvs->gen);
> net->ipvs = NULL;
> --
> 2.43.0
Regards
--
Julian Anastasov <ja@ssi.bg>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-30 17:21 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-27 6:24 [PATCH net] ipvs: fix protocol data lifetime during namespace teardown Chengfeng Ye
2026-09-30 17:21 ` Julian Anastasov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®