Re: [net,2/2] net: openvswitch: fix skb leak on flow key update failure during ct

From: Aaron Conole

Date: Mon Jul 27 2026 - 16:39:04 EST


Ilya Maximets <i.maximets@xxxxxxx> writes:

> ovs_ct_execute() always steals or frees the skb on failure while
> ovs_flow_key_update() does not. So, if it fails and we return right
> away, the skb ends up leaked.
>
> Fix that by breaking instead and letting the common error handling
> code at the bottom of the loop to free the skb properly.
>
> This is a very unlikely scenario as it requires the packet to become
> unparseable by applying a set of actions on a previously parseable skb,
> but should be fixed nevertheless.
>
> Reported by Sashiko.
>
> Fixes: ec0d043d05e6 ("openvswitch: Ensure flow is valid before executing ct")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Ilya Maximets <i.maximets@xxxxxxx>
> ---
> net/openvswitch/actions.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)

Reviewed-by: Aaron Conole <aconole@xxxxxxxxxx>