Re: [PATCH net v9 1/1] openvswitch: Fix CT limit teardown use-after-free

From: Ilya Maximets

Date: Fri Aug 21 2026 - 17:29:48 EST


On 8/21/26 5:19 AM, Yuqi Xu wrote:
> Packet processing uses CT limit state under RCU, while netns teardown
> frees that state under ovs_mutex. The CT limit pointer was neither removed
> from readers nor protected by a grace period, allowing packet processing to
> dereference the freed state.
>
> An unprivileged user can trigger this bug from a user and network
> namespace, causing a slab-use-after-free in ovs_ct_execute() when the
> netns is torn down.
>
> Publish the CT limit pointer through RCU, remove it before teardown, and
> wait for readers before freeing its contents. Keep ovs_mutex around
> individual CT limit updates, and use the RCU read-side lock while GET
> traverses the RCU-protected limit lists.
>
> Netns teardown detaches the RCU-protected CT limit state in the pernet
> .pre_exit callback while holding ovs_mutex. The pernet core guarantees an
> RCU grace period between the .pre_exit and .exit callbacks, so the .exit
> callback completes the teardown without adding any extra synchronization.
>
> The netlink command handlers do not need NULL checks because the userspace
> netlink socket holds an active reference to its network namespace while a
> request is processed. The per-netns exit path therefore cannot run
> concurrently with SET, DEL, or GET for that socket's namespace.
>
> Fixes: 11efd5cb04a1 ("openvswitch: Support conntrack zone limit")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: Vega <vega@xxxxxxxxxx>
> Link: https://lore.kernel.org/all/cover.1784711445.git.xuyuqiabc@xxxxxxxxx
> Assisted-by: Codex:GPT-5.4
> Co-developed-by: Nan Li <tonanli66@xxxxxxxxx>
> Signed-off-by: Nan Li <tonanli66@xxxxxxxxx>
> Signed-off-by: Yuqi Xu <xuyuqiabc@xxxxxxxxx>
> Reviewed-by: Ren Wei <enjou1224z@xxxxxxxxx>
> ---
>
> Changes in v9:
>
> - Rebase onto net/main.
> - Drop the data parameter from ovs_ct_exit_finish() and read the detached
> state from ovs_net directly, fixing the build with
> CONFIG_NETFILTER_CONNCOUNT disabled.
> - Rename ct_exit_data to ct_limit_exit_data and stop moving declarations
> around in ovs_exit_net().
> - v8 Link: https://lore.kernel.org/all/cover.1787129643.git.xuyuqiabc@xxxxxxxxx/
>

Reviewed-by: Ilya Maximets <i.maximets@xxxxxxx>