[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20251210110754.22620-1-fw@strlen.de>
Date: Wed, 10 Dec 2025 12:07:50 +0100
From: Florian Westphal <fw@...len.de>
To: <netdev@...r.kernel.org>
Cc: Paolo Abeni <pabeni@...hat.com>,
"David S. Miller" <davem@...emloft.net>,
Eric Dumazet <edumazet@...gle.com>,
Jakub Kicinski <kuba@...nel.org>,
<netfilter-devel@...r.kernel.org>,
pablo@...filter.org
Subject: [PATCH net 0/4] netfilter: updates for net
Hi,
The following patchset contains Netfilter fixes for *net*:
1) Fix refcount leaks in nf_conncount, from Fernando Fernandez Mancera.
This addresses a recent regression that came in the last -next
pull request.
2) Fix a null dereference in route error handling in IPVS, from Slavin
Liu. This is an ancient issue dating back to 5.1 days.
3) Always set ifindex in route tuple in the flowtable output path, from
Lorenzo Bianconi. This bug came in with the recent output path refactoring.
4) Prefer 'exit $ksft_xfail' over 'exit $ksft_skip' when we fail to
trigger a nat race condition to exercise the clash resolution path in
selftest infra, $ksft_skip should be reserved for missing tooling,
From myself.
Please, pull these changes from:
The following changes since commit 6bcb7727d9e612011b70d64a34401688b986d6ab:
Merge branch 'inet-frags-flush-pending-skbs-in-fqdir_pre_exit' (2025-12-10 01:15:33 -0800)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git tags/nf-25-12-10
for you to fetch changes up to b8a81b0ce539e021ac72825238aea1eb657000f0:
selftests: netfilter: prefer xfail in case race wasn't triggered (2025-12-10 11:55:59 +0100)
----------------------------------------------------------------
netfilter pull request nf-25-12-10
----------------------------------------------------------------
Fernando Fernandez Mancera (1):
netfilter: nf_conncount: fix leaked ct in error paths
Florian Westphal (1):
selftests: netfilter: prefer xfail in case race wasn't triggered
Lorenzo Bianconi (1):
netfilter: always set route tuple out ifindex
Slavin Liu (1):
ipvs: fix ipv4 null-ptr-deref in route error path
net/netfilter/ipvs/ip_vs_xmit.c | 3 +++
net/netfilter/nf_conncount.c | 25 ++++++++++++----------
net/netfilter/nf_flow_table_path.c | 4 +++-
.../selftests/net/netfilter/conntrack_clash.sh | 9 ++++----
4 files changed, 24 insertions(+), 17 deletions(-)
Powered by blists - more mailing lists