Re: nft_set_pipapo: UAF and double free from a stranded GC batch in the 5.15.y / 6.1.y / 6.6.y backports of 9df95785d3d8
Greg KH <[email protected]> Tue, 4 Aug 2026 08:01:12 +0200
| Newsgroups | gmane.linux.network,gmane.linux.kernel.stable,gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <2026080436-dyslexic-willfully-fb2e@gregkh> |
On Mon, Aug 03, 2026 at 09:19:28PM +0300, Fahad Alharbi wrote:
> Hello,
>
> 6.6.148 backported the pipapo on-demand-clone series, but two commits from
> the original 2024 series were not included. Two consequences are visible in
> the source. Both are straightforward to confirm; no reproducer is needed.
>
> Requested trees: 6.6.y
>
> Missing commits:
>
> 8b8a2417558c ("netfilter: nft_set_pipapo: prepare destroy function for
> on-demand clone")
> 532aec7e878b ("netfilter: nft_set_pipapo: remove dirty flag")
>
> Both are Florian Westphal, 2024-04-25, and both are present in 6.10.y
> through 7.1.y and in mainline. Neither is in 6.6.y.
That is because they do not cleanly apply there. Can you provide
working backports for that tree, and any other older tree that you think
needs it, so we can queue them up?
thanks,
greg k-h