[PATCH 0/10] pull request (net): ipsec 2026-08-18

Steffen Klassert <[email protected]>
Newsgroups gmane.linux.network
Message-ID <[email protected]>
1) xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
   Tighten the secpath-depth check so a full chain can't write
   past xvec[].

2) Add and revert "esp: do not unref managed frag pages in esp_ssg_unref()"
   The patch does not fully fully resolve the issue, a corrected version
   will follow.

3) xfrm: espintcp: fix UAF during close
   Synchronize espintcp close with the xfrm_trans_reinject work
   queue so the freed socket message isn't dereferenced again.

4) xfrm: drop ESP-in-TCP packets with no ingress device
   Drop queued ESP-in-TCP records whose saved ingress device has
   gone away, avoiding a NULL device deref in the XFRM input path.

5) xfrm: avoid lock inversion in nat keepalive work
   Split the NAT keepalive walk into a reference-collection phase
   and a per-state lock phase to break the AB-BA with state removal.
   This patch has some issues that are fixed with a followup patch.

6) xfrm: Fix skb double-free in xfrm_dev_direct_output()
   Stop freeing the skb unconditionally in xfrm_dev_direct_output(),
   letting local_out()'s result indicate when ownership has moved on.

7) xfrm: ah6: validate routing header segments_left
   Validate the segments_left/hdrlen invariant before rearranging
   the routing-header addresses, avoiding an OOB memmove on
   malformed HDRINCL packets.

8) xfrm: fix xfrm_state_construct() auth-trunc leak
   Detect an already-attached auth-trunc allocation by the pointer
   rather than inferring it from the algorithm id, so a prior
   attach isn't overwritten and lost.

9) xfrm: bound nat keepalive state collection
   Replace the per-state allocation in the NAT keepalive walk
   with a fixed-size batch that drains under BH-disabled locking
   and resumes from the cursor, bounding the worker's memory.

Please pull or let me know if there are problems.

Thanks!

The following changes since commit 3f1f755366687d051174739fb99f7d560202f60b:

  net: openvswitch: reject oversized nested action attrs (2026-07-11 13:09:11 +0200)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec.git tags/ipsec-2026-08-18

for you to fetch changes up to 4e9442ce551ebd84b52ad649df721e2dc28af95a:

  xfrm: bound nat keepalive state collection (2026-08-18 07:35:01 +0200)

----------------------------------------------------------------
ipsec-2026-08-18

----------------------------------------------------------------
Asim Viladi Oglu Manizada (1):
      xfrm: ah6: validate routing header segments_left

Maher Azzouzi (1):
      esp: do not unref managed frag pages in esp_ssg_unref()

Sabrina Dubroca (1):
      xfrm: espintcp: fix UAF during close

Sanghyun Park (1):
      xfrm: Fix skb double-free in xfrm_dev_direct_output()

Steffen Klassert (1):
      Revert "esp: do not unref managed frag pages in esp_ssg_unref()"

Xiang Mei (1):
      xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full

Zhiling Zou (1):
      xfrm: drop ESP-in-TCP packets with no ingress device

Zihan Xi (3):
      xfrm: avoid lock inversion in nat keepalive work
      xfrm: fix xfrm_state_construct() auth-trunc leak
      xfrm: bound nat keepalive state collection

 net/ipv6/ah6.c                | 29 ++++++++++++++---------
 net/ipv6/xfrm6_input.c        |  2 +-
 net/xfrm/espintcp.c           |  9 +++++++-
 net/xfrm/xfrm_nat_keepalive.c | 53 +++++++++++++++++++++++++++++++++++--------
 net/xfrm/xfrm_output.c        |  4 +---
 net/xfrm/xfrm_user.c          |  2 +-
 6 files changed, 73 insertions(+), 26 deletions(-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.