On 8/14/26 3:40 PM, Ruoyu Wang wrote:
> ovs_ct_init() acquires a connlabels reference before initializing the
> conntrack limit state. If ovs_ct_limit_init() fails, its error is returned
> directly. The pernet core does not invoke the exit callback for the
> operation whose initialization failed, so ovs_ct_exit() cannot drop the
> reference.
> 
> This leaves labels_used elevated when Open vSwitch pernet registration
> fails for an existing network namespace. Subsequent conntrack entries in
> that namespace may allocate label extensions even though Open vSwitch
> failed to register.
> 
> Drop the connlabels reference before returning a conntrack limit
> initialization error. ovs_ct_limit_init() already releases its partial
> state, and the original error remains unchanged.
> 
> This issue was found by a static analysis checker and confirmed by
> manual source review.
> 
> Fixes: 11efd5cb04a1 ("openvswitch: Support conntrack zone limit")

Should add Cc: for the stable here.

> Signed-off-by: Ruoyu Wang <[email protected]>
> ---
>  net/openvswitch/conntrack.c | 8 +++++++-
>  1 file changed, 7 insertions(+), 1 deletion(-)
> 
> diff --git a/net/openvswitch/conntrack.c b/net/openvswitch/conntrack.c
> index 95697d4e16e64..fbaa677144143 100644
> --- a/net/openvswitch/conntrack.c
> +++ b/net/openvswitch/conntrack.c
> @@ -2001,6 +2001,9 @@ int ovs_ct_init(struct net *net)
>  {
>       unsigned int n_bits = sizeof(struct ovs_key_ct_labels) * BITS_PER_BYTE;
>       struct ovs_net *ovs_net = net_generic(net, ovs_net_id);
> +#if  IS_ENABLED(CONFIG_NETFILTER_CONNCOUNT)
> +     int err;
> +#endif

No need to guard it with a macro.  It should be cleaner to initialize
as zero and return err in both cases in the end.

>  
>       if (nf_connlabels_get(net, n_bits - 1)) {
>               ovs_net->xt_label = false;
> @@ -2010,7 +2013,10 @@ int ovs_ct_init(struct net *net)
>       }
>  
>  #if  IS_ENABLED(CONFIG_NETFILTER_CONNCOUNT)
> -     return ovs_ct_limit_init(net, ovs_net);
> +     err = ovs_ct_limit_init(net, ovs_net);
> +     if (err && ovs_net->xt_label)
> +             nf_connlabels_put(net);
> +     return err;
>  #else
>       return 0;
>  #endif

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to