| commit | 2ffcc1008ec07bc0d54abf1e34ffa84d16b697cb | [log] [tgz] |
|---|---|---|
| author | Slavin Liu <[email protected]> | Fri Sep 12 01:57:59 2025 +0800 |
| committer | Cloud Image Release <[email protected]> | Tue Oct 07 16:08:07 2025 -0700 |
| tree | 368f23716846afcc8f591f42626106e64ce731ae | |
| parent | fd4b4207f1f75c6e71a4e1a9d57f8abc08b300cd [diff] |
ipvs: Defer ip_vs_ftp unregister during netns cleanup
On the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp
before connections with valid cp->app pointers are flushed, leading to a
use-after-free.
Fix this by introducing a global `exiting_module` flag, set to true in
ip_vs_ftp_exit() before unregistering the pernet subsystem. In
__ip_vs_ftp_exit(), skip ip_vs_ftp unregister if called during netns
cleanup (when exiting_module is false) and defer it to
__ip_vs_cleanup_batch(), which unregisters all apps after all connections
are flushed. If called during module exit, unregister ip_vs_ftp
immediately.
BUG=b/449335583
TEST=presubmit,validation
RELEASE_NOTE=Fixed KCTF-134121b in the Linux kernel.
cos-patch: security-high
Fixes: 61b1ab4583e2 ("IPVS: netns, add basic init per netns.")
Suggested-by: Julian Anastasov <[email protected]>
Change-Id: If409c0fd0c23bc70ba59795f95301a0aff89825a
Signed-off-by: Slavin Liu <[email protected]>
Signed-off-by: Julian Anastasov <[email protected]>
Signed-off-by: Florian Westphal <[email protected]>
Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/113623
Tested-by: Cusky Presubmit Bot <[email protected]>
Reviewed-by: Chenglong Tang <[email protected]>
Main-Branch-Verified: Cusky Presubmit Bot <[email protected]>
Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/113666