]> Gentwo Git Trees - linux/.git/commit
netfilter: nft_connlimit: fix possible data race on connection count
authorFernando Fernandez Mancera <fmancera@suse.de>
Fri, 24 Oct 2025 15:54:39 +0000 (17:54 +0200)
committerFlorian Westphal <fw@strlen.de>
Wed, 29 Oct 2025 13:47:59 +0000 (14:47 +0100)
commit8d96dfdcabef00e28f0c851b1502adb679dfc6d9
tree0594169fc27f9bb3cdd8271ec32ea43fb008bc04
parent514f1dc8f2ca3101e04cdf452e53baca3a76e544
netfilter: nft_connlimit: fix possible data race on connection count

nft_connlimit_eval() reads priv->list->count to check if the connection
limit has been exceeded. This value is being read without a lock and can
be modified by a different process. Use READ_ONCE() for correctness.

Fixes: df4a90250976 ("netfilter: nf_conncount: merge lookup and add functions")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Florian Westphal <fw@strlen.de>
net/netfilter/nft_connlimit.c