tree f7ca2a5965738ea5d8ca9781cd6f941c544496b8
parent 81668026811f1248b6eaa73f8f60a949614ea3d1
author Pablo Neira Ayuso <pablo@netfilter.org> 1707328191 +0100
committer COS Cherry Picker <cloud-image-release@prod.google.com> 1708987047 -0800

netfilter: nft_set_rbtree: skip end interval element from gc

commit 60c0c230c6f046da536d3df8b39a20b9a9fd6af0 upstream.

rbtree lazy gc on insert might collect an end interval element that has
been just added in this transactions, skip end interval elements that
are not yet active.

BUG=b/325656688
TEST=presubmit
RELEASE_NOTE=Fixed CVE-2024-26581 in the Linux kernel.

cos-patch: security-high
Fixes: f718863aca46 ("netfilter: nft_set_rbtree: fix overlap expiration walk")
Cc: stable@vger.kernel.org
Reported-by: lonial con <kongln9170@gmail.com>
Change-Id: If8cc1a513a524d4e45cd8a7eceaab97aa9109410
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 1296c110c5a0b45a8fcf58e7d18bc5da61a565cb)
Signed-off-by: Robert Kolchmeyer <rkolchmeyer@google.com>
Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/65322
Tested-by: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
Main-Branch-Verified: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
Reviewed-by: Oleksandr Tymoshenko <ovt@google.com>
