]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
sctp: prevent peer transport count overflow
authorAsim Viladi Oglu Manizada <manizada@pm.me>
Sat, 25 Jul 2026 03:21:06 +0000 (03:21 +0000)
committerJakub Kicinski <kuba@kernel.org>
Mon, 27 Jul 2026 22:45:24 +0000 (15:45 -0700)
sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.

SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.

Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.

Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
Cc: stable@vger.kernel.org
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/sctp/associola.c

index 62d3cc155809c72c46a3d75df0335c0009895b71..b6ac0966420a1f2e8bcbf14df7f4522d9895173f 100644 (file)
@@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
                return peer;
        }
 
+       if (asoc->peer.transport_count == U16_MAX)
+               return NULL;
+
        peer = sctp_transport_new(asoc->base.net, addr, gfp);
        if (!peer)
                return NULL;