]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
sctp: auth: verify auth requirement when auth_chunk is NULL
authorQing Luo <luoqing@kylinos.cn>
Tue, 21 Jul 2026 01:55:32 +0000 (09:55 +0800)
committerJakub Kicinski <kuba@kernel.org>
Wed, 22 Jul 2026 20:16:08 +0000 (13:16 -0700)
sctp_auth_chunk_verify() returns true unconditionally when
chunk->auth_chunk is NULL, silently skipping authentication.
This is incorrect when:

1. skb_clone() failed in the BH receive path, leaving auth_chunk
   NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new
   connections, so the early sctp_auth_recv_cid() check cannot
   catch this.

2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never
   called and auth_chunk remains NULL.

Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL:
if authentication is required, return false to drop the chunk;
otherwise continue normally.

Fixes: bbd0d59809f9 ("[SCTP]: Implement the receive and verification of AUTH chunk")
Signed-off-by: Qing Luo <luoqing@kylinos.cn>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260721015532.120157-2-l1138897701@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/sctp/sm_statefuns.c

index 3893b44448b3816ec1359e49f150fd26a56a1165..708fa07d5fffc7e716d342a72981ec1d16594bea 100644 (file)
@@ -643,7 +643,7 @@ static bool sctp_auth_chunk_verify(struct net *net, struct sctp_chunk *chunk,
        struct sctp_chunk auth;
 
        if (!chunk->auth_chunk)
-               return true;
+               return !sctp_auth_recv_cid(chunk->chunk_hdr->type, asoc);
 
        /* SCTP-AUTH:  auth_chunk pointer is only set when the cookie-echo
         * is supposed to be authenticated and we have to do delayed