]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
authorHanQuan <eilaimemedsnaimel@gmail.com>
Mon, 13 Jul 2026 03:20:21 +0000 (03:20 +0000)
committerJakub Kicinski <kuba@kernel.org>
Tue, 21 Jul 2026 19:30:38 +0000 (12:30 -0700)
sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the
capacity limit for ep->auth_chunk_list, allowing it to hold up to
20 chunk entries (param_hdr.length up to 24). However, the copy
destination asoc->c.auth_chunks in struct sctp_cookie is only
SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16
chunks are added, sctp_association_init() memcpy overflows the
destination by up to 4 bytes.

Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching
the destination capacity.

Fixes: 1f485649f529 ("[SCTP]: Implement SCTP-AUTH internals")
Signed-off-by: HanQuan <eilaimemedsnaimel@gmail.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260713032021.3491702-1-zhoujian.zja@antgroup.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/sctp/auth.c

index be9782760f509340ff649f6ed663ad89dbf0829f..c901d373af803cdc92ba99d96a3d2eec0f69fcd1 100644 (file)
@@ -672,7 +672,7 @@ int sctp_auth_ep_add_chunkid(struct sctp_endpoint *ep, __u8 chunk_id)
        /* Check if we can add this chunk to the array */
        param_len = ntohs(p->param_hdr.length);
        nchunks = param_len - sizeof(struct sctp_paramhdr);
-       if (nchunks == SCTP_NUM_CHUNK_TYPES)
+       if (nchunks == SCTP_AUTH_MAX_CHUNKS)
                return -EINVAL;
 
        p->chunks[nchunks] = chunk_id;