Re: [PATCH nf] netfilter: conntrack: sctp: verify vtag before state changes
Yizhou Zhao <[email protected]> Wed, 29 Jul 2026 12:56:39 +0800
| Newsgroups | gmane.linux.kernel,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network,gmane.linux.kernel.stable |
|---|---|
| Message-ID | <[email protected]> |
Hi Pablo, Thank you for the review. > On Jul 29, 2026, at 03:26, Pablo Neira Ayuso <[email protected]> wrote: > > Hi, > > On Tue, Jul 28, 2026 at 03:35:06PM +0800, Yizhou Zhao wrote: >> The packet-wide vtag check in nf_conntrack_sctp_packet() is skipped when >> the bundle map contains any chunk type with special vtag handling. The >> per-chunk path re-checks INIT, ABORT, SHUTDOWN_COMPLETE, and >> COOKIE_ECHO, but other state-changing chunks still fall through to >> sctp_new_state() without validating sh->vtag. >> >> This lets a wrong-vtag packet bundle HEARTBEAT with COOKIE_ACK, ERROR, >> SHUTDOWN, or SHUTDOWN_ACK and still advance conntrack state. That can >> desynchronize conntrack from the real SCTP association and cause denial >> of service for SCTP traffic behind a stateful firewall. > > Are you assuming a specific policy in place? The connection tracking > does not police packets, it just provides tracking. You are right, I overstated the impact. Conntrack only tracks packet state, and whether a packet is dropped depends on a firewall rule that uses that state. > > Can you provide a more specific scenario? The issue I reproduced is that a wrong-vtag [SHUTDOWN, HEARTBEAT] bundle changes SCTP conntrack state from ESTABLISHED to SHUTDOWN_SENT, while the SCTP endpoints discard the packet because of the invalid vtag. This can therefore desynchronize conntrack from the association. For example, a stateful policy that drops INVALID, accepts ESTABLISHED/RELATED, and accepts new SCTP only for INIT will see the conntrack timeout change from 210 seconds to 3 seconds. If the entry expires while the real association remains established, a later DATA packet is invalid and that policy drops it. This requires an attacker that can inject a matching SCTP 4-tuple into the firewall path, and it does not require knowing the correct vtag. > > We are seeing several reports related to the connection tracking from > your university lately. > >> Check sh->vtag before processing those chunks when conntrack already >> knows the expected direction vtag. This keeps the existing >> HEARTBEAT/HEARTBEAT_ACK learning and connection-reuse behavior for the >> `vtag == 0` cases. > > Proposed patches to hardening the connection tracking state machine > should be targeted at nf-next. I agree this is better treated as SCTP conntrack state-machine hardening. If you agree, I will respin the patch for nf-next without Fixes or stable Cc. Regards, Yizhou