Re: [PATCH nf] netfilter: conntrack: sctp: verify vtag before state changes
Pablo Neira Ayuso <[email protected]> Fri, 31 Jul 2026 12:33:20 +0200
| Newsgroups | gmane.linux.kernel.stable,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network,gmane.linux.kernel |
|---|---|
| Message-ID | <amx58O5Jb6B29XDJ@chamomile> |
On Wed, Jul 29, 2026 at 12:56:39PM +0800, Yizhou Zhao wrote: > Hi Pablo, > > Thank you for the review. > > > On Jul 29, 2026, at 03:26, Pablo Neira Ayuso <[email protected]> wrote: > > > > Hi, > > > > On Tue, Jul 28, 2026 at 03:35:06PM +0800, Yizhou Zhao wrote: > >> The packet-wide vtag check in nf_conntrack_sctp_packet() is skipped when > >> the bundle map contains any chunk type with special vtag handling. The > >> per-chunk path re-checks INIT, ABORT, SHUTDOWN_COMPLETE, and > >> COOKIE_ECHO, but other state-changing chunks still fall through to > >> sctp_new_state() without validating sh->vtag. > >> > >> This lets a wrong-vtag packet bundle HEARTBEAT with COOKIE_ACK, ERROR, > >> SHUTDOWN, or SHUTDOWN_ACK and still advance conntrack state. That can > >> desynchronize conntrack from the real SCTP association and cause denial > >> of service for SCTP traffic behind a stateful firewall. > > > > Are you assuming a specific policy in place? The connection tracking > > does not police packets, it just provides tracking. > > You are right, I overstated the impact. Conntrack only tracks packet > state, and whether a packet is dropped depends on a firewall rule that > uses that state. > > > > > Can you provide a more specific scenario? > > The issue I reproduced is that a wrong-vtag [SHUTDOWN, HEARTBEAT] bundle > changes SCTP conntrack state from ESTABLISHED to SHUTDOWN_SENT, while the > SCTP endpoints discard the packet because of the invalid vtag. This can > therefore desynchronize conntrack from the association. > > For example, a stateful policy that drops INVALID, accepts > ESTABLISHED/RELATED, and accepts new SCTP only for INIT will see the > conntrack timeout change from 210 seconds to 3 seconds. If the entry > expires while the real association remains established, a later DATA > packet is invalid and that policy drops it. This requires an attacker > that can inject a matching SCTP 4-tuple into the firewall path, and it does > not require knowing the correct vtag. > > > > > We are seeing several reports related to the connection tracking from > > your university lately. > > > >> Check sh->vtag before processing those chunks when conntrack already > >> knows the expected direction vtag. This keeps the existing > >> HEARTBEAT/HEARTBEAT_ACK learning and connection-reuse behavior for the > >> `vtag == 0` cases. > > > > Proposed patches to hardening the connection tracking state machine > > should be targeted at nf-next. > > I agree this is better treated as SCTP conntrack state-machine hardening. > If you agree, I will respin the patch for nf-next without Fixes or stable Cc. Yes, repurpose this patch to nf-next without Fixes tag and stable for review. Thanks.