Re: [PATCH net v2] sctp: Prevent TOCTOU out-of-bounds write
Kuniyuki Iwashima <[email protected]>
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CAAVpQUAHHVUBQZ=fgCUe8Mg9CD6d=CutyEsE4m82TGdt+VqpNQ@mail.gmail.com> |
Thanks for the patch. On Mon, Oct 27, 2025 at 3:16 AM Stefan Wiehler <[email protected]> wrote: > > Make sure not to exceed bounds in case the address list has grown > between buffer allocation (time-of-check) and write (time-of-use). Could you elaborate a bit more context here like which path we don't hold lock_sock() as Xin confirmed in this thread ? https://lore.kernel.org/netdev/CADvbK_ddE0oUPXijkFJbWF6tFTq5TntpFMzDWH+uV_kc+KB7VA@mail.gmail.com/ Also, it would be better to post the two patches as a series git send-email --annotate --cover-letter --thread --no-chain-reply-to \ --subject-prefix "PATCH v3 net" \ --to ... > > Suggested-by: Kuniyuki Iwashima <[email protected]> > Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file") > Signed-off-by: Stefan Wiehler <[email protected]> > --- > V1 -> V2: Add changelog and credit > --- > net/sctp/diag.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/net/sctp/diag.c b/net/sctp/diag.c > index 996c2018f0e6..4ee44e0111ae 100644 > --- a/net/sctp/diag.c > +++ b/net/sctp/diag.c > @@ -85,6 +85,9 @@ static int inet_diag_msg_sctpladdrs_fill(struct sk_buff *skb, > memcpy(info, &laddr->a, sizeof(laddr->a)); > memset(info + sizeof(laddr->a), 0, addrlen - sizeof(laddr->a)); > info += addrlen; > + > + if (!--addrcnt) > + break; > } > > return 0; > -- > 2.51.0 >