[PATCH net 1/1] sctp: stream: clear out_curr when freeing stream data
Ren Wei <[email protected]> Thu, 28 May 2026 15:51:00 +0800
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.netdev |
|---|---|
| Message-ID | <cd2b851530e741d4878ee7db59cba895d70e672a.1779640196.git.xuyq21@lenovo.com> |
From: Yuqi Xu <[email protected]> out_curr caches the current outbound stream and points into the stream->out storage. Once the stream tables are torn down, that pointer is no longer valid and must not survive the teardown. sctp_stream_update() frees the old stream tables before installing the new ones. If out_curr still points into the old outbound table, later dequeue paths can continue from stale scheduler state instead of falling back to the normal queue walk. Clear out_curr in sctp_stream_free(), which owns the lifetime of the stream storage and covers every teardown caller. Fixes: 5bbbbe32a431 ("sctp: introduce stream scheduler foundations") Cc: [email protected] Reported-by: Yuan Tan <[email protected]> Reported-by: Yifan Wu <[email protected]> Reported-by: Juefei Pu <[email protected]> Reported-by: Zhengchuan Liang <[email protected]> Reported-by: Xin Liu <[email protected]> Assisted-by: Codex:GPT-5.4 Signed-off-by: Yuqi Xu <[email protected]> Signed-off-by: Ren Wei <[email protected]> --- net/sctp/stream.c | 1 + 1 file changed, 1 insertion(+) diff --git a/net/sctp/stream.c b/net/sctp/stream.c index c2247793c88b..207e0a77f9af 100644 --- a/net/sctp/stream.c +++ b/net/sctp/stream.c @@ -186,6 +186,7 @@ void sctp_stream_free(struct sctp_stream *stream) int i; sched->unsched_all(stream); + stream->out_curr = NULL; for (i = 0; i < stream->outcnt; i++) sctp_stream_free_ext(stream, i); genradix_free(&stream->out); -- 2.54.0