Re: [PATCH net] sctp: validate embedded address parameter length
[email protected] Thu, 11 Jun 2026 22:30:20 +0000
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.netdev |
|---|---|
| Message-ID | <178121702013.389578.4099391378396702786.git-patchwork-notify@kernel.org> |
Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski <[email protected]>: On Tue, 9 Jun 2026 18:14:28 -0400 you wrote: > sctp_verify_asconf() and sctp_verify_param() only validate ADD_IP, DEL_IP, > and SET_PRIMARY parameters against a fixed minimum size of sizeof(struct > sctp_addip_param) + sizeof(struct sctp_paramhdr). This ensures the outer > parameter is large enough to contain an embedded address parameter header, > but does not verify that the embedded address parameter's declared length > fits within the bounds of the outer parameter. > > [...] Here is the summary with links: - [net] sctp: validate embedded address parameter length https://git.kernel.org/netdev/net/c/e9361d0ca55c You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html