[PATCH net 1/1] sctp: avoid auth_enable sysctl UAF during netns teardown

Ren Wei <[email protected]> Sun, 28 Jun 2026 16:39:54 +0800
Newsgroups org.kernel.vger.linux-sctp,org.kernel.vger.netdev
Message-ID <b9f1f02b0780ad6a719e2413f5f0bb8eb7702d94.1782585631.git.roxy520tt@gmail.com>
From: Zhiling Zou <[email protected]>

proc_sctp_do_auth() updates the SCTP control socket after changing
net.sctp.auth_enable.  The handler gets the per-net SCTP state from
ctl->data, so an already opened sysctl file can still target a network
namespace while that namespace is being torn down.

SCTP unregisters its per-net sysctls from sctp_defaults_exit(), but
sctp_ctrlsock_exit() runs earlier because the control-socket pernet ops
are registered after the defaults ops.  This leaves a teardown window
where auth_enable is still writable after inet_ctl_sock_destroy() has
released net->sctp.ctl_sock, leading to a use-after-free when the sysctl
handler locks and dereferences the stale socket.

Unregister the per-net SCTP sysctl table before destroying the control
socket.  Make sctp_sysctl_net_unregister() tolerate a missing header and
clear the saved pointer so the later defaults exit path and init-error
path can safely share the same unregister helper.

Fixes: 15649fd5415e ("sctp: sysctl: auth_enable: avoid using current->nsproxy")
Cc: [email protected]
Reported-by: Yuan Tan <[email protected]>
Reported-by: Yifan Wu <[email protected]>
Reported-by: Juefei Pu <[email protected]>
Reported-by: Xin Liu <[email protected]>
Assisted-by: Codex:gpt-5.4
Signed-off-by: Zhiling Zou <[email protected]>
Signed-off-by: Ren Wei <[email protected]>
---
 net/sctp/protocol.c | 3 +++
 net/sctp/sysctl.c   | 9 +++++++--
 2 files changed, 10 insertions(+), 2 deletions(-)

diff --git a/net/sctp/protocol.c b/net/sctp/protocol.c
index 587b0017a67d..ae381d304bd5 100644
--- a/net/sctp/protocol.c
+++ b/net/sctp/protocol.c
@@ -1457,8 +1457,11 @@ static int __net_init sctp_ctrlsock_init(struct net *net)
 
 static void __net_exit sctp_ctrlsock_exit(struct net *net)
 {
+	sctp_sysctl_net_unregister(net);
+
 	/* Free the control endpoint.  */
 	inet_ctl_sock_destroy(net->sctp.ctl_sock);
+	net->sctp.ctl_sock = NULL;
 }
 
 static struct pernet_operations sctp_ctrlsock_ops = {
diff --git a/net/sctp/sysctl.c b/net/sctp/sysctl.c
index 15e7db9a3ab2..fca840484ebf 100644
--- a/net/sctp/sysctl.c
+++ b/net/sctp/sysctl.c
@@ -615,11 +615,16 @@ int sctp_sysctl_net_register(struct net *net)
 
 void sctp_sysctl_net_unregister(struct net *net)
 {
+	struct ctl_table_header *header = net->sctp.sysctl_header;
 	const struct ctl_table *table;
 
-	table = net->sctp.sysctl_header->ctl_table_arg;
-	unregister_net_sysctl_table(net->sctp.sysctl_header);
+	if (!header)
+		return;
+
+	table = header->ctl_table_arg;
+	unregister_net_sysctl_table(header);
 	kfree(table);
+	net->sctp.sysctl_header = NULL;
 }
 
 static struct ctl_table_header *sctp_sysctl_header;
-- 
2.43.0