Re: [PATCH net v2] sctp: validate stream count in sctp_process_strreset_inreq()

[email protected] Tue, 21 Jul 2026 21:00:08 +0000
Newsgroups org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <178466760889.1059197.2799666690554843790.git-patchwork-notify@kernel.org>
Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <[email protected]>:

On Thu,  9 Jul 2026 21:07:18 -0400 you wrote:
> When processing a RESET_IN_REQUEST from a peer,
> sctp_process_strreset_inreq() derives the stream count from the
> parameter length but does not check whether the resulting
> RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.
> 
> The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
> larger than the IN request header (sctp_strreset_inreq, 8 bytes).
> Generally, the IP payload is bounded to 65535 bytes, so the stream
> list cannot be large enough to trigger the overflow. However, on
> interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a
> stream list that fits within the incoming IN parameter can cause a
> __u16 overflow in sctp_make_strreset_req() when computing the OUT
> request size, leading to an undersized skb allocation and a kernel
> BUG:
> 
> [...]

Here is the summary with links:
  - [net,v2] sctp: validate stream count in sctp_process_strreset_inreq()
    https://git.kernel.org/netdev/net/c/18ae07691d43

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html