Re: [PATCH v4 net] sctp: auth: verify auth requirement when auth_chunk is NULL
Xin Long <[email protected]> Wed, 22 Jul 2026 13:37:09 -0400
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CADvbK_cP69nhZJShW4_vVf1zsccTW_xQ1bGJnYwbhaLCLLsF6Q@mail.gmail.com> |
On Mon, Jul 20, 2026 at 9:56=E2=80=AFPM luoqing <[email protected]> wrote= : > > From: Qing Luo <[email protected]> > > sctp_auth_chunk_verify() returns true unconditionally when > chunk->auth_chunk is NULL, silently skipping authentication. > This is incorrect when: > > 1. skb_clone() failed in the BH receive path, leaving auth_chunk > NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new > connections, so the early sctp_auth_recv_cid() check cannot > catch this. > > 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never > called and auth_chunk remains NULL. > > Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: > if authentication is required, return false to drop the chunk; > otherwise continue normally. > > Fixes: bbd0d59809f9 ("[SCTP]: Implement the receive and verification of A= UTH chunk") > Signed-off-by: Qing Luo <[email protected]> > --- > net/sctp/sm_statefuns.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c > index d23d935e128e..89ed618b1de3 100644 > --- a/net/sctp/sm_statefuns.c > +++ b/net/sctp/sm_statefuns.c > @@ -642,7 +642,7 @@ static bool sctp_auth_chunk_verify(struct net *net, s= truct sctp_chunk *chunk, > struct sctp_chunk auth; > > if (!chunk->auth_chunk) > - return true; > + return !sctp_auth_recv_cid(chunk->chunk_hdr->type, asoc); > > /* SCTP-AUTH: auth_chunk pointer is only set when the cookie-ech= o > * is supposed to be authenticated and we have to do delayed > -- > 2.25.1 > Acked-by: Xin Long <[email protected]>