Re: [PATCH net] sctp: prevent peer transport count overflow

Xin Long <[email protected]> Sun, 26 Jul 2026 21:54:37 -0400
Newsgroups org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <CADvbK_dkGGDe=U5SP4nNGuFRgT4FLqbBsEggh2k7qtnhU1XfxQ@mail.gmail.com>
On Fri, Jul 24, 2026 at 11:21=E2=80=AFPM Asim Viladi Oglu Manizada
<[email protected]> wrote:
>
> sctp_assoc_add_peer() increments the association's 16-bit transport_count
> for every new unique peer. Adding the 65,536th transport wraps the count =
to
> zero.
>
> SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payloa=
d,
> then copies one sockaddr_storage for every entry in transport_addr_list.
> After the wrap, a diagnostic dump reserves an empty payload and writes
> 8 MiB of peer addresses past the skb tail.
>
> Reject a new unique peer when transport_count has reached U16_MAX. Perfor=
m
> the check after the existing-peer lookup so a duplicate address continues
> to return its existing transport at the limit.
>
> Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
> Cc: [email protected]
> Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
> Signed-off-by: Asim Viladi Oglu Manizada <[email protected]>
> ---
>  net/sctp/associola.c | 3 +++
>  1 file changed, 3 insertions(+)
>
> diff --git a/net/sctp/associola.c b/net/sctp/associola.c
> index 62d3cc155809..b6ac0966420a 100644
> --- a/net/sctp/associola.c
> +++ b/net/sctp/associola.c
> @@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sct=
p_association *asoc,
>                 return peer;
>         }
>
> +       if (asoc->peer.transport_count =3D=3D U16_MAX)
> +               return NULL;
> +
>         peer =3D sctp_transport_new(asoc->base.net, addr, gfp);
>         if (!peer)
>                 return NULL;
> --
> 2.53.0
>
Acked-by: Xin Long <[email protected]>