Re: [PATCH net] sctp: prevent peer transport count overflow
Xin Long <[email protected]> Sun, 26 Jul 2026 21:54:37 -0400
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CADvbK_dkGGDe=U5SP4nNGuFRgT4FLqbBsEggh2k7qtnhU1XfxQ@mail.gmail.com> |
On Fri, Jul 24, 2026 at 11:21=E2=80=AFPM Asim Viladi Oglu Manizada <[email protected]> wrote: > > sctp_assoc_add_peer() increments the association's 16-bit transport_count > for every new unique peer. Adding the 65,536th transport wraps the count = to > zero. > > SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payloa= d, > then copies one sockaddr_storage for every entry in transport_addr_list. > After the wrap, a diagnostic dump reserves an empty payload and writes > 8 MiB of peer addresses past the skb tail. > > Reject a new unique peer when transport_count has reached U16_MAX. Perfor= m > the check after the existing-peer lookup so a duplicate address continues > to return its existing transport at the limit. > > Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file") > Cc: [email protected] > Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix > Signed-off-by: Asim Viladi Oglu Manizada <[email protected]> > --- > net/sctp/associola.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/net/sctp/associola.c b/net/sctp/associola.c > index 62d3cc155809..b6ac0966420a 100644 > --- a/net/sctp/associola.c > +++ b/net/sctp/associola.c > @@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sct= p_association *asoc, > return peer; > } > > + if (asoc->peer.transport_count =3D=3D U16_MAX) > + return NULL; > + > peer =3D sctp_transport_new(asoc->base.net, addr, gfp); > if (!peer) > return NULL; > -- > 2.53.0 > Acked-by: Xin Long <[email protected]>