Re: [PATCH net] sctp: fix addip_serial increment on ASCONF_ACK allocation failure
Jakub Kicinski <[email protected]> Tue, 28 Jul 2026 18:24:31 -0700
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 23 Jul 2026 15:18:18 +0800 luoqing wrote: > From: Qing Luo <[email protected]> > > In sctp_process_asconf(), when sctp_make_asconf_ack() fails to allocate > the ASCONF_ACK chunk due to memory pressure, the code jumps to the > done label where asoc->peer.addip_serial is unconditionally incremented. > > This leaves the peer's ASCONF (serial N) unacknowledged while the local > endpoint now expects serial N+1. When the peer retransmits serial N, it > falls into the serial < addip_serial + 1 branch , > which attempts to look up a cached ACK for serial N. No cached ACK > exists since the allocation failed, so the retransmission is silently > discarded. The peer eventually times out and ABORTs the association. > > Move the addip_serial increment inside the if (asconf_ack) block so that > the serial number is only advanced when the ASCONF_ACK is successfully > created and cached. This way, on allocation failure, the serial number > is unchanged and the peer's retransmitted ASCONF will be correctly > re-processed. > > Fixes: 1da177e4c3f4 (Linux-2.6.12-rc2) nit: missing quotation marks around the subject -- pw-bot: cr