Re: [PATCH net] sctp: stop processing a packet once its association is deleted
Xin Long <[email protected]>
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CADvbK_egNorDqoGeHb_wOZ6wVxQ_f_1jFJ5uNvXu93-KAd3rXQ@mail.gmail.com> |
On Fri, Aug 14, 2026 at 6:36 PM Hyunwoo Kim <[email protected]> wrote: > > sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is > NULL, and caches the result in chunk->asoc and chunk->transport without > taking a reference. > > A packet that matches no association is handed to the endpoint, so a peer > can bundle COOKIE ECHO, SHUTDOWN and SHUTDOWN ACK in one packet. The > COOKIE ECHO creates the association, the SHUTDOWN chunk caches it, and > with the outqueue empty the SHUTDOWN ACK reaches sctp_sf_do_9_2_final(), > so the association and its transports are freed. > > The endpoint loop has no counterpart to the asoc->base.dead check in > sctp_assoc_bh_rcv(). The next chunk writes to last_time_heard in the freed > transport and is then passed to sctp_do_sm() with the freed association. > The transport is freed through RCU, so this needs the packet to come off > the socket backlog, where the loop runs in task context. > > The endpoint loop cannot do the same check: it holds no reference on the > association, so reading asoc->base.dead would itself be a use-after-free. > Mark the packet for discard in the command interpreter, just before it > deletes the association. That is also before sctp_inq_free() releases the > chunk on the association receive path. > > sctp_sf_do_5_2_4_dupcook() issues SCTP_CMD_DELETE_TCB for the temporary > association, while the one the packet belongs to stays alive. A restarting > peer can bundle DATA behind its COOKIE ECHO, so compare against > chunk->asoc and leave that case alone. > > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Cc: [email protected] > Signed-off-by: Hyunwoo Kim <[email protected]> > --- > net/sctp/sm_sideeffect.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/net/sctp/sm_sideeffect.c b/net/sctp/sm_sideeffect.c > index 424f10a6fdba9b..94716406d602ce 100644 > --- a/net/sctp/sm_sideeffect.c > +++ b/net/sctp/sm_sideeffect.c > @@ -1332,6 +1332,10 @@ static int sctp_cmd_interpreter(enum sctp_event_type event_type, > sctp_outq_uncork(&asoc->outqueue, gfp); > local_cork = 0; > } > + /* No chunk left in this packet may use this asoc. */ > + if (event_type == SCTP_EVENT_T_CHUNK && > + chunk->asoc == asoc) > + chunk->pdiscard = 1; > /* Delete the current association. */ > sctp_cmd_delete_tcb(commands, asoc); > asoc = NULL; > -- > 2.43.0 > Acked-by: Xin Long <[email protected]> Note: I don't think the pre-existing issue reported in sashiko-gemini [1] can be reproduced, as the SCTP GSO packet can never bundle a chunk after SHUTDOWN_ACK. [1] https://sashiko.dev/#/patchset/an-YYtoqw1QpTXUL%40v4bel