Re: [PATCH net v3] sctp: fix NULL deref on untransmitted RECONF completion

Xin Long <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.linux-kernel,org.kernel.vger.linux-sctp,org.kernel.vger.stable
Message-ID <CADvbK_c6rqUdxyMSC=XF7ShHbjHSY1d2wEUmYpr0RGO+E0i_Kg@mail.gmail.com>
On Sun, Aug 23, 2026 at 1:29 PM Weiming Shi <[email protected]> wrote:
>
> sctp_process_strreset_outreq(), sctp_process_strreset_addstrm_out() and
> sctp_process_strreset_resp() complete a pending stream reconfiguration
> request by stopping the reconf timer on the transport it was sent on:
>
>         t = asoc->strreset_chunk->transport;
>         if (timer_delete(&t->reconf_timer))
>                 sctp_transport_put(t);
>
> chunk->transport is assigned by __sctp_packet_append_chunk() when the
> chunk is appended to an outbound packet, and sctp_outq_flush_ctrl() arms
> the reconf timer at that same point. A request already published in
> asoc->strreset_chunk but not yet transmitted has neither, so completing
> it dereferences NULL.
>
> Two ways to get there. sctp_send_asconf_del_ip() sets
> asoc->src_out_of_asoc_ok without sending anything when the address being
> removed is the association's last one, and sctp_outq_flush_ctrl() then
> leaves every non-ASCONF control chunk queued; as only
> sctp_process_asconf_ack() clears that flag, it persists. An unprivileged
> process that removes such an address and then asks for a stream reset
> panics the kernel from softirq. A peer needs neither ASCONF nor local
> help: sctp_cmd_interpreter() uncorks the outqueue only once the whole
> packet has been processed, so a reply built while walking a RECONF chunk
> stays untransmitted for the rest of that walk, and one RECONF chunk
> carrying [Incoming SSN Reset Request, Outgoing SSN Reset Request,
> Response] -- or two RECONF chunks in one packet -- reaches the same
> dereference.
>
>   KASAN: null-ptr-deref in range [0x00000000000001e8-0x00000000000001ef]
>   RIP: 0010:timer_delete+0x67/0x110
>   Call Trace:
>    <IRQ>
>    sctp_process_strreset_addstrm_out (net/sctp/stream.c:832)
>    sctp_sf_do_reconf (net/sctp/sm_statefuns.c:4212)
>    sctp_do_sm (net/sctp/sm_sideeffect.c:1172)
>    sctp_assoc_bh_rcv (net/sctp/associola.c:1044)
>    sctp_rcv (net/sctp/input.c:243)
>    ip_local_deliver (net/ipv4/ip_input.c:262)
>    process_backlog (net/core/dev.c:6680)
>    </IRQ>
>
> A response can only acknowledge a request that was actually sent, so do
> not match asoc->strreset_chunk while chunk->transport is NULL. Guarding
> the lookup covers all three completion sites.
>
> Fixes: 810544764536 ("sctp: implement receiver-side procedures for the Outgoing SSN Reset Request Parameter")
> Cc: [email protected]
> Reported-by: Xiang Mei <[email protected]>
> Suggested-by: Xin Long <[email protected]>
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: Weiming Shi <[email protected]>
> ---
>
> v3:
> - No code change; v2's changelog linked the wrong v1 posting.
>
> v2: https://lore.kernel.org/linux-sctp/[email protected]/
> v1: https://lore.kernel.org/linux-sctp/[email protected]/
>  net/sctp/stream.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/net/sctp/stream.c b/net/sctp/stream.c
> index 34ffe6c945a4..2012f61e250e 100644
> --- a/net/sctp/stream.c
> +++ b/net/sctp/stream.c
> @@ -488,7 +488,7 @@ static struct sctp_paramhdr *sctp_chunk_lookup_strreset_param(
>         struct sctp_reconf_chunk *hdr;
>         union sctp_params param;
>
> -       if (!chunk)
> +       if (!chunk || !chunk->transport)
>                 return NULL;
>
>         hdr = (struct sctp_reconf_chunk *)chunk->chunk_hdr;
> --
> 2.55.0
>

Acked-by: Xin Long <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.