From mboxrd@z Thu Jan 1 00:00:00 1970 From: Xin Long Subject: [PATCH net] sctp: fix the issue that pathmtu may be set lower than MINSEGMENT Date: Mon, 2 Jul 2018 14:51:16 +0800 Message-ID: <0928f7dda7db59c8aa01e97a87792d9e643e70ab.1530514276.git.lucien.xin@gmail.com> Cc: davem@davemloft.net, Marcelo Ricardo Leitner , Neil Horman , syzkaller@googlegroups.com To: network dev , linux-sctp@vger.kernel.org Return-path: Received: from mail-pg0-f65.google.com ([74.125.83.65]:40254 "EHLO mail-pg0-f65.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753216AbeGBGvY (ORCPT ); Mon, 2 Jul 2018 02:51:24 -0400 Sender: netdev-owner@vger.kernel.org List-ID: After commit b6c5734db070 ("sctp: fix the handling of ICMP Frag Needed for too small MTUs"), sctp_transport_update_pmtu would refetch pathmtu from the dst and set it to transport's pathmtu without any check. The new pathmtu may be lower than MINSEGMENT if the dst is obsolete and updated by .get_dst() in sctp_transport_update_pmtu. Syzbot reported a warning in sctp_mtu_payload caused by this. This fix uses the refetched pathmtu only when it's greater than the frag_needed pmtu. Fixes: b6c5734db070 ("sctp: fix the handling of ICMP Frag Needed for too small MTUs") Reported-by: syzbot+f0d9d7cba052f9344b03@syzkaller.appspotmail.com Signed-off-by: Xin Long --- net/sctp/transport.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net/sctp/transport.c b/net/sctp/transport.c index 445b7ef..ddfb687 100644 --- a/net/sctp/transport.c +++ b/net/sctp/transport.c @@ -282,7 +282,10 @@ bool sctp_transport_update_pmtu(struct sctp_transport *t, u32 pmtu) if (dst) { /* Re-fetch, as under layers may have a higher minimum size */ - pmtu = SCTP_TRUNC4(dst_mtu(dst)); + u32 mtu = SCTP_TRUNC4(dst_mtu(dst)); + + if (pmtu < mtu) + pmtu = mtu; change = t->pathmtu != pmtu; } t->pathmtu = pmtu; -- 2.1.0