* [PATCH net v3 1/2] sctp: avoid auth_enable sysctl UAF during netns teardown
[not found] <cover.1784033357.git.roxy520tt@gmail.com>
@ 2026-07-15 1:50 ` Ren Wei
2026-07-16 13:31 ` Xin Long
2026-07-21 21:20 ` patchwork-bot+netdevbpf
2026-07-15 1:50 ` [PATCH net v3 2/2] sctp: close UDP tunnel sockets " Ren Wei
1 sibling, 2 replies; 5+ messages in thread
From: Ren Wei @ 2026-07-15 1:50 UTC (permalink / raw)
To: linux-sctp, netdev
Cc: marcelo.leitner, lucien.xin, davem, edumazet, pabeni, horms,
matttbe, yuantan098, yifanwucs, tomapufckgml, bird, tpluszz77,
roxy520tt, n05ec, sashiko-bot
From: Zhiling Zou <roxy520tt@gmail.com>
proc_sctp_do_auth() updates the SCTP control socket after changing
net.sctp.auth_enable. The handler gets the per-net SCTP state from
ctl->data, so an already opened sysctl file can still target a network
namespace while that namespace is being torn down.
SCTP previously registered its per-net sysctls from sctp_defaults_init(),
while the control socket is created later from sctp_ctrlsock_init(). This
exposed a window during initialization where auth_enable was writable
before net->sctp.ctl_sock existed, and a teardown window where auth_enable
stayed writable after inet_ctl_sock_destroy() had released the control
socket.
Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after
sctp_ctl_sock_init() succeeds, and unregister the sysctl table before
destroying the control socket in sctp_ctrlsock_exit(). If sysctl
registration fails after the control socket was created, destroy the
control socket in the same init path.
Make sctp_sysctl_net_unregister() tolerate a missing header and clear the
saved pointer so init-error and exit paths can safely share the unregister
helper.
Fixes: 15649fd5415e ("sctp: sysctl: auth_enable: avoid using current->nsproxy")
Cc: stable@vger.kernel.org
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Yifan Wu <yifanwucs@gmail.com>
Reported-by: Juefei Pu <tomapufckgml@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Co-developed-by: Qi Tang <tpluszz77@gmail.com>
Signed-off-by: Qi Tang <tpluszz77@gmail.com>
Signed-off-by: Zhiling Zou <roxy520tt@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
---
Changes in v3:
- Follow Xin Long's suggestion and return immediately when
sctp_ctl_sock_init() fails.
- Keep per-net SCTP sysctl registration in a separate success path after
the control socket has been created.
net/sctp/protocol.c | 20 ++++++++++++--------
net/sctp/sysctl.c | 9 +++++++--
2 files changed, 19 insertions(+), 10 deletions(-)
diff --git a/net/sctp/protocol.c b/net/sctp/protocol.c
index cf335494bffe..49d9740b1e0f 100644
--- a/net/sctp/protocol.c
+++ b/net/sctp/protocol.c
@@ -1383,10 +1383,6 @@ static int __net_init sctp_defaults_init(struct net *net)
net->sctp.l3mdev_accept = 1;
#endif
- status = sctp_sysctl_net_register(net);
- if (status)
- goto err_sysctl_register;
-
/* Allocate and initialise sctp mibs. */
status = init_sctp_mibs(net);
if (status)
@@ -1420,8 +1416,6 @@ static int __net_init sctp_defaults_init(struct net *net)
cleanup_sctp_mibs(net);
#endif
err_init_mibs:
- sctp_sysctl_net_unregister(net);
-err_sysctl_register:
return status;
}
@@ -1436,7 +1430,6 @@ static void __net_exit sctp_defaults_exit(struct net *net)
net->sctp.proc_net_sctp = NULL;
#endif
cleanup_sctp_mibs(net);
- sctp_sysctl_net_unregister(net);
}
static struct pernet_operations sctp_defaults_ops = {
@@ -1450,16 +1443,27 @@ static int __net_init sctp_ctrlsock_init(struct net *net)
/* Initialize the control inode/socket for handling OOTB packets. */
status = sctp_ctl_sock_init(net);
- if (status)
+ if (status) {
pr_err("Failed to initialize the SCTP control sock\n");
+ return status;
+ }
+
+ status = sctp_sysctl_net_register(net);
+ if (status) {
+ inet_ctl_sock_destroy(net->sctp.ctl_sock);
+ net->sctp.ctl_sock = NULL;
+ }
return status;
}
static void __net_exit sctp_ctrlsock_exit(struct net *net)
{
+ sctp_sysctl_net_unregister(net);
+
/* Free the control endpoint. */
inet_ctl_sock_destroy(net->sctp.ctl_sock);
+ net->sctp.ctl_sock = NULL;
}
static struct pernet_operations sctp_ctrlsock_ops = {
diff --git a/net/sctp/sysctl.c b/net/sctp/sysctl.c
index 15e7db9a3ab2..fca840484ebf 100644
--- a/net/sctp/sysctl.c
+++ b/net/sctp/sysctl.c
@@ -615,11 +615,16 @@ int sctp_sysctl_net_register(struct net *net)
void sctp_sysctl_net_unregister(struct net *net)
{
+ struct ctl_table_header *header = net->sctp.sysctl_header;
const struct ctl_table *table;
- table = net->sctp.sysctl_header->ctl_table_arg;
- unregister_net_sysctl_table(net->sctp.sysctl_header);
+ if (!header)
+ return;
+
+ table = header->ctl_table_arg;
+ unregister_net_sysctl_table(header);
kfree(table);
+ net->sctp.sysctl_header = NULL;
}
static struct ctl_table_header *sctp_sysctl_header;
--
2.43.0
^ permalink raw reply related [flat|nested] 5+ messages in thread* [PATCH net v3 2/2] sctp: close UDP tunnel sockets during netns teardown
[not found] <cover.1784033357.git.roxy520tt@gmail.com>
2026-07-15 1:50 ` [PATCH net v3 1/2] sctp: avoid auth_enable sysctl UAF during netns teardown Ren Wei
@ 2026-07-15 1:50 ` Ren Wei
2026-07-16 13:31 ` Xin Long
1 sibling, 1 reply; 5+ messages in thread
From: Ren Wei @ 2026-07-15 1:50 UTC (permalink / raw)
To: linux-sctp, netdev
Cc: marcelo.leitner, lucien.xin, davem, edumazet, pabeni, horms,
matttbe, yuantan098, yifanwucs, tomapufckgml, bird, tpluszz77,
roxy520tt, n05ec, sashiko-bot
From: Zhiling Zou <roxy520tt@gmail.com>
proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when
net.sctp.udp_port is set, and stops/restarts them when the sysctl value
changes. The netns exit path does not stop these sockets, so a namespace
can be torn down while its SCTP UDP tunnel sockets are still installed.
Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering
the per-net sysctl table. This prevents new sysctl writes from racing in
while the sockets are being released, and closes the sockets before the
control socket is destroyed.
Fixes: 046c052b475e ("sctp: enable udp tunneling socks")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/b9f1f02b0780ad6a719e2413f5f0bb8eb7702d94.1782585631.git.roxy520tt%40gmail.com
Signed-off-by: Zhiling Zou <roxy520tt@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
---
Changes in v3:
- No code changes.
net/sctp/protocol.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/sctp/protocol.c b/net/sctp/protocol.c
index 49d9740b1e0f..27c26e12f95d 100644
--- a/net/sctp/protocol.c
+++ b/net/sctp/protocol.c
@@ -1460,6 +1460,7 @@ static int __net_init sctp_ctrlsock_init(struct net *net)
static void __net_exit sctp_ctrlsock_exit(struct net *net)
{
sctp_sysctl_net_unregister(net);
+ sctp_udp_sock_stop(net);
/* Free the control endpoint. */
inet_ctl_sock_destroy(net->sctp.ctl_sock);
--
2.43.0
^ permalink raw reply related [flat|nested] 5+ messages in thread