Netdev List
 help / color / mirror / Atom feed
* [PATCH net] sctp: prevent peer transport count overflow
@ 2026-07-25  3:21 Asim Viladi Oglu Manizada
  2026-07-27  1:54 ` Xin Long
  2026-07-27 22:50 ` patchwork-bot+netdevbpf
  0 siblings, 2 replies; 3+ messages in thread
From: Asim Viladi Oglu Manizada @ 2026-07-25  3:21 UTC (permalink / raw)
  To: netdev
  Cc: marcelo.leitner, lucien.xin, davem, edumazet, kuba, pabeni, horms,
	linux-sctp, linux-kernel

sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.

SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.

Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.

Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
Cc: stable@vger.kernel.org
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
---
 net/sctp/associola.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/sctp/associola.c b/net/sctp/associola.c
index 62d3cc155809..b6ac0966420a 100644
--- a/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
 		return peer;
 	}
 
+	if (asoc->peer.transport_count == U16_MAX)
+		return NULL;
+
 	peer = sctp_transport_new(asoc->base.net, addr, gfp);
 	if (!peer)
 		return NULL;
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH net] sctp: prevent peer transport count overflow
  2026-07-25  3:21 [PATCH net] sctp: prevent peer transport count overflow Asim Viladi Oglu Manizada
@ 2026-07-27  1:54 ` Xin Long
  2026-07-27 22:50 ` patchwork-bot+netdevbpf
  1 sibling, 0 replies; 3+ messages in thread
From: Xin Long @ 2026-07-27  1:54 UTC (permalink / raw)
  To: Asim Viladi Oglu Manizada
  Cc: netdev, marcelo.leitner, davem, edumazet, kuba, pabeni, horms,
	linux-sctp, linux-kernel

On Fri, Jul 24, 2026 at 11:21 PM Asim Viladi Oglu Manizada
<manizada@pm.me> wrote:
>
> sctp_assoc_add_peer() increments the association's 16-bit transport_count
> for every new unique peer. Adding the 65,536th transport wraps the count to
> zero.
>
> SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
> then copies one sockaddr_storage for every entry in transport_addr_list.
> After the wrap, a diagnostic dump reserves an empty payload and writes
> 8 MiB of peer addresses past the skb tail.
>
> Reject a new unique peer when transport_count has reached U16_MAX. Perform
> the check after the existing-peer lookup so a duplicate address continues
> to return its existing transport at the limit.
>
> Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
> Cc: stable@vger.kernel.org
> Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
> Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
> ---
>  net/sctp/associola.c | 3 +++
>  1 file changed, 3 insertions(+)
>
> diff --git a/net/sctp/associola.c b/net/sctp/associola.c
> index 62d3cc155809..b6ac0966420a 100644
> --- a/net/sctp/associola.c
> +++ b/net/sctp/associola.c
> @@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
>                 return peer;
>         }
>
> +       if (asoc->peer.transport_count == U16_MAX)
> +               return NULL;
> +
>         peer = sctp_transport_new(asoc->base.net, addr, gfp);
>         if (!peer)
>                 return NULL;
> --
> 2.53.0
>
Acked-by: Xin Long <lucien.xin@gmail.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net] sctp: prevent peer transport count overflow
  2026-07-25  3:21 [PATCH net] sctp: prevent peer transport count overflow Asim Viladi Oglu Manizada
  2026-07-27  1:54 ` Xin Long
@ 2026-07-27 22:50 ` patchwork-bot+netdevbpf
  1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-07-27 22:50 UTC (permalink / raw)
  To: Asim Viladi Oglu Manizada
  Cc: netdev, marcelo.leitner, lucien.xin, davem, edumazet, kuba,
	pabeni, horms, linux-sctp, linux-kernel

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Sat, 25 Jul 2026 03:21:06 +0000 you wrote:
> sctp_assoc_add_peer() increments the association's 16-bit transport_count
> for every new unique peer. Adding the 65,536th transport wraps the count to
> zero.
> 
> SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
> then copies one sockaddr_storage for every entry in transport_addr_list.
> After the wrap, a diagnostic dump reserves an empty payload and writes
> 8 MiB of peer addresses past the skb tail.
> 
> [...]

Here is the summary with links:
  - [net] sctp: prevent peer transport count overflow
    https://git.kernel.org/netdev/net/c/bd0e9289e264

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-07-27 22:50 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-25  3:21 [PATCH net] sctp: prevent peer transport count overflow Asim Viladi Oglu Manizada
2026-07-27  1:54 ` Xin Long
2026-07-27 22:50 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox