* [PATCH net] sctp: prevent peer transport count overflow
@ 2026-07-25 3:21 Asim Viladi Oglu Manizada
2026-07-27 1:54 ` Xin Long
2026-07-27 22:50 ` patchwork-bot+netdevbpf
0 siblings, 2 replies; 3+ messages in thread
From: Asim Viladi Oglu Manizada @ 2026-07-25 3:21 UTC (permalink / raw)
To: netdev
Cc: marcelo.leitner, lucien.xin, davem, edumazet, kuba, pabeni, horms,
linux-sctp, linux-kernel
sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.
SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.
Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.
Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
Cc: stable@vger.kernel.org
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
---
net/sctp/associola.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/sctp/associola.c b/net/sctp/associola.c
index 62d3cc155809..b6ac0966420a 100644
--- a/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
return peer;
}
+ if (asoc->peer.transport_count == U16_MAX)
+ return NULL;
+
peer = sctp_transport_new(asoc->base.net, addr, gfp);
if (!peer)
return NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH net] sctp: prevent peer transport count overflow
2026-07-25 3:21 [PATCH net] sctp: prevent peer transport count overflow Asim Viladi Oglu Manizada
@ 2026-07-27 1:54 ` Xin Long
2026-07-27 22:50 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: Xin Long @ 2026-07-27 1:54 UTC (permalink / raw)
To: Asim Viladi Oglu Manizada
Cc: netdev, marcelo.leitner, davem, edumazet, kuba, pabeni, horms,
linux-sctp, linux-kernel
On Fri, Jul 24, 2026 at 11:21 PM Asim Viladi Oglu Manizada
<manizada@pm.me> wrote:
>
> sctp_assoc_add_peer() increments the association's 16-bit transport_count
> for every new unique peer. Adding the 65,536th transport wraps the count to
> zero.
>
> SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
> then copies one sockaddr_storage for every entry in transport_addr_list.
> After the wrap, a diagnostic dump reserves an empty payload and writes
> 8 MiB of peer addresses past the skb tail.
>
> Reject a new unique peer when transport_count has reached U16_MAX. Perform
> the check after the existing-peer lookup so a duplicate address continues
> to return its existing transport at the limit.
>
> Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
> Cc: stable@vger.kernel.org
> Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
> Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
> ---
> net/sctp/associola.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/net/sctp/associola.c b/net/sctp/associola.c
> index 62d3cc155809..b6ac0966420a 100644
> --- a/net/sctp/associola.c
> +++ b/net/sctp/associola.c
> @@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
> return peer;
> }
>
> + if (asoc->peer.transport_count == U16_MAX)
> + return NULL;
> +
> peer = sctp_transport_new(asoc->base.net, addr, gfp);
> if (!peer)
> return NULL;
> --
> 2.53.0
>
Acked-by: Xin Long <lucien.xin@gmail.com>
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH net] sctp: prevent peer transport count overflow
2026-07-25 3:21 [PATCH net] sctp: prevent peer transport count overflow Asim Viladi Oglu Manizada
2026-07-27 1:54 ` Xin Long
@ 2026-07-27 22:50 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-07-27 22:50 UTC (permalink / raw)
To: Asim Viladi Oglu Manizada
Cc: netdev, marcelo.leitner, lucien.xin, davem, edumazet, kuba,
pabeni, horms, linux-sctp, linux-kernel
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Sat, 25 Jul 2026 03:21:06 +0000 you wrote:
> sctp_assoc_add_peer() increments the association's 16-bit transport_count
> for every new unique peer. Adding the 65,536th transport wraps the count to
> zero.
>
> SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
> then copies one sockaddr_storage for every entry in transport_addr_list.
> After the wrap, a diagnostic dump reserves an empty payload and writes
> 8 MiB of peer addresses past the skb tail.
>
> [...]
Here is the summary with links:
- [net] sctp: prevent peer transport count overflow
https://git.kernel.org/netdev/net/c/bd0e9289e264
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-07-27 22:50 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-25 3:21 [PATCH net] sctp: prevent peer transport count overflow Asim Viladi Oglu Manizada
2026-07-27 1:54 ` Xin Long
2026-07-27 22:50 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox