mirror of
https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9.git
synced 2026-09-09 00:08:12 +08:00
sctp: prevent peer transport count overflow
JIRA: https://redhat.atlassian.net/browse/RHEL-214461
Backported from tree(s): net
sctp: prevent peer transport count overflow
sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.
SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.
Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.
Fixes: 8f840e47f1 ("sctp: add the sctp_diag.c file")
Cc: stable@vger.kernel.org
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit bd0e9289e2642f6a5c54faad304ce0f41e926d22)
Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
This commit is contained in:
@@ -616,6 +616,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
|
||||
return peer;
|
||||
}
|
||||
|
||||
if (asoc->peer.transport_count == U16_MAX)
|
||||
return NULL;
|
||||
|
||||
peer = sctp_transport_new(asoc->base.net, addr, gfp);
|
||||
if (!peer)
|
||||
return NULL;
|
||||
|
||||
Reference in New Issue
Block a user