)]}'
{
  "commit": "c9158ceaf27780ef64534ad72f44ffde3f8ccc49",
  "tree": "34a2f5bc83b67c881dd3e206919e0c22088633bb",
  "parents": [
    "d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3"
  ],
  "author": {
    "name": "Xin Long",
    "email": "lucien.xin@gmail.com",
    "time": "Wed Aug 05 11:18:40 2026 -0400"
  },
  "committer": {
    "name": "Jakub Kicinski",
    "email": "kuba@kernel.org",
    "time": "Thu Aug 06 09:29:47 2026 -0700"
  },
  "message": "sctp: clear control chunk transport if it is being removed\n\nsctp_make_heartbeat_ack() caches the destination transport in\nchunk-\u003etransport without taking a reference. When src_out_of_asoc_ok is\nenabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead\nof being transmitted immediately.\n\nIf the peer transport is removed while the chunk is still queued,\nsctp_assoc_rm_peer() drops the transport and schedules it for RCU freeing,\nbut only clears cached transport pointers in out_chunk_list.  The queued\ncontrol chunk therefore retains a dangling transport pointer.\n\nOnce an ASCONF_ACK clears the suppression and the queued control chunk is\ntransmitted, SCTP dereferences the stale transport pointer, leading to a\nuse-after-free.\n\nFix this by also clearing chunk-\u003etransport for queued control chunks in\ncontrol_chunk_list when removing the transport.\n\nFixes: 8a07eb0a50ae (\"sctp: Add ASCONF operation on the single-homed host\")\nReported-by: Daniele Linguaglossa \u003cdanielelinguaglossa@gmail.com\u003e\nSigned-off-by: Xin Long \u003clucien.xin@gmail.com\u003e\nLink: https://patch.msgid.link/7e1168cb722132152a29d47e5eafaeac4a3bf6f3.1785943120.git.lucien.xin@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "b6ac0966420a1f2e8bcbf14df7f4522d9895173f",
      "old_mode": 33188,
      "old_path": "net/sctp/associola.c",
      "new_id": "5b0ae616e1ff9407090affd1c949ec985cab609a",
      "new_mode": 33188,
      "new_path": "net/sctp/associola.c"
    }
  ]
}
