| From 47e15a8d12e366d0d261bcbc394394f44418938d Mon Sep 17 00:00:00 2001 |
| From: Hyunwoo Kim <imv4bel@gmail.com> |
| Date: Sat, 15 Aug 2026 07:36:18 +0900 |
| Subject: sctp: stop processing a packet once its association is deleted |
| |
| From: Hyunwoo Kim <imv4bel@gmail.com> |
| |
| commit 47e15a8d12e366d0d261bcbc394394f44418938d upstream. |
| |
| sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is |
| NULL, and caches the result in chunk->asoc and chunk->transport without |
| taking a reference. |
| |
| A packet that matches no association is handed to the endpoint, so a peer |
| can bundle COOKIE ECHO, SHUTDOWN and SHUTDOWN ACK in one packet. The |
| COOKIE ECHO creates the association, the SHUTDOWN chunk caches it, and |
| with the outqueue empty the SHUTDOWN ACK reaches sctp_sf_do_9_2_final(), |
| so the association and its transports are freed. |
| |
| The endpoint loop has no counterpart to the asoc->base.dead check in |
| sctp_assoc_bh_rcv(). The next chunk writes to last_time_heard in the freed |
| transport and is then passed to sctp_do_sm() with the freed association. |
| The transport is freed through RCU, so this needs the packet to come off |
| the socket backlog, where the loop runs in task context. |
| |
| The endpoint loop cannot do the same check: it holds no reference on the |
| association, so reading asoc->base.dead would itself be a use-after-free. |
| Mark the packet for discard in the command interpreter, just before it |
| deletes the association. That is also before sctp_inq_free() releases the |
| chunk on the association receive path. |
| |
| sctp_sf_do_5_2_4_dupcook() issues SCTP_CMD_DELETE_TCB for the temporary |
| association, while the one the packet belongs to stays alive. A restarting |
| peer can bundle DATA behind its COOKIE ECHO, so compare against |
| chunk->asoc and leave that case alone. |
| |
| Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") |
| Cc: stable@vger.kernel.org |
| Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com> |
| Acked-by: Xin Long <lucien.xin@gmail.com> |
| Link: https://patch.msgid.link/an-YYtoqw1QpTXUL@v4bel |
| Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| net/sctp/sm_sideeffect.c | 4 ++++ |
| 1 file changed, 4 insertions(+) |
| |
| --- a/net/sctp/sm_sideeffect.c |
| +++ b/net/sctp/sm_sideeffect.c |
| @@ -1327,6 +1327,10 @@ static int sctp_cmd_interpreter(enum sct |
| sctp_outq_uncork(&asoc->outqueue, gfp); |
| local_cork = 0; |
| } |
| + /* No chunk left in this packet may use this asoc. */ |
| + if (event_type == SCTP_EVENT_T_CHUNK && |
| + chunk->asoc == asoc) |
| + chunk->pdiscard = 1; |
| /* Delete the current association. */ |
| sctp_cmd_delete_tcb(commands, asoc); |
| asoc = NULL; |