| From 74e2e5459ab49fa62d74395afd93ed4de34b9241 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Tue, 21 Oct 2025 16:00:36 +0300 |
| Subject: sctp: avoid NULL dereference when chunk data buffer is missing |
| |
| From: Alexey Simakov <bigalex934@gmail.com> |
| |
| [ Upstream commit 441f0647f7673e0e64d4910ef61a5fb8f16bfb82 ] |
| |
| chunk->skb pointer is dereferenced in the if-block where it's supposed |
| to be NULL only. |
| |
| chunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list |
| instead and do it just before replacing chunk->skb. We're sure that |
| otherwise chunk->skb is non-NULL because of outer if() condition. |
| |
| Fixes: 90017accff61 ("sctp: Add GSO support") |
| Signed-off-by: Alexey Simakov <bigalex934@gmail.com> |
| Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com> |
| Link: https://patch.msgid.link/20251021130034.6333-1-bigalex934@gmail.com |
| Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/sctp/inqueue.c | 13 +++++++------ |
| 1 file changed, 7 insertions(+), 6 deletions(-) |
| |
| diff --git a/net/sctp/inqueue.c b/net/sctp/inqueue.c |
| index 7182c5a450fb5..6a434d441dc70 100644 |
| --- a/net/sctp/inqueue.c |
| +++ b/net/sctp/inqueue.c |
| @@ -163,13 +163,14 @@ struct sctp_chunk *sctp_inq_pop(struct sctp_inq *queue) |
| chunk->head_skb = chunk->skb; |
| |
| /* skbs with "cover letter" */ |
| - if (chunk->head_skb && chunk->skb->data_len == chunk->skb->len) |
| + if (chunk->head_skb && chunk->skb->data_len == chunk->skb->len) { |
| + if (WARN_ON(!skb_shinfo(chunk->skb)->frag_list)) { |
| + __SCTP_INC_STATS(dev_net(chunk->skb->dev), |
| + SCTP_MIB_IN_PKT_DISCARDS); |
| + sctp_chunk_free(chunk); |
| + goto next_chunk; |
| + } |
| chunk->skb = skb_shinfo(chunk->skb)->frag_list; |
| - |
| - if (WARN_ON(!chunk->skb)) { |
| - __SCTP_INC_STATS(dev_net(chunk->skb->dev), SCTP_MIB_IN_PKT_DISCARDS); |
| - sctp_chunk_free(chunk); |
| - goto next_chunk; |
| } |
| } |
| |
| -- |
| 2.51.0 |
| |