From: Daehyeon Ko <4ncienth@gmail.com>
To: marcelo.leitner@gmail.com, lucien.xin@gmail.com
Cc: davem@davemloft.net, edumazet@kernel.org, kuba@kernel.org,
pabeni@redhat.com, horms@kernel.org, nhorman@tuxdriver.com,
linux-sctp@vger.kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org, Daehyeon Ko <4ncienth@gmail.com>
Subject: [PATCH net] sctp: revalidate output stream after association connect wait
Date: Fri, 2 Oct 2026 10:04:49 +0900 [thread overview]
Message-ID: <20261002010449.3689454-1-4ncienth@gmail.com> (raw)
When message interleaving is enabled, the first send waits for association
establishment before building its data chunks. The wait drops the socket
lock, and handshake processing can reduce the output stream count to the
peer-advertised inbound stream count. sctp_stream_init() then frees the
extension of every removed stream.
The sender currently resumes with the stream that it checked before the
wait. If the peer removed that stream, sctp_outq_tail() later dereferences
its NULL extension. Fatal-oops policies then panic the host.
KASAN: null-ptr-deref in range [0x38-0x3f]
RIP: sctp_outq_tail+0x49e/0xaa0
Call Trace:
sctp_primitive_SEND
sctp_sendmsg_to_asoc
sctp_sendmsg
Revalidate the output stream after the association connect wait. Return
EINVAL if it falls outside the negotiated range. This matches the pre-wait
check.
Fixes: 668c9beb9020 ("sctp: implement assign_number for sctp_stream_interleave")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
net/sctp/socket.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index 4652fd90d9a6c..394d31cb698e0 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -1848,6 +1848,11 @@ static int sctp_sendmsg_to_asoc(struct sctp_association *asoc,
err = -ESRCH;
goto err;
}
+ if (unlikely(sinfo->sinfo_stream >=
+ asoc->stream.outcnt)) {
+ err = -EINVAL;
+ goto err;
+ }
} else {
wait_connect = true;
}
reply other threads:[~2026-10-02 1:05 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002010449.3689454-1-4ncienth@gmail.com \
--to=4ncienth@gmail.com \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sctp@vger.kernel.org \
--cc=lucien.xin@gmail.com \
--cc=marcelo.leitner@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=nhorman@tuxdriver.com \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®