ACK: [SRU][RNJ][PATCH v2 1/1] sctp: don't free the ASCONF's own transport in DEL-IP processing

Andrei Gherzan andrei.gherzan at canonical.com
Fri Sep 4 10:06:44 UTC 2026


On 26/09/04 01:58PM, ChunAn Wu via kernel-team wrote:
> From: Jun Yang <junvyyang at tencent.com>
> 
> sctp_process_asconf() caches the transport the ASCONF chunk is processed
> against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
> For an ASCONF located through its Address Parameter by
> __sctp_rcv_asconf_lookup(), that cached transport corresponds to the
> Address Parameter, which need not be the packet's source address.
> 
> sctp_process_asconf_param() rejects a DEL-IP for the packet source address
> (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
> A single ASCONF can therefore carry, in order:
> 
>     [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]
> 
> where L differs from the source. The DEL-IP for L passes the D8 check and
> calls sctp_assoc_rm_peer() on the transport that asconf->transport still
> points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
> reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
> sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
> transport (->ipaddr, ->state) and plants the dangling pointer into
> asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
> only the pointer that is no longer on the list, removes every real
> transport, leaving the association with a transport_count of 0 and
> primary_path/active_path pointing at freed memory.
> 
> Reject a DEL-IP that targets the transport the ASCONF is being processed
> against, mirroring the existing source-address guard, so the wildcard
> branch can never reuse a freed transport.
> 
> Fixes: 42e30bf3463c ("[SCTP]: Handle the wildcard ADD-IP Address parameter")
> Cc: stable at kernel.org
> Signed-off-by: Jun Yang <junvyyang at tencent.com>
> Acked-by: Xin Long <lucien.xin at gmail.com>
> Link: https://patch.msgid.link/tencent_73762ED1DF08CC9D5F5F61954B01350CFE0A@qq.com
> Signed-off-by: Jakub Kicinski <kuba at kernel.org>
> (cherry picked from commit 9b2854f86f0b56e9027d68e7a3fc909d1a9b566f)
> CVE-2026-64564
> Signed-off-by: ChunAn Wu <an.wu at canonical.com>
> ---
>  net/sctp/sm_make_chunk.c | 6 ++++++
>  1 file changed, 6 insertions(+)
> 
> diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
> index a7804e47d382..1f8a1e6069b3 100644
> --- a/net/sctp/sm_make_chunk.c
> +++ b/net/sctp/sm_make_chunk.c
> @@ -3153,6 +3153,12 @@ static __be16 sctp_process_asconf_param(struct sctp_association *asoc,
>  		if (!peer)
>  			return SCTP_ERROR_DNS_FAILED;
>  
> +		/* Don't free asconf->transport; a later wildcard DEL-IP
> +		 * parameter reuses it.
> +		 */
> +		if (peer == asconf->transport)
> +			return SCTP_ERROR_REQ_REFUSED;
> +
>  		sctp_assoc_rm_peer(asoc, peer);
>  		break;
>  	case SCTP_PARAM_SET_PRIMARY:

Acked-by: Andrei Gherzan <andrei.gherzan at canonical.com>

-- 
Andrei Gherzan
gpg: rsa4096/D4D94F67AD0E9640
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260904/90730f50/attachment.sig>


More information about the kernel-team mailing list