All Virtuozzo development lists (kernel + QEMU)
 help / color / mirror / Atom feed
From: Konstantin Khorenko <khorenko@virtuozzo.com>
Subject: [Devel] [PATCH RHEL10 COMMIT] ms/sctp: don't free the ASCONF's own transport in DEL-IP processing
Date: Tue, 11 Aug 2026 16:48:46 +0200	[thread overview]
Message-ID: <202608111448.67BEmk92092501@f0.sw.ru> (raw)
In-Reply-To: <20260811114914.3200654-1-ptikhomirov@virtuozzo.com>

The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git at bitbucket.org:openvz/vzkernel.git
after rh10-6.12.0-211.39.1.16.3.vz10
------>
commit 1dc6f66fbdec7b456a8fefb9e99b6e05c72fd9ac
Author: Jun Yang <junvyyang@tencent.com>
Date:   Tue Aug 11 13:49:07 2026 +0200

    ms/sctp: don't free the ASCONF's own transport in DEL-IP processing
    
    sctp_process_asconf() caches the transport the ASCONF chunk is processed
    against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
    For an ASCONF located through its Address Parameter by
    __sctp_rcv_asconf_lookup(), that cached transport corresponds to the
    Address Parameter, which need not be the packet's source address.
    
    sctp_process_asconf_param() rejects a DEL-IP for the packet source address
    (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
    A single ASCONF can therefore carry, in order:
    
        [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]
    
    where L differs from the source. The DEL-IP for L passes the D8 check and
    calls sctp_assoc_rm_peer() on the transport that asconf->transport still
    points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
    reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
    sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
    transport (->ipaddr, ->state) and plants the dangling pointer into
    asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
    only the pointer that is no longer on the list, removes every real
    transport, leaving the association with a transport_count of 0 and
    primary_path/active_path pointing at freed memory.
    
    Reject a DEL-IP that targets the transport the ASCONF is being processed
    against, mirroring the existing source-address guard, so the wildcard
    branch can never reuse a freed transport.
    
    Fixes: 42e30bf3463c ("[SCTP]: Handle the wildcard ADD-IP Address parameter")
    Cc: stable at kernel.org
    Signed-off-by: Jun Yang <junvyyang@tencent.com>
    Acked-by: Xin Long <lucien.xin@gmail.com>
    Link: https://patch.msgid.link/tencent_73762ED1DF08CC9D5F5F61954B01350CFE0A at qq.com
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>
    
    CVE-2026-64564
    Feature: fix ms/net
    https://virtuozzo.atlassian.net/browse/VSTOR-140910
    (cherry picked from commit 9b2854f86f0b56e9027d68e7a3fc909d1a9b566f)
    Signed-off-by: Pavel Tikhomirov <ptikhomirov@virtuozzo.com>
---
 net/sctp/sm_make_chunk.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
index 07e220b8a4af5..b3fb015409031 100644
--- a/net/sctp/sm_make_chunk.c
+++ b/net/sctp/sm_make_chunk.c
@@ -3156,6 +3156,12 @@ static __be16 sctp_process_asconf_param(struct sctp_association *asoc,
 		if (!peer)
 			return SCTP_ERROR_DNS_FAILED;
 
+		/* Don't free asconf->transport; a later wildcard DEL-IP
+		 * parameter reuses it.
+		 */
+		if (peer == asconf->transport)
+			return SCTP_ERROR_REQ_REFUSED;
+
 		sctp_assoc_rm_peer(asoc, peer);
 		break;
 	case SCTP_PARAM_SET_PRIMARY:

      reply	other threads:[~2026-08-11 14:48 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-11 11:49 [Devel] [PATCH VZ10] sctp: " Pavel Tikhomirov
2026-08-11 14:48 ` Konstantin Khorenko [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202608111448.67BEmk92092501@f0.sw.ru \
    --to=khorenko@virtuozzo.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.