mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
sctp: auth: verify auth requirement when auth_chunk is NULL
[ Upstream commit8e04823c12] sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally. Fixes:bbd0d59809("[SCTP]: Implement the receive and verification of AUTH chunk") Signed-off-by: Qing Luo <luoqing@kylinos.cn> Acked-by: Xin Long <lucien.xin@gmail.com> Link: https://patch.msgid.link/20260721015532.120157-2-l1138897701@163.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
4528678f70
commit
ec2e157fc9
@@ -640,7 +640,7 @@ static bool sctp_auth_chunk_verify(struct net *net, struct sctp_chunk *chunk,
|
||||
struct sctp_chunk auth;
|
||||
|
||||
if (!chunk->auth_chunk)
|
||||
return true;
|
||||
return !sctp_auth_recv_cid(chunk->chunk_hdr->type, asoc);
|
||||
|
||||
/* SCTP-AUTH: auth_chunk pointer is only set when the cookie-echo
|
||||
* is supposed to be authenticated and we have to do delayed
|
||||
|
||||
Reference in New Issue
Block a user