Re: [PATCH net v2] sctp: validate stream count in sctp_process_strreset_inreq()
From: patchwork-bot+netdevbpf
Date: Tue Jul 21 2026 - 17:37:16 EST
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@xxxxxxxxxx>:
On Thu, 9 Jul 2026 21:07:18 -0400 you wrote:
> When processing a RESET_IN_REQUEST from a peer,
> sctp_process_strreset_inreq() derives the stream count from the
> parameter length but does not check whether the resulting
> RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.
>
> The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
> larger than the IN request header (sctp_strreset_inreq, 8 bytes).
> Generally, the IP payload is bounded to 65535 bytes, so the stream
> list cannot be large enough to trigger the overflow. However, on
> interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a
> stream list that fits within the incoming IN parameter can cause a
> __u16 overflow in sctp_make_strreset_req() when computing the OUT
> request size, leading to an undersized skb allocation and a kernel
> BUG:
>
> [...]
Here is the summary with links:
- [net,v2] sctp: validate stream count in sctp_process_strreset_inreq()
https://git.kernel.org/netdev/net/c/18ae07691d43
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html