Re: [PATCH net] sctp: reject stale cookies with mismatched verification tags
From: Xin Long
Date: Fri Jul 24 2026 - 12:07:44 EST
On Thu, Jul 23, 2026 at 6:56 PM Yuxiang Yang
<yangyx22@xxxxxxxxxxxxxxxxxxxxx> wrote:
>
> sctp_unpack_cookie() skips cookie expiration checks whenever an
> association already exists. This is broader than the exception in
> RFC 9260 Section 5.2.4.
>
> For an existing association, Section 5.2.4 permits an expired State
> Cookie only when both Verification Tags in the cookie match the current
> association. Otherwise, the packet SHOULD be discarded and a Stale
> Cookie ERROR MUST be sent.
>
> The broad check lets an expired Action A restart cookie reach
> sctp_sf_do_dupcook_a(). In a runtime test with the default 60 second
> cookie lifetime, replaying such a cookie after 65 seconds returned a
> COOKIE-ACK and restarted the association.
>
> Check cookie expiration unless both Verification Tags match. This
> preserves the Action D exception for a lost COOKIE ACK while rejecting
> expired cookies in all other cases.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Yuxiang Yang <yangyx22@xxxxxxxxxxxxxxxxxxxxx>
> ---
> net/sctp/sm_make_chunk.c | 11 +++++++----
> 1 file changed, 7 insertions(+), 4 deletions(-)
>
> diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
> index c02809264..a1c0334a1 100644
> --- a/net/sctp/sm_make_chunk.c
> +++ b/net/sctp/sm_make_chunk.c
> @@ -1802,9 +1802,9 @@ struct sctp_association *sctp_unpack_cookie(
> goto fail;
> }
>
> - /* Check to see if the cookie is stale. If there is already
> - * an association, there is no need to check cookie's expiration
> - * for init collision case of lost COOKIE ACK.
> + /* Check to see if the cookie is stale. RFC 9260 Section 5.2.4
> + * exempts an expired cookie only when both Verification Tags match
> + * the current association.
> * If skb has been timestamped, then use the stamp, otherwise
> * use current time. This introduces a small possibility that
> * a cookie may be considered expired, but this would only slow
> @@ -1815,7 +1815,10 @@ struct sctp_association *sctp_unpack_cookie(
> else
> kt = ktime_get_real();
>
> - if (!asoc && ktime_before(bear_cookie->expiration, kt)) {
> + if ((!asoc ||
> + asoc->c.my_vtag != bear_cookie->my_vtag ||
> + asoc->c.peer_vtag != bear_cookie->peer_vtag) &&
> + ktime_before(bear_cookie->expiration, kt)) {
> suseconds_t usecs = ktime_to_us(ktime_sub(kt, bear_cookie->expiration));
> __be32 n = htonl(usecs);
>
> --
> 2.34.1
>
Acked-by: Xin Long <lucien.xin@xxxxxxxxx>