Re: [PATCH net] sctp: prevent peer transport count overflow

From: Xin Long

Date: Sun Jul 26 2026 - 21:55:08 EST


On Fri, Jul 24, 2026 at 11:21 PM Asim Viladi Oglu Manizada
<manizada@xxxxx> wrote:
>
> sctp_assoc_add_peer() increments the association's 16-bit transport_count
> for every new unique peer. Adding the 65,536th transport wraps the count to
> zero.
>
> SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
> then copies one sockaddr_storage for every entry in transport_addr_list.
> After the wrap, a diagnostic dump reserves an empty payload and writes
> 8 MiB of peer addresses past the skb tail.
>
> Reject a new unique peer when transport_count has reached U16_MAX. Perform
> the check after the existing-peer lookup so a duplicate address continues
> to return its existing transport at the limit.
>
> Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
> Signed-off-by: Asim Viladi Oglu Manizada <manizada@xxxxx>
> ---
> net/sctp/associola.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/net/sctp/associola.c b/net/sctp/associola.c
> index 62d3cc155809..b6ac0966420a 100644
> --- a/net/sctp/associola.c
> +++ b/net/sctp/associola.c
> @@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
> return peer;
> }
>
> + if (asoc->peer.transport_count == U16_MAX)
> + return NULL;
> +
> peer = sctp_transport_new(asoc->base.net, addr, gfp);
> if (!peer)
> return NULL;
> --
> 2.53.0
>
Acked-by: Xin Long <lucien.xin@xxxxxxxxx>