sctp: prevent peer transport count overflow
authorAsim Viladi Oglu Manizada <manizada@pm.me>
Sat, 25 Jul 2026 03:21:06 +0000 (03:21 +0000)
committerJakub Kicinski <kuba@kernel.org>
Mon, 27 Jul 2026 22:45:24 +0000 (15:45 -0700)
commitbd0e9289e2642f6a5c54faad304ce0f41e926d22
tree9ac9838b72a70a57a8e3f6e857fd2f5e30e13ab2
parent9d8da8e0a9bce4a340af60dd0446bc7eb8d07587
sctp: prevent peer transport count overflow

sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.

SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.

Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.

Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
Cc: stable@vger.kernel.org
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/sctp/associola.c