mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the
capacity limit for ep->auth_chunk_list, allowing it to hold up to
20 chunk entries (param_hdr.length up to 24). However, the copy
destination asoc->c.auth_chunks in struct sctp_cookie is only
SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16
chunks are added, sctp_association_init() memcpy overflows the
destination by up to 4 bytes.
Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching
the destination capacity.
Fixes: 1f485649f5 ("[SCTP]: Implement SCTP-AUTH internals")
Signed-off-by: HanQuan <eilaimemedsnaimel@gmail.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260713032021.3491702-1-zhoujian.zja@antgroup.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
ecaa378263
commit
ff04b26794
|
|
@ -672,7 +672,7 @@ int sctp_auth_ep_add_chunkid(struct sctp_endpoint *ep, __u8 chunk_id)
|
|||
/* Check if we can add this chunk to the array */
|
||||
param_len = ntohs(p->param_hdr.length);
|
||||
nchunks = param_len - sizeof(struct sctp_paramhdr);
|
||||
if (nchunks == SCTP_NUM_CHUNK_TYPES)
|
||||
if (nchunks == SCTP_AUTH_MAX_CHUNKS)
|
||||
return -EINVAL;
|
||||
|
||||
p->chunks[nchunks] = chunk_id;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user