Thread (4 messages) flat view 4 messages, 3 authors, 2d ago

Re: [PATCH] sctp: validate cookie AUTH state before use

From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-08-07 22:40:47
Also in: linux-sctp, lkml

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski [off-list ref]:

On Tue,  4 Aug 2026 20:00:42 +0000 you wrote:
When cookie authentication is disabled, COOKIE_ECHO restores fixed-size
AUTH fields directly from peer-controlled cookie bytes.  A forged RANDOM
length, HMAC list, or CHUNKS list can then reach association consumers
with lengths or identifiers that were never validated against the local
backing arrays.

A forged RANDOM length can cause out-of-bounds reads during key-vector
construction.  A forged HMAC identifier also caused a 32-byte write past
a zero-length AUTH chunk, providing a primitive for a local privilege
escalation chain.

[...]
Here is the summary with links:
  - sctp: validate cookie AUTH state before use
    https://git.kernel.org/netdev/net/c/3dbb44d88b1e

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help