[PATCH v4 net] sctp: auth: verify auth requirement when auth_chunk is NULL

luoqing posted 1 patch 3 days, 23 hours ago
net/sctp/sm_statefuns.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH v4 net] sctp: auth: verify auth requirement when auth_chunk is NULL
Posted by luoqing 3 days, 23 hours ago
From: Qing Luo <luoqing@kylinos.cn>

sctp_auth_chunk_verify() returns true unconditionally when
chunk->auth_chunk is NULL, silently skipping authentication.
This is incorrect when:

1. skb_clone() failed in the BH receive path, leaving auth_chunk
   NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new
   connections, so the early sctp_auth_recv_cid() check cannot
   catch this.

2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never
   called and auth_chunk remains NULL.

Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL:
if authentication is required, return false to drop the chunk;
otherwise continue normally.

Fixes: bbd0d59809f9 ("[SCTP]: Implement the receive and verification of AUTH chunk")
Signed-off-by: Qing Luo <luoqing@kylinos.cn>
---
 net/sctp/sm_statefuns.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
index d23d935e128e..89ed618b1de3 100644
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -642,7 +642,7 @@ static bool sctp_auth_chunk_verify(struct net *net, struct sctp_chunk *chunk,
 	struct sctp_chunk auth;
 
 	if (!chunk->auth_chunk)
-		return true;
+		return !sctp_auth_recv_cid(chunk->chunk_hdr->type, asoc);
 
 	/* SCTP-AUTH:  auth_chunk pointer is only set when the cookie-echo
 	 * is supposed to be authenticated and we have to do delayed
-- 
2.25.1
Re: [PATCH v4 net] sctp: auth: verify auth requirement when auth_chunk is NULL
Posted by Xin Long 2 days, 7 hours ago
On Mon, Jul 20, 2026 at 9:56 PM luoqing <l1138897701@163.com> wrote:
>
> From: Qing Luo <luoqing@kylinos.cn>
>
> sctp_auth_chunk_verify() returns true unconditionally when
> chunk->auth_chunk is NULL, silently skipping authentication.
> This is incorrect when:
>
> 1. skb_clone() failed in the BH receive path, leaving auth_chunk
>    NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new
>    connections, so the early sctp_auth_recv_cid() check cannot
>    catch this.
>
> 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never
>    called and auth_chunk remains NULL.
>
> Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL:
> if authentication is required, return false to drop the chunk;
> otherwise continue normally.
>
> Fixes: bbd0d59809f9 ("[SCTP]: Implement the receive and verification of AUTH chunk")
> Signed-off-by: Qing Luo <luoqing@kylinos.cn>
> ---
>  net/sctp/sm_statefuns.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
> index d23d935e128e..89ed618b1de3 100644
> --- a/net/sctp/sm_statefuns.c
> +++ b/net/sctp/sm_statefuns.c
> @@ -642,7 +642,7 @@ static bool sctp_auth_chunk_verify(struct net *net, struct sctp_chunk *chunk,
>         struct sctp_chunk auth;
>
>         if (!chunk->auth_chunk)
> -               return true;
> +               return !sctp_auth_recv_cid(chunk->chunk_hdr->type, asoc);
>
>         /* SCTP-AUTH:  auth_chunk pointer is only set when the cookie-echo
>          * is supposed to be authenticated and we have to do delayed
> --
> 2.25.1
>
Acked-by: Xin Long <lucien.xin@gmail.com>