summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorQing Luo <luoqing@kylinos.cn>2026-07-23 14:11:07 +0800
committerJakub Kicinski <kuba@kernel.org>2026-07-29 16:36:20 -0700
commit9ae7ed101cf28613071ebfbc42668c8917a670cf (patch)
tree6e04ea97d51df9995a838de0a0107e4ae8d8bdbc
parent2bb54b49e9d522f54dc9c0fe10ba40fbc56041c8 (diff)
downloadlinux-next-9ae7ed101cf28613071ebfbc42668c8917a670cf.tar.gz
linux-next-9ae7ed101cf28613071ebfbc42668c8917a670cf.zip
sctp: auth: discard auth_chunk when skb_clone fails
When processing AUTH + COOKIE-ECHO packets, if skb_clone() fails due to memory pressure, chunk->auth_chunk is NULL. The original code still sets chunk->auth = 1 and continues, leaving the COOKIE-ECHO to be processed without a valid auth_chunk for deferred verification. Discard the AUTH chunk early via pdiscard when skb_clone() fails, so that the receive loop can continue processing remaining chunks in the inqueue instead of stalling the entire packet. Signed-off-by: Qing Luo <luoqing@kylinos.cn> Acked-by: Xin Long <lucien.xin@gmail.com> Link: https://patch.msgid.link/20260723061107.384106-1-l1138897701@163.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
-rw-r--r--net/sctp/associola.c4
-rw-r--r--net/sctp/endpointola.c4
2 files changed, 8 insertions, 0 deletions
diff --git a/net/sctp/associola.c b/net/sctp/associola.c
index 62d3cc155809..a5f2835dbe0f 100644
--- a/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -999,6 +999,10 @@ static void sctp_assoc_bh_rcv(struct work_struct *work)
if (next_hdr->type == SCTP_CID_COOKIE_ECHO) {
chunk->auth_chunk = skb_clone(chunk->skb,
GFP_ATOMIC);
+ if (!chunk->auth_chunk) {
+ chunk->pdiscard = 1;
+ continue;
+ }
chunk->auth = 1;
continue;
}
diff --git a/net/sctp/endpointola.c b/net/sctp/endpointola.c
index dfb1719275db..a15b599b20b7 100644
--- a/net/sctp/endpointola.c
+++ b/net/sctp/endpointola.c
@@ -368,6 +368,10 @@ static void sctp_endpoint_bh_rcv(struct work_struct *work)
if (next_hdr->type == SCTP_CID_COOKIE_ECHO) {
chunk->auth_chunk = skb_clone(chunk->skb,
GFP_ATOMIC);
+ if (!chunk->auth_chunk) {
+ chunk->pdiscard = 1;
+ continue;
+ }
chunk->auth = 1;
continue;
}