Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 2 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
sctp: clear control chunk transport if it is being removed

In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being removed sctp_make_heartbeat_ack() caches the destination transport in chunk->transport without taking a reference. When src_out_of_asoc_ok is enabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead of being transmitted immediately. If the peer transport is removed while the chunk is still queued, sctp_assoc_rm_peer() drops the transport and schedules it for RCU freeing, but only clears cached transport pointers in out_chunk_list. The queued control chunk therefore retains a dangling transport pointer. Once an ASCONF_ACK clears the suppression and the queued control chunk is transmitted, SCTP dereferences the stale transport pointer, leading to a use-after-free. Fix this by also clearing chunk->transport for queued control chunks in control_chunk_list when removing the transport.

Affected products

Linux
  • <936658ec41c28c397ef390140e02d4c91ade92f0
  • <3.1
  • =<5.15.*
  • <8de65194a04d2552cd39b6c67d942d490f22d174
  • <fad4766a74220fe579c6fcaa10ba01c23529814f
  • <4d6b9cac6df5e0cfef1a66b3edd7aebdb9e4b7e7
  • =<7.1.*
  • <c9158ceaf27780ef64534ad72f44ffde3f8ccc49
  • <6160e756db81d6cb63e3e2952efcf6c5134be385
  • =<5.10.*
  • <dbb3f418a8665ffb0514e1a9520ab6a1c5d4d886
  • =<6.18.*
  • =<6.1.*
  • <18d704bdd809377dfd81a3c2f42426763b5da227
  • ==3.1
  • =<6.6.*
  • =<6.12.*
  • =<*