diff options
author | Xin Long <lucien.xin@gmail.com> | 2016-07-30 07:58:35 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2016-07-31 07:06:22 +0200 |
commit | 1aa25ec227a4be21515594f485b0f4985109f0d8 (patch) | |
tree | a5fedd47061bb248e731aae532c51dc8d6bacb22 /net/sctp/output.c | |
parent | tcp: consider recv buf for the initial window scale (diff) | |
download | linux-1aa25ec227a4be21515594f485b0f4985109f0d8.tar.xz linux-1aa25ec227a4be21515594f485b0f4985109f0d8.zip |
sctp: fix the issue sctp requeue auth chunk incorrectly
sctp needs to queue auth chunk back when we know that we are going
to generate another segment. But commit f1533cce60d1 ("sctp: fix
panic when sending auth chunks") requeues the last chunk processed
which is probably not the auth chunk.
It causes panic when calculating the MAC in sctp_auth_calculate_hmac(),
as the incorrect offset of the auth chunk in skb->data.
This fix is to requeue it by using packet->auth.
Fixes: f1533cce60d1 ("sctp: fix panic when sending auth chunks")
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/sctp/output.c')
-rw-r--r-- | net/sctp/output.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/net/sctp/output.c b/net/sctp/output.c index 7425f6c23888..1f1682b9a6a8 100644 --- a/net/sctp/output.c +++ b/net/sctp/output.c @@ -610,7 +610,8 @@ int sctp_packet_transmit(struct sctp_packet *packet, gfp_t gfp) /* We will generate more packets, so re-queue * auth chunk. */ - list_add(&chunk->list, &packet->chunk_list); + list_add(&packet->auth->list, + &packet->chunk_list); } else { sctp_chunk_free(packet->auth); packet->auth = NULL; |