sctp: ensure sk_state is set to CLOSED if hashing fails in sctp_listen_start

If hashing fails in sctp_listen_start(), the socket remains in the
LISTENING state, even though it was not added to the hash table.
This can lead to a scenario where a socket appears to be listening
without actually being accessible.

This patch ensures that if the hashing operation fails, the sk_state
is set back to CLOSED before returning an error.

Note that there is no need to undo the autobind operation if hashing
fails, as the bind port can still be used for next listen() call on
the same socket.

Fixes: 76c6d988ae ("sctp: add sock_reuseport for the sock in __sctp_hash_endpoint")
Reported-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
Xin Long 2024-10-07 12:25:11 -04:00 committed by David S. Miller
parent 82c5b53140
commit 4d5c70e615

View File

@ -8531,6 +8531,7 @@ static int sctp_listen_start(struct sock *sk, int backlog)
struct sctp_endpoint *ep = sp->ep; struct sctp_endpoint *ep = sp->ep;
struct crypto_shash *tfm = NULL; struct crypto_shash *tfm = NULL;
char alg[32]; char alg[32];
int err;
/* Allocate HMAC for generating cookie. */ /* Allocate HMAC for generating cookie. */
if (!sp->hmac && sp->sctp_hmac_alg) { if (!sp->hmac && sp->sctp_hmac_alg) {
@ -8558,18 +8559,25 @@ static int sctp_listen_start(struct sock *sk, int backlog)
inet_sk_set_state(sk, SCTP_SS_LISTENING); inet_sk_set_state(sk, SCTP_SS_LISTENING);
if (!ep->base.bind_addr.port) { if (!ep->base.bind_addr.port) {
if (sctp_autobind(sk)) { if (sctp_autobind(sk)) {
inet_sk_set_state(sk, SCTP_SS_CLOSED); err = -EAGAIN;
return -EAGAIN; goto err;
} }
} else { } else {
if (sctp_get_port(sk, inet_sk(sk)->inet_num)) { if (sctp_get_port(sk, inet_sk(sk)->inet_num)) {
inet_sk_set_state(sk, SCTP_SS_CLOSED); err = -EADDRINUSE;
return -EADDRINUSE; goto err;
} }
} }
WRITE_ONCE(sk->sk_max_ack_backlog, backlog); WRITE_ONCE(sk->sk_max_ack_backlog, backlog);
return sctp_hash_endpoint(ep); err = sctp_hash_endpoint(ep);
if (err)
goto err;
return 0;
err:
inet_sk_set_state(sk, SCTP_SS_CLOSED);
return err;
} }
/* /*