Page MenuHomeFreeBSD

pf: limit extra SCTP states
Needs ReviewPublic

Authored by kp on Jun 21 2025, 7:19 PM.
Tags
None
Referenced Files
F142044168: D50968.id.diff
Thu, Jan 15, 9:31 AM
Unknown Object (File)
Mon, Dec 29, 4:17 AM
Unknown Object (File)
Dec 15 2025, 9:29 PM
Unknown Object (File)
Dec 10 2025, 1:13 PM
Unknown Object (File)
Nov 6 2025, 12:16 PM
Unknown Object (File)
Nov 6 2025, 12:16 PM
Unknown Object (File)
Nov 3 2025, 9:26 PM
Unknown Object (File)
Nov 3 2025, 4:13 AM

Details

Reviewers
None
Group Reviewers
network
Summary

For SCTP we create states for all combinations of endpoints, to allow multihoming to work.
Malicious users could abuse this to fill our state table more easily
than they otherwise could, because we create states between all
combinations of endpoints. Limit this to no more than 8 extra endpoints
for each side of the connection.

MFC after: 2 weeks
Sponsored by: Orange Business Services

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 65013
Build 61896: arc lint + arc unit