HomeFreeBSD

MFC r368593:

Description

MFC r368593:
Clean up more resouces of an existing SCTP association in case of
a restart.
This fixes a use-after-free scenario, which was reported by Felix
Wilhelm from Google in case a peer is able to modify the cookie.
However, this can also be triggered by an assciation restart under
some specific conditions.

MFC r368622:
Harden the handling of outgoing streams in case of an restart or INIT
collision. This avouds an out-of-bounce access in case the peer can
break the cookie signature. Thanks to Felix Wilhelm from Google for
reporting the issue.

Details

Provenance
tuexenAuthored on
Parents
rS368756: Fix abort in jemalloc extent coalescing.
Branches
Unknown
Tags
Unknown