diff options
| author | Pauli Virtanen <pav@iki.fi> | 2026-07-10 11:23:42 +0300 |
|---|---|---|
| committer | Luiz Augusto von Dentz <luiz.von.dentz@intel.com> | 2026-07-10 15:57:42 -0400 |
| commit | 137501e0242f0226e76febd2f3b850db83bb2f4e (patch) | |
| tree | 71e00c6e530bb39e1dc411e7d8c7e59850f497f9 /net/dsa | |
| parent | f3f75fd597f25c511b0ebeef53016564007b7c13 (diff) | |
| download | linux-next-137501e0242f0226e76febd2f3b850db83bb2f4e.tar.gz linux-next-137501e0242f0226e76febd2f3b850db83bb2f4e.zip | |
Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also
needs to hold refcount to avoid UAF.
Take appropriate locks for hci_conn lookups, and take refcount for
hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays
valid.
When accessing conn->state, ensure hdev->lock is held to avoid data
race.
Fixes: 7b445e220db9 ("Bluetooth: MGMT: Fix holding hci_conn reference while command is queued")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Diffstat (limited to 'net/dsa')
0 files changed, 0 insertions, 0 deletions
