Commit 4d7b41c
Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()
Extend a critical section to prevent chan from early freeing.
Also make the l2cap_connect() return type void. Nothing is using the
returned value but it is ugly to return a potentially freed pointer.
Making it void will help with backports because earlier kernels did use
the return value. Now the compile will break for kernels where this
patch is not a complete fix.
Call stack summary:
[use]
l2cap_bredr_sig_cmd
l2cap_connect
┌ mutex_lock(&conn->chan_lock);
│ chan = pchan->ops->new_connection(pchan); <- alloc chan
│ __l2cap_chan_add(conn, chan);
│ l2cap_chan_hold(chan);
│ list_add(&chan->list, &conn->chan_l); ... (1)
└ mutex_unlock(&conn->chan_lock);
chan->conf_state ... (4) <- use after free
[free]
l2cap_conn_del
┌ mutex_lock(&conn->chan_lock);
│ foreach chan in conn->chan_l: ... (2)
│ l2cap_chan_put(chan);
│ l2cap_chan_destroy
│ kfree(chan) ... (3) <- chan freed
└ mutex_unlock(&conn->chan_lock);
==================================================================
BUG: KASAN: slab-use-after-free in instrument_atomic_read
include/linux/instrumented.h:68 [inline]
BUG: KASAN: slab-use-after-free in _test_bit
include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]
BUG: KASAN: slab-use-after-free in l2cap_connect+0xa67/0x11a0
net/bluetooth/l2cap_core.c:4260
Read of size 8 at addr ffff88810bf040a0 by task kworker/u3:1/311
Fixes: 73ffa90 ("Bluetooth: Move conf_{req,rsp} stuff to struct l2cap_chan")
Signed-off-by: Sungwoo Kim <iam@sung-woo.kim>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>1 parent 66c3933 commit 4d7b41c
1 file changed
+10
-11
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3902 | 3902 | | |
3903 | 3903 | | |
3904 | 3904 | | |
3905 | | - | |
3906 | | - | |
3907 | | - | |
| 3905 | + | |
| 3906 | + | |
3908 | 3907 | | |
3909 | 3908 | | |
3910 | 3909 | | |
3911 | | - | |
| 3910 | + | |
3912 | 3911 | | |
3913 | 3912 | | |
3914 | 3913 | | |
| |||
3921 | 3920 | | |
3922 | 3921 | | |
3923 | 3922 | | |
3924 | | - | |
| 3923 | + | |
3925 | 3924 | | |
3926 | 3925 | | |
3927 | 3926 | | |
| |||
4008 | 4007 | | |
4009 | 4008 | | |
4010 | 4009 | | |
4011 | | - | |
4012 | | - | |
4013 | | - | |
4014 | | - | |
4015 | | - | |
4016 | 4010 | | |
4017 | 4011 | | |
4018 | 4012 | | |
4019 | 4013 | | |
4020 | 4014 | | |
4021 | 4015 | | |
| 4016 | + | |
| 4017 | + | |
| 4018 | + | |
4022 | 4019 | | |
4023 | 4020 | | |
4024 | 4021 | | |
| |||
4041 | 4038 | | |
4042 | 4039 | | |
4043 | 4040 | | |
4044 | | - | |
| 4041 | + | |
| 4042 | + | |
| 4043 | + | |
4045 | 4044 | | |
4046 | 4045 | | |
4047 | 4046 | | |
| |||
0 commit comments