]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced
authorLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Wed, 20 Aug 2025 21:04:00 +0000 (17:04 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 4 Sep 2025 13:31:46 +0000 (15:31 +0200)
[ Upstream commit 15bf2c6391bafb14a3020d06ec0761bce0803463 ]

This attempts to detect if HCI_EV_NUM_COMP_PKTS contain an unbalanced
(more than currently considered outstanding) number of packets otherwise
it could cause the hcon->sent to underflow and loop around breaking the
tracking of the outstanding packets pending acknowledgment.

Fixes: f42809185896 ("Bluetooth: Simplify num_comp_pkts_evt function")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/bluetooth/hci_event.c

index b8213bfa0a674ec96e306dbea88fee250910ad8b..262ff30261d67dba1e57a72dfcd0680669ababbd 100644 (file)
@@ -4395,7 +4395,17 @@ static void hci_num_comp_pkts_evt(struct hci_dev *hdev, void *data,
                if (!conn)
                        continue;
 
-               conn->sent -= count;
+               /* Check if there is really enough packets outstanding before
+                * attempting to decrease the sent counter otherwise it could
+                * underflow..
+                */
+               if (conn->sent >= count) {
+                       conn->sent -= count;
+               } else {
+                       bt_dev_warn(hdev, "hcon %p sent %u < count %u",
+                                   conn, conn->sent, count);
+                       conn->sent = 0;
+               }
 
                switch (conn->type) {
                case ACL_LINK: