]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
authorPauli Virtanen <pav@iki.fi>
Sat, 25 Jul 2026 09:59:22 +0000 (12:59 +0300)
committerLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Tue, 28 Jul 2026 20:13:13 +0000 (16:13 -0400)
hci_conn_del() caller must hold hdev->lock, check the conn was not
concurrently deleted, and usually inform socket the conn is going to be
deleted.

Use hci_abort_conn_sync() instead of calling hci_conn_del() without
locks etc.

Fixes: 8e8b92ee60de5 ("Bluetooth: hci_sync: Add hci_le_create_conn_sync")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
net/bluetooth/hci_sync.c

index 0118342ac7ea23445be01bbcd3e9713a6f073fad..10bc4c71509f4c4c16fe256bcf88bfbd136da694 100644 (file)
@@ -6757,7 +6757,9 @@ static int hci_le_create_conn_sync(struct hci_dev *hdev, void *data)
                if (hci_dev_test_flag(hdev, HCI_LE_SCAN) &&
                    hdev->le_scan_type == LE_SCAN_ACTIVE &&
                    !hci_dev_test_flag(hdev, HCI_LE_SIMULTANEOUS_ROLES)) {
-                       hci_conn_del(conn);
+                       conn->state = BT_OPEN;
+                       hci_abort_conn_sync(hdev, conn,
+                                           HCI_ERROR_REJ_LIMITED_RESOURCES);
                        hci_conn_put(conn);
                        return -EBUSY;
                }