]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
Bluetooth: hci_core: Fix calling mgmt_device_connected
authorLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Fri, 8 Nov 2024 16:19:54 +0000 (11:19 -0500)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 14 Dec 2024 18:51:47 +0000 (19:51 +0100)
commit 7967dc8f797f454d4f4acec15c7df0cdf4801617 upstream.

Since 61a939c68ee0 ("Bluetooth: Queue incoming ACL data until
BT_CONNECTED state is reached") there is no long the need to call
mgmt_device_connected as ACL data will be queued until BT_CONNECTED
state.

Link: https://bugzilla.kernel.org/show_bug.cgi?id=219458
Link: https://github.com/bluez/bluez/issues/1014
Fixes: 333b4fd11e89 ("Bluetooth: L2CAP: Fix uaf in l2cap_connect")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/bluetooth/hci_core.c

index f611379dc19446709ba0f9946d915e7923ac1ee0..7ed5d6e47e4f351d72acec56c369ef0a1060e121 100644 (file)
@@ -4964,8 +4964,6 @@ static void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb)
 
        hci_dev_lock(hdev);
        conn = hci_conn_hash_lookup_handle(hdev, handle);
-       if (conn && hci_dev_test_flag(hdev, HCI_MGMT))
-               mgmt_device_connected(hdev, conn, NULL, 0);
        hci_dev_unlock(hdev);
 
        if (conn) {