]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
authorPauli Virtanen <pav@iki.fi>
Sat, 25 Jul 2026 09:59:17 +0000 (12:59 +0300)
committerLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Tue, 28 Jul 2026 20:13:12 +0000 (16:13 -0400)
There is theoretical UAF if the conn is freed while the hci_sync task is
running.

Hold refcount to avoid that.

Fixes: 227a0cdf4a02 ("Bluetooth: MGMT: Fix not generating command complete for MGMT_OP_DISCONNECT")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
net/bluetooth/hci_conn.c

index ebb04badf10c0ca40f1669cc2d5dd45d75fb2c7d..b1f911fd4ad6a605a654420f1ec569882dfef52f 100644 (file)
@@ -3165,6 +3165,13 @@ static int abort_conn_sync(struct hci_dev *hdev, void *data)
        return hci_abort_conn_sync(hdev, conn, conn->abort_reason);
 }
 
+static void abort_conn_destroy(struct hci_dev *hdev, void *data, int err)
+{
+       struct hci_conn *conn = data;
+
+       hci_conn_put(conn);
+}
+
 int hci_abort_conn(struct hci_conn *conn, u8 reason)
 {
        struct hci_dev *hdev = conn->hdev;
@@ -3190,7 +3197,10 @@ int hci_abort_conn(struct hci_conn *conn, u8 reason)
         * as a result to MGMT_OP_DISCONNECT/MGMT_OP_UNPAIR which does
         * already queue its callback on cmd_sync_work.
         */
-       err = hci_cmd_sync_run_once(hdev, abort_conn_sync, conn, NULL);
+       err = hci_cmd_sync_run_once(hdev, abort_conn_sync, hci_conn_get(conn),
+                                   abort_conn_destroy);
+       if (err)
+               hci_conn_put(conn);
        return (err == -EEXIST) ? 0 : err;
 }