[PATCH 0/2] Bluetooth: btmtksdio: Fix SKB handling in the TX path
Chris Lu <[email protected]>
| Newsgroups | org.infradead.lists.linux-mediatek,org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
btmtksdio_tx_packet() rounds the SDIO transfer size up to the 256 byte block size, but never grows the SKB accordingly, so the host controller reads up to 255 bytes of uninitialised memory and sends it to the device, and can read past the end of the buffer as well. Patch 2 fixes that by padding the SKB with zeros. The padding is written behind skb->tail, which is only safe once the driver owns the data buffer, so patch 1 replaces the open-coded headroom check with skb_cow_head() first. Patch 1 on its own changes no observable behaviour, but it is a hard prerequisite, so both patches carry the same Fixes: tag. Both patches were previously part of a larger MT7928 series [1]. They are unrelated to MT7928 and to the USB driver, so they are sent separately here. The remaining parts of that series will follow as separate topic branches. Tested on a Chromebook with MT7921S: Bluetooth power on, then A2DP connect and stream continuously for one hour without failure. The padding added by patch 2 covers every packet whose length is not a multiple of the block size, and the reallocation added by patch 1 covers every HCI command, which hci_send_cmd_sync() always clones into hdev->sent_cmd. [1] https://lore.kernel.org/linux-bluetooth/[email protected]/ Chris Lu (2): Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path drivers/bluetooth/btmtksdio.c | 33 ++++++++++++++++++++++++--------- 1 file changed, 24 insertions(+), 9 deletions(-) -- 2.45.2