Re: [PATCH 01/11] Bluetooth: btintel: Fix diagnostics event detection

Luiz Augusto von Dentz <[email protected]> Mon, 27 Jul 2026 13:21:21 -0400
Newsgroups org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-kernel
Message-ID <CABBYNZJEn7iF6jrdM1tWpGd4eQQYx2qvKF9SQ5W9MhCFfQ2eGg@mail.gmail.com>
Hi Zijun,

On Sat, Jul 25, 2026 at 4:54 AM Zijun Hu <[email protected]> wrote:
>
> For a diagnostics VSE, diagnostics_hdr[] sits at the start of the event
> payload, skb->data[2], but btintel_recv_event() wrongly guards its
> memcmp with @len, which is measured from skb->data[3] for the earlier
> INTEL_BOOTLOADER check.
>
> Fix by using @hdr->plen, which is the event payload length, instead.
>
> Fixes: af395330abed ("Bluetooth: btintel: Add Intel devcoredump support")
> Signed-off-by: Zijun Hu <[email protected]>
> ---
>  drivers/bluetooth/btintel.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/bluetooth/btintel.c b/drivers/bluetooth/btintel.c
> index 5e9cac090bd8..d7baf1b9d852 100644
> --- a/drivers/bluetooth/btintel.c
> +++ b/drivers/bluetooth/btintel.c
> @@ -3826,17 +3826,17 @@ int btintel_recv_event(struct hci_dev *hdev, struct sk_buff *skb)
>                                 kfree_skb(skb);
>                                 return 0;
>                         }
>                 }
>
>                 /* Handle all diagnostics events separately. May still call
>                  * hci_recv_frame.
>                  */
> -               if (len >= sizeof(diagnostics_hdr) &&
> +               if (hdr->plen >= sizeof(diagnostics_hdr) &&
>                     memcmp(&skb->data[2], diagnostics_hdr,
>                            sizeof(diagnostics_hdr)) == 0) {
>                         return btintel_diagnostics(hdev, skb);
>                 }
>         }

While this seems correct the hdr->plen could also be wrong and don't
actually match skb content so Id prefer to use len - 1 or something
else that actually evaluate against skb->len.

>         return hci_recv_frame(hdev, skb);
>  }
>
> --
> 2.34.1
>


-- 
Luiz Augusto von Dentz