[BUG] Bluetooth: KASAN null-ptr-deref in klist_put during HCI connection sysfs teardown

ZW Tang <[email protected]>
Newsgroups org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-kernel
Message-ID <CAA2SOT5U4fUJg2DOKr0-YKm0g5xAutjLKvkci99k5kQ6GMtf0g@mail.gmail.com>
Hi,

I am reporting a KASAN null-ptr-deref triggered by a syzkaller
reproducer on Linux 7.2-rc3.

The crash happens during Bluetooth HCI/vhci teardown. The reproducer
creates Bluetooth L2CAP/BNEP sockets and issues BNEPCONNADD. When the
syz-executor exits, vhci_release() unregisters the HCI device, which
flushes HCI connections and reaches hci_conn_del_sysfs(). During this
sysfs cleanup path, device_move() tries to move a child device away
from the HCI connection device, and the kernel crashes in klist_put()
while removing the device from the old parent's klist.

This looks like a Bluetooth HCI connection sysfs lifetime / teardown
ordering issue, rather than a generic klist problem.

Reproducer:
syz reproducer: https://pastebin.com/raw/n2k0FdAq
kernel config: https://pastebin.com/raw/j608iPvW
console output: https://pastebin.com/raw/Sy0Am14Y

Kernel:
HEAD commit: 1137d8b5df06137fb49513cc923b3b24d94cb809
git tree: torvalds/linux
kernel version: 7.2.0-rc3 #1 PREEMPT(full) (QEMU Ubuntu 24.10)

Crash log excerpt:

Oops: general protection fault, probably for non-canonical address
0xdffffc000000000b: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000058-0x000000000000005f]
CPU: 1 UID: 0 PID: 22881 Comm: syz-executor Not tainted 7.2.0-rc3 #1
PREEMPT(full)
Hardware name: QEMU Ubuntu 24.10 PC (i440FX + PIIX, 1996), BIOS
1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010+0x4b/0x170

Call Trace:
<TASK>
klist_remove+0x12a/0x2d0
device_move+0x136/0xf10
hci_conn_del_sysfs+0x87/0x1b0
hci_conn_del+0x5ca/0x11e0
hci_conn_hash_flush+0x184/0x290
hci_dev_close_sync+0x656/0x1350
hci_dev_do_close+0x31/0xc0
hci_unregister_dev+0x23f/0x6a0
vhci_release+0x181/0x230
__fput+0x401/0xb50
task_work_run+0x172/0x280
do_exit+0xa54/0x3030
do_group_exit+0xd3/0x2a0
get_signal+0x26db/0x2790
arch_do_signal_or_restart+0x80/0x910
exit_to_user_mode_loop+0x115/0x660
do_syscall_64+0x5ba/0x7a0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>

Registers around the fault:

RAX: dffffc0000000000 RBX: 0000000000000001 RCX: 0000000000000000
RDX: 000000000000000b RSI: ffff8880006d5940 RDI: 0000000000000058
RBP: ffff888075ce9c60 R12: 0000000000000000

The NULL-deref range and RDI=0x58 suggest that klist_put() is
dereferencing a field through a NULL klist pointer while device_move()
is removing the device from its old parent's klist. Since this is
reached from hci_conn_del_sysfs(), it may indicate that a child device
under the HCI connection sysfs device is being moved or removed after
its parent klist state has already been cleared, or that the same
child/connection sysfs relation can be torn down more than once during
HCI device unregister.


Thanks
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.