Re: [PATCH] Bluetooth: L2CAP: access chan->conn safely in get/setsockopt

[email protected]
Newsgroups org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-kernel
Message-ID <178647901038.1134064.15275221947394205709.git-patchwork-notify@kernel.org>
Hello:

This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <[email protected]>:

On Sun,  9 Aug 2026 20:42:41 +0300 you wrote:
> Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref")
> l2cap_chan::conn has held reference and remains non-NULL also after the
> corresponding hci_conn is deleted.  In this state accessing various
> fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in
> l2cap_sock_setsockopt() access of conn->hcon->hdev.
> 
> Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before
> trying to use it in l2cap_sock.c.  Hold l2cap_chan_lock() in
> getsockopt/setsockopt to ensure it stays alive, and to avoid data races
> in l2cap_chan fields.
> 
> [...]

Here is the summary with links:
  - Bluetooth: L2CAP: access chan->conn safely in get/setsockopt
    https://git.kernel.org/bluetooth/bluetooth-next/c/d1b752f55289

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.