Re: [PATCH 0/2] Bluetooth: btmtksdio: Fix SKB handling in the TX path

[email protected]
Newsgroups org.kernel.vger.linux-bluetooth,org.infradead.lists.linux-mediatek,org.kernel.vger.linux-kernel
Message-ID <178699595738.1691257.9499694982738760170.git-patchwork-notify@kernel.org>
Hello:

This series was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <[email protected]>:

On Mon, 17 Aug 2026 17:53:30 +0800 you wrote:
> btmtksdio_tx_packet() rounds the SDIO transfer size up to the 256 byte
> block size, but never grows the SKB accordingly, so the host controller
> reads up to 255 bytes of uninitialised memory and sends it to the device,
> and can read past the end of the buffer as well.
> 
> Patch 2 fixes that by padding the SKB with zeros. The padding is written
> behind skb->tail, which is only safe once the driver owns the data
> buffer, so patch 1 replaces the open-coded headroom check with
> skb_cow_head() first. Patch 1 on its own changes no observable
> behaviour, but it is a hard prerequisite, so both patches carry the same
> Fixes: tag.
> 
> [...]

Here is the summary with links:
  - [1/2] Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX
    https://git.kernel.org/bluetooth/bluetooth-next/c/951d9f743029
  - [2/2] Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path
    https://git.kernel.org/bluetooth/bluetooth-next/c/262cb784c96c

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.