Re: [PATCH v3] Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready

Luiz Augusto von Dentz <[email protected]>
Newsgroups org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <CABBYNZL1_fTkwdhjK0aKqg44c0MneOAOWThQQDPudFUe0m_htA@mail.gmail.com>
Hi Hang,

On Tue, Aug 18, 2026 at 7:33 AM Hang Nan <[email protected]> wrote:
>
> iso_conn_ready() looks up the BIS listener socket with iso_get_sock(),
> which takes a reference, and then, without re-checking its state,
> creates a child socket from it:
>
>     parent = iso_get_sock(hdev, ...);
>     if (!parent)
>         return;
>
>     lock_sock(parent);
>     sk = iso_sock_alloc(sock_net(parent), NULL, BTPROTO_ISO, ...);
>     ...
>     iso_chan_add(conn, sk, parent);
>     ...
>     release_sock(parent);
>     sock_put(parent);
>
> If the listener socket is closed concurrently, between iso_get_sock()
> and lock_sock(), the reference taken by iso_get_sock() may be the last
> one: the close path drops the link-list reference, and once
> iso_conn_ready() drops its own reference at the end of the function the
> socket is freed.  The child socket, however, is already linked to the
> freed parent, and a later disconnect of the child runs iso_chan_del()
> -> bt_accept_unlink(), which dereferences the dangling parent pointer
> into the freed accept queue (a use-after-free).  The same dangling
> pointer is also dereferenced through parent->***() in
> iso_chan_del().
>
> Fix it the same way the connected (non-BIS) path was fixed in commit
> 0d255e63fcf3 ("Bluetooth: ISO: hold sk properly in iso_conn_ready"):
> after taking the socket lock, re-check that the parent is still a
> listening, alive socket, and bail out otherwise.
>
> Fixes: ccf74f2390d60 ("Bluetooth: Add BTPROTO_ISO socket type")
> Cc: [email protected]
> Signed-off-by: Hang Nan <[email protected]>
> ---
> Changes in v3:
> - Move the changelog below the "---" separator so it is not part
>   of the commit message
> - Shorten the comment in iso_conn_ready()
>
> Changes in v2:
> - Fix GitLint B3: replace hard tabs with spaces in the commit
>   message code snippet (no functional change)
>
>  net/bluetooth/iso.c | 8 ++++++++
>  1 file changed, 8 insertions(+)
>
> diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
> index aa2ce78f56a2..069fc87a4e18 100644
> --- a/net/bluetooth/iso.c
> +++ b/net/bluetooth/iso.c
> @@ -2277,6 +2277,14 @@ static void iso_conn_ready(struct iso_conn *conn)
>
>                 lock_sock(parent);
>
> +               /* The listener may have been closed concurrently. */
> +               if (parent->sk_state != BT_LISTEN ||
> +                   (parent, SOCK_ZAPPED)) {
> +                       release_sock_flagsock(parent);
> +                       sock_put(parent);
> +                       return;
> +               }

Looks like there is a typo and this should have been release_sock
rather than release_sock_flagsock (or there is a new function called
that introduced via some other tree?)

>                 sk = iso_sock_alloc(sock_net(parent), NULL,
>                                     BTPROTO_ISO, GFP_ATOMIC, 0);
>                 if (!sk) {
>


-- 
Luiz Augusto von Dentz
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.