Re: [PATCH 5.15.y, 5.10.y] Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref

Sasha Levin <[email protected]>
Newsgroups org.kernel.vger.stable
Message-ID <[email protected]>
On Fri, Aug 07, 2026 at 06:58:01PM +0000, Todd Kjos wrote:
>-	if (conn) {
>-		struct amp_mgr *mgr = conn->hcon->amp_mgr;
>+	if (!test_and_set_bit(FLAG_DEL, &chan->flags)) {
>+		struct amp_mgr *mgr = chan->conn->hcon->amp_mgr;

Hmm... I don't think that dropping the "conn" NULL check is safe on these trees. 5.15 and
5.10 still have net/bluetooth/a2mp.c, and a2mp_chan_open() calls
l2cap_chan_del(chan, 0) on the l2cap_ertm_init() failure path, before
__l2cap_chan_add() has run - so chan->conn is still NULL there. With
this hunk that dereferences chan->conn->hcon->amp_mgr and then list_del()s
a zeroed list_head. Upstream is only safe because BT_HS and a2mp.c were
removed before b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel
timeout by holding conn ref") landed.

It's also missing a follow-up fix:

  d38eaf611839 ("Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev")

-- 
Thanks,
Sasha
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.