* [PATCH] Bluetooth: btqcomsmd: Fix skb double free corruption
@ 2017-11-22 14:03 Loic Poulain
2017-11-28 8:44 ` Marcel Holtmann
0 siblings, 1 reply; 2+ messages in thread
From: Loic Poulain @ 2017-11-22 14:03 UTC (permalink / raw)
To: marcel, johan.hedberg; +Cc: linux-bluetooth, Loic Poulain
In case of hci send frame failure, skb is still owned
by the caller (hci_core) and then should not be freed.
This fixes crash on dragonboard-410c when sending SCO
packet. skb is freed by both btqcomsmd and hci_core.
Fixes: 1511cc750c3d ("Bluetooth: Introduce Qualcomm WCNSS SMD based HCI driver")
Signed-off-by: Loic Poulain <loic.poulain@linaro.org>
---
drivers/bluetooth/btqcomsmd.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btqcomsmd.c b/drivers/bluetooth/btqcomsmd.c
index 663bed6..2c9a5fc 100644
--- a/drivers/bluetooth/btqcomsmd.c
+++ b/drivers/bluetooth/btqcomsmd.c
@@ -88,7 +88,8 @@ static int btqcomsmd_send(struct hci_dev *hdev, struct sk_buff *skb)
break;
}
- kfree_skb(skb);
+ if (!ret)
+ kfree_skb(skb);
return ret;
}
--
2.7.4
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] Bluetooth: btqcomsmd: Fix skb double free corruption
2017-11-22 14:03 [PATCH] Bluetooth: btqcomsmd: Fix skb double free corruption Loic Poulain
@ 2017-11-28 8:44 ` Marcel Holtmann
0 siblings, 0 replies; 2+ messages in thread
From: Marcel Holtmann @ 2017-11-28 8:44 UTC (permalink / raw)
To: Loic Poulain; +Cc: Johan Hedberg, linux-bluetooth
Hi Loic,
> In case of hci send frame failure, skb is still owned
> by the caller (hci_core) and then should not be freed.
>
> This fixes crash on dragonboard-410c when sending SCO
> packet. skb is freed by both btqcomsmd and hci_core.
>
> Fixes: 1511cc750c3d ("Bluetooth: Introduce Qualcomm WCNSS SMD based HCI driver")
> Signed-off-by: Loic Poulain <loic.poulain@linaro.org>
> ---
> drivers/bluetooth/btqcomsmd.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
patch has been applied to bluetooth-next tree.
Regards
Marcel
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2017-11-28 8:44 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-11-22 14:03 [PATCH] Bluetooth: btqcomsmd: Fix skb double free corruption Loic Poulain
2017-11-28 8:44 ` Marcel Holtmann
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).