Linux bluetooth development
 help / color / mirror / Atom feed
* [PATCH] Bluetooth: hci_core: Serialize fragmented ISO packet queueing
@ 2026-09-26 17:29 Chengfeng Ye
  2026-09-27 23:26 ` bluez.test.bot
  2026-09-28 15:40 ` [PATCH] " patchwork-bot+bluetooth
  0 siblings, 2 replies; 3+ messages in thread
From: Chengfeng Ye @ 2026-09-26 17:29 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz
  Cc: linux-bluetooth, linux-kernel, Chengfeng Ye, stable

The fragmented path in hci_queue_iso() calls __skb_queue_tail() without
holding conn->data_q.lock. The socket lock serializes senders, but the
transmit worker can concurrently remove packets from this queue using
skb_dequeue().

After an insertion saves the old tail pointer, hci_sched_iso() can dequeue
that packet and pass it to the driver. The driver can free the packet
before the insertion resumes and writes to the old tail's next pointer,
causing a use-after-free. Concurrent updates can also corrupt the queue.

KASAN reported:

  BUG: KASAN: slab-use-after-free in hci_send_iso+0xc7d/0xe10
  Call Trace:
   hci_send_iso+0xc7d/0xe10
   iso_sock_sendmsg+0x710/0x900
   __sys_sendto+0x34a/0x3a0

  Allocated by task 86:
   __alloc_skb+0xdd/0x820
   alloc_skb_with_frags+0x7e/0x770
   sock_alloc_send_pskb+0x67a/0x820
   bt_skb_sendmsg.constprop.0+0xc0/0x6c0
   iso_sock_sendmsg+0x44e/0x900

  Freed by task 90:
   kmem_cache_free+0xcb/0x3d0
   vhci_read+0x33f/0x4d0
   vfs_read+0x177/0xa20

Hold the queue lock across the entire fragment batch, as hci_queue_acl()
does, to serialize insertion against dequeue while preserving fragment
ordering.

Fixes: 26afbd826ee3 ("Bluetooth: Add initial implementation of CIS connections")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
 net/bluetooth/hci_core.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index d183efaf9063..9ae1b25d7f60 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -3325,6 +3325,8 @@ static void hci_queue_iso(struct hci_conn *conn, struct sk_buff_head *queue,
 
 		skb_shinfo(skb)->frag_list = NULL;
 
+		spin_lock_bh(&queue->lock);
+
 		__skb_queue_tail(queue, skb);
 
 		do {
@@ -3339,6 +3341,8 @@ static void hci_queue_iso(struct hci_conn *conn, struct sk_buff_head *queue,
 
 			__skb_queue_tail(queue, skb);
 		} while (list);
+
+		spin_unlock_bh(&queue->lock);
 	}
 
 	bt_dev_dbg(hdev, "hcon %p queued %d", conn, skb_queue_len(queue));
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* RE: Bluetooth: hci_core: Serialize fragmented ISO packet queueing
  2026-09-26 17:29 [PATCH] Bluetooth: hci_core: Serialize fragmented ISO packet queueing Chengfeng Ye
@ 2026-09-27 23:26 ` bluez.test.bot
  2026-09-28 15:40 ` [PATCH] " patchwork-bot+bluetooth
  1 sibling, 0 replies; 3+ messages in thread
From: bluez.test.bot @ 2026-09-27 23:26 UTC (permalink / raw)
  To: linux-bluetooth, nicoyip.dev

[-- Attachment #1: Type: text/plain, Size: 1958 bytes --]

This is automated email and please do not reply to this email!

Dear submitter,

Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1174572/

---Test result---

Test Summary:
CheckPatch                    PASS      0.77 seconds
VerifyFixes                   PASS      0.14 seconds
VerifySignedoff               PASS      0.13 seconds
GitLint                       PASS      0.35 seconds
SubjectPrefix                 PASS      0.13 seconds
BuildKernel                   PASS      30.02 seconds
CheckAllWarning               PASS      33.78 seconds
CheckSparse                   PASS      35.76 seconds
BuildKernel32                 PASS      28.90 seconds
CheckKernelLLVM               PASS      32.81 seconds
TestRunnerSetup               PASS      790.39 seconds
TestRunner_l2cap-tester       PASS      16.60 seconds
TestRunner_iso-tester         PASS      30.86 seconds
TestRunner_bnep-tester        PASS      3.14 seconds
TestRunner_mgmt-tester        PASS      61.02 seconds
TestRunner_rfcomm-tester      PASS      4.49 seconds
TestRunner_sco-tester         PASS      7.64 seconds
TestRunner_ioctl-tester       PASS      4.66 seconds
TestRunner_mesh-tester        FAIL      7.85 seconds
TestRunner_smp-tester         PASS      4.32 seconds
TestRunner_userchan-tester    PASS      3.22 seconds
TestRunner_6lowpan-tester     PASS      4.39 seconds
IncrementalBuild              PASS      27.08 seconds

Details
##############################
Test: TestRunner_mesh-tester - FAIL
Desc: Run mesh-tester with test-runner
Output:
Total: 10, Passed: 8 (80.0%), Failed: 2, Not Run: 0

Failed Test Cases
Mesh - Send cancel - 1                               Timed out    2.422 seconds
Mesh - Send cancel - 2                               Timed out    1.999 seconds


https://github.com/bluez/bluetooth-next/pull/826

---
Regards,
Linux Bluetooth


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] Bluetooth: hci_core: Serialize fragmented ISO packet queueing
  2026-09-26 17:29 [PATCH] Bluetooth: hci_core: Serialize fragmented ISO packet queueing Chengfeng Ye
  2026-09-27 23:26 ` bluez.test.bot
@ 2026-09-28 15:40 ` patchwork-bot+bluetooth
  1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+bluetooth @ 2026-09-28 15:40 UTC (permalink / raw)
  To: Chengfeng Ye; +Cc: marcel, luiz.dentz, linux-bluetooth, linux-kernel, stable

Hello:

This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@intel.com>:

On Sun, 27 Sep 2026 01:29:35 +0800 you wrote:
> The fragmented path in hci_queue_iso() calls __skb_queue_tail() without
> holding conn->data_q.lock. The socket lock serializes senders, but the
> transmit worker can concurrently remove packets from this queue using
> skb_dequeue().
> 
> After an insertion saves the old tail pointer, hci_sched_iso() can dequeue
> that packet and pass it to the driver. The driver can free the packet
> before the insertion resumes and writes to the old tail's next pointer,
> causing a use-after-free. Concurrent updates can also corrupt the queue.
> 
> [...]

Here is the summary with links:
  - Bluetooth: hci_core: Serialize fragmented ISO packet queueing
    https://git.kernel.org/bluetooth/bluetooth-next/c/1a572db43c05

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-28 15:41 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 17:29 [PATCH] Bluetooth: hci_core: Serialize fragmented ISO packet queueing Chengfeng Ye
2026-09-27 23:26 ` bluez.test.bot
2026-09-28 15:40 ` [PATCH] " patchwork-bot+bluetooth

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox