Linux bluetooth development
 help / color / mirror / Atom feed
From: Johan Hedberg <johan.hedberg@gmail.com>
To: Glenn Ruben Bakke <glenn.ruben.bakke@nordicsemi.no>
Cc: alex.aring@gmail.com, linux-bluetooth@vger.kernel.org,
	lukasz.duda@nordicsemi.no
Subject: Re: [PATCH] Bluetooth: 6lowpan: Fix kernel NULL pointer dereferences
Date: Sat, 23 Jan 2016 12:25:36 +0000	[thread overview]
Message-ID: <20160123122536.GA16166@t440s> (raw)
In-Reply-To: <1452699702-3986-1-git-send-email-glenn.ruben.bakke@nordicsemi.no>

Hi Glenn,

On Wed, Jan 13, 2016, Glenn Ruben Bakke wrote:
> The fixes provided in this patch assigns a valid net_device structure to
> skb before dispatching it for further processing.
> 
> Scenario #1:
> ============
> 
> Bluetooth 6lowpan receives an uncompressed IPv6 header, and dispatches it
> to netif. The following error occurs:
> 
> Null pointer dereference error #1 crash log:
> 
> [  845.854013] BUG: unable to handle kernel NULL pointer dereference at
>                0000000000000048
> [  845.855785] IP: [<ffffffff816e3d36>] enqueue_to_backlog+0x56/0x240
> ...
> [  845.909459] Call Trace:
> [  845.911678]  [<ffffffff816e3f64>] netif_rx_internal+0x44/0xf0
> 
> The first modification fixes the NULL pointer dereference error by
> assigning dev to the local_skb in order to set a valid net_device before
> processing the skb by netif_rx_ni().
> 
> Scenario #2:
> ============
> 
> Bluetooth 6lowpan receives an UDP compressed message which needs further
> decompression by nhc_udp. The following error occurs:
> 
> Null pointer dereference error #2 crash log:
> 
> [   63.295149] BUG: unable to handle kernel NULL pointer dereference at
>                0000000000000840
> [   63.295931] IP: [<ffffffffc0559540>] udp_uncompress+0x320/0x626
>                [nhc_udp]
> 
> The second modification fixes the NULL pointer dereference error by
> assigning dev to the local_skb in the case of a udp compressed packet.
> The 6lowpan udp_uncompress function expects that the net_device is set in
> the skb when checking lltype.
> 
> Signed-off-by: Glenn Ruben Bakke <glenn.ruben.bakke@nordicsemi.no>
> Signed-off-by: Lukasz Duda <lukasz.duda@nordicsemi.no>
> ---
>  net/bluetooth/6lowpan.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)

Applied to bluetooth.git. Thanks.

Johan

      parent reply	other threads:[~2016-01-23 12:25 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-01-13 15:41 [PATCH] Bluetooth: 6lowpan: Fix kernel NULL pointer dereferences Glenn Ruben Bakke
2016-01-14 10:28 ` Jukka Rissanen
2016-01-23 12:25 ` Johan Hedberg [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20160123122536.GA16166@t440s \
    --to=johan.hedberg@gmail.com \
    --cc=alex.aring@gmail.com \
    --cc=glenn.ruben.bakke@nordicsemi.no \
    --cc=linux-bluetooth@vger.kernel.org \
    --cc=lukasz.duda@nordicsemi.no \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox