From: Johan Hedberg <johan.hedberg@gmail.com>
To: Glenn Ruben Bakke <glenn.ruben.bakke@nordicsemi.no>
Cc: alex.aring@gmail.com, linux-bluetooth@vger.kernel.org,
lukasz.duda@nordicsemi.no
Subject: Re: [PATCH] Bluetooth: 6lowpan: Fix kernel NULL pointer dereferences
Date: Sat, 23 Jan 2016 12:25:36 +0000 [thread overview]
Message-ID: <20160123122536.GA16166@t440s> (raw)
In-Reply-To: <1452699702-3986-1-git-send-email-glenn.ruben.bakke@nordicsemi.no>
Hi Glenn,
On Wed, Jan 13, 2016, Glenn Ruben Bakke wrote:
> The fixes provided in this patch assigns a valid net_device structure to
> skb before dispatching it for further processing.
>
> Scenario #1:
> ============
>
> Bluetooth 6lowpan receives an uncompressed IPv6 header, and dispatches it
> to netif. The following error occurs:
>
> Null pointer dereference error #1 crash log:
>
> [ 845.854013] BUG: unable to handle kernel NULL pointer dereference at
> 0000000000000048
> [ 845.855785] IP: [<ffffffff816e3d36>] enqueue_to_backlog+0x56/0x240
> ...
> [ 845.909459] Call Trace:
> [ 845.911678] [<ffffffff816e3f64>] netif_rx_internal+0x44/0xf0
>
> The first modification fixes the NULL pointer dereference error by
> assigning dev to the local_skb in order to set a valid net_device before
> processing the skb by netif_rx_ni().
>
> Scenario #2:
> ============
>
> Bluetooth 6lowpan receives an UDP compressed message which needs further
> decompression by nhc_udp. The following error occurs:
>
> Null pointer dereference error #2 crash log:
>
> [ 63.295149] BUG: unable to handle kernel NULL pointer dereference at
> 0000000000000840
> [ 63.295931] IP: [<ffffffffc0559540>] udp_uncompress+0x320/0x626
> [nhc_udp]
>
> The second modification fixes the NULL pointer dereference error by
> assigning dev to the local_skb in the case of a udp compressed packet.
> The 6lowpan udp_uncompress function expects that the net_device is set in
> the skb when checking lltype.
>
> Signed-off-by: Glenn Ruben Bakke <glenn.ruben.bakke@nordicsemi.no>
> Signed-off-by: Lukasz Duda <lukasz.duda@nordicsemi.no>
> ---
> net/bluetooth/6lowpan.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
Applied to bluetooth.git. Thanks.
Johan
prev parent reply other threads:[~2016-01-23 12:25 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-01-13 15:41 [PATCH] Bluetooth: 6lowpan: Fix kernel NULL pointer dereferences Glenn Ruben Bakke
2016-01-14 10:28 ` Jukka Rissanen
2016-01-23 12:25 ` Johan Hedberg [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160123122536.GA16166@t440s \
--to=johan.hedberg@gmail.com \
--cc=alex.aring@gmail.com \
--cc=glenn.ruben.bakke@nordicsemi.no \
--cc=linux-bluetooth@vger.kernel.org \
--cc=lukasz.duda@nordicsemi.no \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox