* [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
@ 2026-09-15 9:13 Zijun Hu
2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
2026-09-15 9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu
0 siblings, 2 replies; 5+ messages in thread
From: Zijun Hu @ 2026-09-15 9:13 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz
Cc: Linux Bluetooth, linux-kernel, Zijun Hu
This series fixes heap-buffer-overflows in btmon and btmon-logger
triggered by HCI devcoredump.
---
Previous discussion link:
https://lore.kernel.org/all/20260913-misc_fix-v1-2-558c1e4028b9@oss.qualcomm.com
---
Zijun Hu (2):
monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump
monitor/control.c | 3 +++
tools/btmon-logger.c | 3 +++
2 files changed, 6 insertions(+)
---
base-commit: c8e2b951b07fc9b84fa7f3e70dcde2b61aab3ad8
change-id: 20260915-fix_heap_overflow-4e93e9ed9063
Best regards,
--
Zijun Hu <zijun.hu@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 5+ messages in thread* [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump 2026-09-15 9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu @ 2026-09-15 9:13 ` Zijun Hu 2026-09-15 11:25 ` monitor: Fix heap-buffer-overflows " bluez.test.bot 2026-09-30 14:09 ` bluez.test.bot 2026-09-15 9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu 1 sibling, 2 replies; 5+ messages in thread From: Zijun Hu @ 2026-09-15 9:13 UTC (permalink / raw) To: Marcel Holtmann, Luiz Augusto von Dentz Cc: Linux Bluetooth, linux-kernel, Zijun Hu Kernel HCI devcoredump can accumulate a large amount of dump data from MANY packets, then send it as a SINGLE DIAG packet to the monitor channel, so cause payload length @len in the header exceed BTSNOOP_MAX_PACKET_SIZE, but btmon uses @len to access the payload in @buf without validating that @len fits within @buf, causing a heap-buffer-overflow. Kernel: include/net/bluetooth/hci_mon.h struct hci_mon_hdr { __le16 opcode; __le16 index; __le16 len; } __packed; BlueZ: src/shared/btsnoop.h #define BTSNOOP_MAX_PACKET_SIZE (1486 + 4) monitor/control.c struct control_data { uint16_t channel; int fd; unsigned char buf[BTSNOOP_MAX_PACKET_SIZE]; uint16_t offset; }; The heap-buffer-overflow Issue: ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088 READ of size 17916 at 0x51b00000065c thread T0 #0 0x7f50b987a028 in write ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:1096 #1 0x5b4f3443ae3a in btsnoop_write ../src/shared/btsnoop.c:289 #2 0x5b4f3429cbf0 in data_callback ../monitor/control.c:969 #3 0x5b4f3444fa9d in mainloop_run ../src/shared/mainloop.c:104 #4 0x5b4f34451da6 in mainloop_run_with_signal ../src/shared/mainloop-notify.c:196 #5 0x5b4f342953fc in main ../monitor/main.c:303 #6 0x7f50b8c2a1c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 #7 0x7f50b8c2a28a in __libc_start_main_impl ../csu/libc-start.c:360 #8 0x5b4f34295ed4 in _start (/usr/bin/btmon+0x29fed4) (BuildId: b41caafb24db693946c283eaea48112186863d2d) Fix by clamping @len to the amount of data received before accessing @buf. --- monitor/control.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/monitor/control.c b/monitor/control.c index 83347d5dbc3e..1eab9c4fe0bd 100644 --- a/monitor/control.c +++ b/monitor/control.c @@ -961,16 +961,19 @@ static void data_callback(int fd, uint32_t events, void *user_data) pktlen = le16_to_cpu(hdr.len); switch (data->channel) { case HCI_CHANNEL_CONTROL: packet_control(tv, cred, index, opcode, data->buf, pktlen); break; case HCI_CHANNEL_MONITOR: + if (pktlen > (len - MGMT_HDR_SIZE)) + pktlen = (len - MGMT_HDR_SIZE); + btsnoop_write_hci(btsnoop_file, tv, index, opcode, 0, data->buf, pktlen); ellisys_inject_hci(tv, index, opcode, data->buf, pktlen); packet_monitor(tv, cred, index, opcode, data->buf, pktlen); break; } -- 2.34.1 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* RE: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump 2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu @ 2026-09-15 11:25 ` bluez.test.bot 2026-09-30 14:09 ` bluez.test.bot 1 sibling, 0 replies; 5+ messages in thread From: bluez.test.bot @ 2026-09-15 11:25 UTC (permalink / raw) To: linux-bluetooth, zijun.hu [-- Attachment #1: Type: text/plain, Size: 8593 bytes --] This is automated email and please do not reply to this email! Dear submitter, Thank you for submitting the patches to the linux bluetooth mailing list. This is a CI test results with your patch series: PW Link:https://patchwork.kernel.org/series/1165307/ ---Test result--- Test Summary: CheckPatch FAIL 0.69 seconds GitLint FAIL 0.49 seconds BuildEll PASS 19.19 seconds BluezMake PASS 373.53 seconds MakeCheck PASS 0.85 seconds MakeDistcheck PASS 138.00 seconds CheckValgrind PASS 144.17 seconds CheckSmatch PASS 291.46 seconds bluezmakeextell PASS 92.06 seconds TestFunctional FAIL 1075.56 seconds IncrementalBuild PASS 380.35 seconds ScanBuild PASS 1107.21 seconds Details ############################## Test: CheckPatch - FAIL Desc: Run checkpatch.pl script Output: [BlueZ,1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump WARNING:COMMIT_COMMENT_SYMBOL: Commit log lines starting with '#' are dropped by git as comments #172: #define BTSNOOP_MAX_PACKET_SIZE (1486 + 4) WARNING:COMMIT_LOG_LONG_LINE: Prefer a maximum 75 chars per line (possible unwrapped commit description?) #182: ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088 /github/workspace/src/patch/14817038.patch total: 0 errors, 2 warnings, 19 lines checked NOTE: For some of the reported defects, checkpatch may be able to mechanically convert to the typical style using --fix or --fix-inplace. /github/workspace/src/patch/14817038.patch has style problems, please review. NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO NOTE: If any of the errors are false positives, please report them to the maintainer, see CHECKPATCH in MAINTAINERS. [BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump WARNING:COMMIT_LOG_LONG_LINE: Prefer a maximum 75 chars per line (possible unwrapped commit description?) #160: btmon-logger uses @len to access the payload in @buf without validating that WARNING:COMMIT_COMMENT_SYMBOL: Commit log lines starting with '#' are dropped by git as comments #173: #define BTSNOOP_MAX_PACKET_SIZE (1486 + 4) /github/workspace/src/patch/14817037.patch total: 0 errors, 2 warnings, 19 lines checked NOTE: For some of the reported defects, checkpatch may be able to mechanically convert to the typical style using --fix or --fix-inplace. /github/workspace/src/patch/14817037.patch has style problems, please review. NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO NOTE: If any of the errors are false positives, please report them to the maintainer, see CHECKPATCH in MAINTAINERS. ############################## Test: GitLint - FAIL Desc: Run gitlint Output: [BlueZ,1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump 12: B3 Line contains hard tab characters (\t): " __le16 opcode;" 13: B3 Line contains hard tab characters (\t): " __le16 index;" 14: B3 Line contains hard tab characters (\t): " __le16 len;" 21: B3 Line contains hard tab characters (\t): " uint16_t channel;" 22: B3 Line contains hard tab characters (\t): " int fd;" 23: B3 Line contains hard tab characters (\t): " unsigned char buf[BTSNOOP_MAX_PACKET_SIZE];" 24: B3 Line contains hard tab characters (\t): " uint16_t offset;" 28: B1 Line exceeds max length (128>80): "ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088" 30: B1 Line exceeds max length (115>80): " #0 0x7f50b987a028 in write ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:1096" 34: B1 Line exceeds max length (85>80): " #4 0x5b4f34451da6 in mainloop_run_with_signal ../src/shared/mainloop-notify.c:196" 36: B1 Line exceeds max length (89>80): " #6 0x7f50b8c2a1c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58" 38: B1 Line exceeds max length (109>80): " #8 0x5b4f34295ed4 in _start (/usr/bin/btmon+0x29fed4) (BuildId: b41caafb24db693946c283eaea48112186863d2d)" [BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump 1: T1 Title exceeds max length (85>80): "[BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump" 12: B3 Line contains hard tab characters (\t): " __le16 opcode;" 13: B3 Line contains hard tab characters (\t): " __le16 index;" 14: B3 Line contains hard tab characters (\t): " __le16 len;" ############################## Test: TestFunctional - FAIL Desc: Run test-functional Output: FAIL functional.test_kernel_testers::test_kernel_selftest[hosts11-vm1-noc]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer" FAIL functional.test_adv_monitor::test_adv_monitor_GHSA_hhgc_hfgf_8m4x[hosts1-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer" FAIL functional.test_btmgmt::test_btmgmt_info[hosts10-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection" FAIL functional.test_bluetoothctl::test_bluetoothctl_show[hosts7-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer" FAIL functional.test_bluetoothctl::test_bluetoothctl_list[hosts7-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection" FAIL functional.test_bluetoothctl::test_bluetoothctl_script_show[hosts7-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer" FAIL functional.test_bluetoothctl::test_bluetoothctl_script_list[hosts7-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection" FAIL functional.test_a2dp::test_a2dp_transport_created[hosts0-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_a2dp::test_a2dp_transport_acquire[hosts0-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_obex::test_obex_ftp_list[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_obex::test_obex_ftp_get[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_obex::test_obexctl_list[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_agent::test_agent_pair_bredr[accept-hosts2-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_agent::test_agent_pair_bredr[reject-hosts2-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_avrcp::test_avrcp_GHSA_m2vx_pw5f_rc8v[hosts3-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bap::test_bap_unicast_transport_created[hosts4-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bap::test_bap_unicast_transport_acquire[hosts4-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bap::test_bap_broadcast_transport_created[lc3-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bap::test_bap_broadcast_transport_created[pbp-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bap::test_bap_broadcast_transport_acquire[lc3-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bap::test_bap_broadcast_transport_acquire[pbp-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bap::test_bass_past_transport_acquire[hosts6-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bluetoothctl::test_bluetoothctl_pair_bredr[hosts8-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" FAIL functional.test_bluetoothctl::test_bluetoothctl_pair_le[hosts9-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly" https://github.com/bluez/bluez/pull/2530 --- Regards, Linux Bluetooth ^ permalink raw reply [flat|nested] 5+ messages in thread
* RE: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump 2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu 2026-09-15 11:25 ` monitor: Fix heap-buffer-overflows " bluez.test.bot @ 2026-09-30 14:09 ` bluez.test.bot 1 sibling, 0 replies; 5+ messages in thread From: bluez.test.bot @ 2026-09-30 14:09 UTC (permalink / raw) To: linux-bluetooth, zijun.hu [-- Attachment #1: Type: text/plain, Size: 703 bytes --] This is an automated email and please do not reply to this email. Dear Submitter, This series was picked up by the CI more than 2 weeks ago and the pull request created for it is still open, which means the series was never applied to the tree. Series: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Pull Request: https://github.com/bluez/bluez/pull/2530 Created: 2026-09-15 10:23:13+00:00 The pull request has been closed and no further action is taken on this series. If the change should still be considered, it must be resent to the Linux Bluetooth mailing list (linux-bluetooth@vger.kernel.org) so that it is picked up again. --- Regards, Linux Bluetooth ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump 2026-09-15 9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu 2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu @ 2026-09-15 9:13 ` Zijun Hu 1 sibling, 0 replies; 5+ messages in thread From: Zijun Hu @ 2026-09-15 9:13 UTC (permalink / raw) To: Marcel Holtmann, Luiz Augusto von Dentz Cc: Linux Bluetooth, linux-kernel, Zijun Hu Kernel HCI devcoredump can accumulate a large amount of dump data from MANY packets, then send it as a SINGLE DIAG packet to the monitor channel, so cause payload length @len in the header exceed BTSNOOP_MAX_PACKET_SIZE, but btmon-logger uses @len to access the payload in @buf without validating that @len fits within @buf, causing a heap-buffer-overflow. Kernel: include/net/bluetooth/hci_mon.h struct hci_mon_hdr { __le16 opcode; __le16 index; __le16 len; } __packed; BlueZ: src/shared/btsnoop.h #define BTSNOOP_MAX_PACKET_SIZE (1486 + 4) tools/btmon-logger.c uint8_t buf[BTSNOOP_MAX_PACKET_SIZE]; Fix by clamping the payload length to the amount of data received before accessing @buf. --- tools/btmon-logger.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/tools/btmon-logger.c b/tools/btmon-logger.c index 261d998a6664..b9a81965a464 100644 --- a/tools/btmon-logger.c +++ b/tools/btmon-logger.c @@ -94,16 +94,19 @@ static void data_callback(int fd, uint32_t events, void *user_data) tv = &ctv; } } opcode = le16_to_cpu(hdr.opcode); index = le16_to_cpu(hdr.index); pktlen = le16_to_cpu(hdr.len); + if (pktlen > (len - sizeof(hdr))) + pktlen = (len - sizeof(hdr)); + btsnoop_write_hci(btsnoop_file, tv, index, opcode, 0, buf, pktlen); } } static bool open_monitor_channel(void) { struct sockaddr_hci addr; -- 2.34.1 ^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-30 14:09 UTC | newest] Thread overview: 5+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-15 9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu 2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu 2026-09-15 11:25 ` monitor: Fix heap-buffer-overflows " bluez.test.bot 2026-09-30 14:09 ` bluez.test.bot 2026-09-15 9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox