Linux bluetooth development
 help / color / mirror / Atom feed
* [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
@ 2026-09-15  9:13 Zijun Hu
  2026-09-15  9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
  2026-09-15  9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu
  0 siblings, 2 replies; 5+ messages in thread
From: Zijun Hu @ 2026-09-15  9:13 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz
  Cc: Linux Bluetooth, linux-kernel, Zijun Hu

This series fixes heap-buffer-overflows in btmon and btmon-logger
triggered by HCI devcoredump.

---
Previous discussion link:
https://lore.kernel.org/all/20260913-misc_fix-v1-2-558c1e4028b9@oss.qualcomm.com

---
Zijun Hu (2):
      monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
      tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump

 monitor/control.c    | 3 +++
 tools/btmon-logger.c | 3 +++
 2 files changed, 6 insertions(+)
---
base-commit: c8e2b951b07fc9b84fa7f3e70dcde2b61aab3ad8
change-id: 20260915-fix_heap_overflow-4e93e9ed9063

Best regards,
--  
Zijun Hu <zijun.hu@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
  2026-09-15  9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu
@ 2026-09-15  9:13 ` Zijun Hu
  2026-09-15 11:25   ` monitor: Fix heap-buffer-overflows " bluez.test.bot
  2026-09-30 14:09   ` bluez.test.bot
  2026-09-15  9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu
  1 sibling, 2 replies; 5+ messages in thread
From: Zijun Hu @ 2026-09-15  9:13 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz
  Cc: Linux Bluetooth, linux-kernel, Zijun Hu

Kernel HCI devcoredump can accumulate a large amount of dump data from MANY
packets, then send it as a SINGLE DIAG packet to the monitor channel, so
cause payload length @len in the header exceed BTSNOOP_MAX_PACKET_SIZE, but
btmon uses @len to access the payload in @buf without validating that
@len fits within @buf, causing a heap-buffer-overflow.

Kernel:
include/net/bluetooth/hci_mon.h
struct hci_mon_hdr {
	__le16  opcode;
	__le16  index;
	__le16  len;
} __packed;

BlueZ:
src/shared/btsnoop.h
#define BTSNOOP_MAX_PACKET_SIZE            (1486 + 4)
monitor/control.c
struct control_data {
	uint16_t channel;
	int fd;
	unsigned char buf[BTSNOOP_MAX_PACKET_SIZE];
	uint16_t offset;
};

The heap-buffer-overflow Issue:
ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088
READ of size 17916 at 0x51b00000065c thread T0
    #0 0x7f50b987a028 in write ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:1096
    #1 0x5b4f3443ae3a in btsnoop_write ../src/shared/btsnoop.c:289
    #2 0x5b4f3429cbf0 in data_callback ../monitor/control.c:969
    #3 0x5b4f3444fa9d in mainloop_run ../src/shared/mainloop.c:104
    #4 0x5b4f34451da6 in mainloop_run_with_signal ../src/shared/mainloop-notify.c:196
    #5 0x5b4f342953fc in main ../monitor/main.c:303
    #6 0x7f50b8c2a1c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
    #7 0x7f50b8c2a28a in __libc_start_main_impl ../csu/libc-start.c:360
    #8 0x5b4f34295ed4 in _start (/usr/bin/btmon+0x29fed4) (BuildId: b41caafb24db693946c283eaea48112186863d2d)

Fix by clamping @len to the amount of data received before accessing
@buf.
---
 monitor/control.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/monitor/control.c b/monitor/control.c
index 83347d5dbc3e..1eab9c4fe0bd 100644
--- a/monitor/control.c
+++ b/monitor/control.c
@@ -961,16 +961,19 @@ static void data_callback(int fd, uint32_t events, void *user_data)
 		pktlen = le16_to_cpu(hdr.len);
 
 		switch (data->channel) {
 		case HCI_CHANNEL_CONTROL:
 			packet_control(tv, cred, index, opcode,
 							data->buf, pktlen);
 			break;
 		case HCI_CHANNEL_MONITOR:
+			if (pktlen > (len - MGMT_HDR_SIZE))
+				pktlen = (len - MGMT_HDR_SIZE);
+
 			btsnoop_write_hci(btsnoop_file, tv, index, opcode, 0,
 							data->buf, pktlen);
 			ellisys_inject_hci(tv, index, opcode,
 							data->buf, pktlen);
 			packet_monitor(tv, cred, index, opcode,
 							data->buf, pktlen);
 			break;
 		}

-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump
  2026-09-15  9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu
  2026-09-15  9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
@ 2026-09-15  9:13 ` Zijun Hu
  1 sibling, 0 replies; 5+ messages in thread
From: Zijun Hu @ 2026-09-15  9:13 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz
  Cc: Linux Bluetooth, linux-kernel, Zijun Hu

Kernel HCI devcoredump can accumulate a large amount of dump data from MANY
packets, then send it as a SINGLE DIAG packet to the monitor channel, so
cause payload length @len in the header exceed BTSNOOP_MAX_PACKET_SIZE, but
btmon-logger uses @len to access the payload in @buf without validating that
@len fits within @buf, causing a heap-buffer-overflow.

Kernel:
include/net/bluetooth/hci_mon.h
struct hci_mon_hdr {
	__le16  opcode;
	__le16  index;
	__le16  len;
} __packed;

BlueZ:
src/shared/btsnoop.h
#define BTSNOOP_MAX_PACKET_SIZE            (1486 + 4)
tools/btmon-logger.c
uint8_t buf[BTSNOOP_MAX_PACKET_SIZE];

Fix by clamping the payload length to the amount of data received before
accessing @buf.
---
 tools/btmon-logger.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/tools/btmon-logger.c b/tools/btmon-logger.c
index 261d998a6664..b9a81965a464 100644
--- a/tools/btmon-logger.c
+++ b/tools/btmon-logger.c
@@ -94,16 +94,19 @@ static void data_callback(int fd, uint32_t events, void *user_data)
 				tv = &ctv;
 			}
 		}
 
 		opcode = le16_to_cpu(hdr.opcode);
 		index  = le16_to_cpu(hdr.index);
 		pktlen = le16_to_cpu(hdr.len);
 
+		if (pktlen > (len - sizeof(hdr)))
+			pktlen = (len - sizeof(hdr));
+
 		btsnoop_write_hci(btsnoop_file, tv, index, opcode, 0, buf,
 									pktlen);
 	}
 }
 
 static bool open_monitor_channel(void)
 {
 	struct sockaddr_hci addr;

-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* RE: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
  2026-09-15  9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
@ 2026-09-15 11:25   ` bluez.test.bot
  2026-09-30 14:09   ` bluez.test.bot
  1 sibling, 0 replies; 5+ messages in thread
From: bluez.test.bot @ 2026-09-15 11:25 UTC (permalink / raw)
  To: linux-bluetooth, zijun.hu

[-- Attachment #1: Type: text/plain, Size: 8593 bytes --]

This is automated email and please do not reply to this email!

Dear submitter,

Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1165307/

---Test result---

Test Summary:
CheckPatch                    FAIL      0.69 seconds
GitLint                       FAIL      0.49 seconds
BuildEll                      PASS      19.19 seconds
BluezMake                     PASS      373.53 seconds
MakeCheck                     PASS      0.85 seconds
MakeDistcheck                 PASS      138.00 seconds
CheckValgrind                 PASS      144.17 seconds
CheckSmatch                   PASS      291.46 seconds
bluezmakeextell               PASS      92.06 seconds
TestFunctional                FAIL      1075.56 seconds
IncrementalBuild              PASS      380.35 seconds
ScanBuild                     PASS      1107.21 seconds

Details
##############################
Test: CheckPatch - FAIL
Desc: Run checkpatch.pl script
Output:
[BlueZ,1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
WARNING:COMMIT_COMMENT_SYMBOL: Commit log lines starting with '#' are dropped by git as comments
#172: 
#define BTSNOOP_MAX_PACKET_SIZE            (1486 + 4)

WARNING:COMMIT_LOG_LONG_LINE: Prefer a maximum 75 chars per line (possible unwrapped commit description?)
#182: 
ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088

/github/workspace/src/patch/14817038.patch total: 0 errors, 2 warnings, 19 lines checked

NOTE: For some of the reported defects, checkpatch may be able to
      mechanically convert to the typical style using --fix or --fix-inplace.

/github/workspace/src/patch/14817038.patch has style problems, please review.

NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO

NOTE: If any of the errors are false positives, please report
      them to the maintainer, see CHECKPATCH in MAINTAINERS.


[BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump
WARNING:COMMIT_LOG_LONG_LINE: Prefer a maximum 75 chars per line (possible unwrapped commit description?)
#160: 
btmon-logger uses @len to access the payload in @buf without validating that

WARNING:COMMIT_COMMENT_SYMBOL: Commit log lines starting with '#' are dropped by git as comments
#173: 
#define BTSNOOP_MAX_PACKET_SIZE            (1486 + 4)

/github/workspace/src/patch/14817037.patch total: 0 errors, 2 warnings, 19 lines checked

NOTE: For some of the reported defects, checkpatch may be able to
      mechanically convert to the typical style using --fix or --fix-inplace.

/github/workspace/src/patch/14817037.patch has style problems, please review.

NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO

NOTE: If any of the errors are false positives, please report
      them to the maintainer, see CHECKPATCH in MAINTAINERS.


##############################
Test: GitLint - FAIL
Desc: Run gitlint
Output:
[BlueZ,1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump

12: B3 Line contains hard tab characters (\t): "	__le16  opcode;"
13: B3 Line contains hard tab characters (\t): "	__le16  index;"
14: B3 Line contains hard tab characters (\t): "	__le16  len;"
21: B3 Line contains hard tab characters (\t): "	uint16_t channel;"
22: B3 Line contains hard tab characters (\t): "	int fd;"
23: B3 Line contains hard tab characters (\t): "	unsigned char buf[BTSNOOP_MAX_PACKET_SIZE];"
24: B3 Line contains hard tab characters (\t): "	uint16_t offset;"
28: B1 Line exceeds max length (128>80): "ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088"
30: B1 Line exceeds max length (115>80): "    #0 0x7f50b987a028 in write ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:1096"
34: B1 Line exceeds max length (85>80): "    #4 0x5b4f34451da6 in mainloop_run_with_signal ../src/shared/mainloop-notify.c:196"
36: B1 Line exceeds max length (89>80): "    #6 0x7f50b8c2a1c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58"
38: B1 Line exceeds max length (109>80): "    #8 0x5b4f34295ed4 in _start (/usr/bin/btmon+0x29fed4) (BuildId: b41caafb24db693946c283eaea48112186863d2d)"
[BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump

1: T1 Title exceeds max length (85>80): "[BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump"
12: B3 Line contains hard tab characters (\t): "	__le16  opcode;"
13: B3 Line contains hard tab characters (\t): "	__le16  index;"
14: B3 Line contains hard tab characters (\t): "	__le16  len;"
##############################
Test: TestFunctional - FAIL
Desc: Run test-functional
Output:
FAIL functional.test_kernel_testers::test_kernel_selftest[hosts11-vm1-noc]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_adv_monitor::test_adv_monitor_GHSA_hhgc_hfgf_8m4x[hosts1-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_btmgmt::test_btmgmt_info[hosts10-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection"
FAIL functional.test_bluetoothctl::test_bluetoothctl_show[hosts7-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_bluetoothctl::test_bluetoothctl_list[hosts7-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection"
FAIL functional.test_bluetoothctl::test_bluetoothctl_script_show[hosts7-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_bluetoothctl::test_bluetoothctl_script_list[hosts7-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection"
FAIL functional.test_a2dp::test_a2dp_transport_created[hosts0-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_a2dp::test_a2dp_transport_acquire[hosts0-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_obex::test_obex_ftp_list[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_obex::test_obex_ftp_get[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_obex::test_obexctl_list[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_agent::test_agent_pair_bredr[accept-hosts2-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_agent::test_agent_pair_bredr[reject-hosts2-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_avrcp::test_avrcp_GHSA_m2vx_pw5f_rc8v[hosts3-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_unicast_transport_created[hosts4-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_unicast_transport_acquire[hosts4-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_created[lc3-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_created[pbp-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_acquire[lc3-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_acquire[pbp-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bass_past_transport_acquire[hosts6-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bluetoothctl::test_bluetoothctl_pair_bredr[hosts8-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bluetoothctl::test_bluetoothctl_pair_le[hosts9-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"


https://github.com/bluez/bluez/pull/2530

---
Regards,
Linux Bluetooth


^ permalink raw reply	[flat|nested] 5+ messages in thread

* RE: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
  2026-09-15  9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
  2026-09-15 11:25   ` monitor: Fix heap-buffer-overflows " bluez.test.bot
@ 2026-09-30 14:09   ` bluez.test.bot
  1 sibling, 0 replies; 5+ messages in thread
From: bluez.test.bot @ 2026-09-30 14:09 UTC (permalink / raw)
  To: linux-bluetooth, zijun.hu

[-- Attachment #1: Type: text/plain, Size: 703 bytes --]

This is an automated email and please do not reply to this email.

Dear Submitter,

This series was picked up by the CI more than 2 weeks ago and the pull
request created for it is still open, which means the series was never
applied to the tree.

   Series:       monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
   Pull Request: https://github.com/bluez/bluez/pull/2530
   Created:      2026-09-15 10:23:13+00:00

The pull request has been closed and no further action is taken on this
series.

If the change should still be considered, it must be resent to the Linux
Bluetooth mailing list (linux-bluetooth@vger.kernel.org) so that it is
picked up again.

---
Regards,
Linux Bluetooth

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-30 14:09 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-15  9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu
2026-09-15  9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
2026-09-15 11:25   ` monitor: Fix heap-buffer-overflows " bluez.test.bot
2026-09-30 14:09   ` bluez.test.bot
2026-09-15  9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox