* [PATCH v2 0/3] Bluetooth: btintel: harden version TLV parsing
@ 2026-08-14 17:15 Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 1/3] Bluetooth: btintel: validate version TLV value lengths Laxman Acharya Padhya
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Laxman Acharya Padhya @ 2026-08-14 17:15 UTC (permalink / raw)
To: linux-bluetooth
Cc: marcel, luiz.dentz, linux-kernel, ali, raghuram.hegde, kiraank,
kiran.k, ravishankar.srivatsa, amit.k.bag
Malformed Intel version TLVs can make btintel_parse_version_tlv() read
beyond the received response. Validate the minimum value length for each
known fixed-size TLV and bound the firmware ID conversion by the TLV's
advertised length. Propagate parser failures to the setup path in a
separate patch.
The two bounds fixes are kept separate because they were introduced by
different commits and apply to different stable trees. The parser error
propagation is also separate because it changes setup behavior.
Changes in v2:
- split the minimum-length validation and firmware ID bounds fix
- use the appropriate Fixes tag for each bounds fix
- keep parser error propagation as a separate behavioral change
- add Ali's Reviewed-by tag to the two bounds fixes
Laxman Acharya Padhya (3):
Bluetooth: btintel: validate version TLV value lengths
Bluetooth: btintel: bound firmware ID by TLV length
Bluetooth: btintel: propagate version TLV parsing errors
drivers/bluetooth/btintel.c | 44 +++++++++++++++++++++++++++++++++----
1 file changed, 40 insertions(+), 4 deletions(-)
--
2.51.2
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v2 1/3] Bluetooth: btintel: validate version TLV value lengths
2026-08-14 17:15 [PATCH v2 0/3] Bluetooth: btintel: harden version TLV parsing Laxman Acharya Padhya
@ 2026-08-14 17:15 ` Laxman Acharya Padhya
2026-08-14 18:29 ` Bluetooth: btintel: harden version TLV parsing bluez.test.bot
2026-08-14 17:15 ` [PATCH v2 2/3] Bluetooth: btintel: bound firmware ID by TLV length Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 3/3] Bluetooth: btintel: propagate version TLV parsing errors Laxman Acharya Padhya
2 siblings, 1 reply; 6+ messages in thread
From: Laxman Acharya Padhya @ 2026-08-14 17:15 UTC (permalink / raw)
To: linux-bluetooth
Cc: marcel, luiz.dentz, linux-kernel, ali, raghuram.hegde, kiraank,
kiran.k, ravishankar.srivatsa, amit.k.bag
btintel_parse_version_tlv() verifies that a complete TLV is present in
the response, but it does not ensure that the value is long enough for
the specific TLV type. A short value can therefore cause an
out-of-bounds read through get_unaligned_le16(), get_unaligned_le32(),
or memcpy().
Reject values shorter than the minimum required by each known TLV type.
Also reject responses that do not contain the Command Complete Status
field.
Fixes: 57375beef71a ("Bluetooth: btintel: Add infrastructure to read controller information")
Reviewed-by: Ali Ahmet Memis <ali@iusegentoo.com>
Assisted-by: Codex:gpt-5 sparse
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
---
drivers/bluetooth/btintel.c | 37 ++++++++++++++++++++++++++++++++++++-
1 file changed, 36 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btintel.c b/drivers/bluetooth/btintel.c
index bf567b7c5f00..26435e41f1ce 100644
--- a/drivers/bluetooth/btintel.c
+++ b/drivers/bluetooth/btintel.c
@@ -570,12 +570,44 @@ int btintel_version_info_tlv(struct hci_dev *hdev,
}
EXPORT_SYMBOL_GPL(btintel_version_info_tlv);
+static u8 btintel_version_tlv_min_len(u8 type)
+{
+ switch (type) {
+ case INTEL_TLV_CNVI_TOP:
+ case INTEL_TLV_CNVR_TOP:
+ case INTEL_TLV_CNVI_BT:
+ case INTEL_TLV_CNVR_BT:
+ case INTEL_TLV_BUILD_NUM:
+ case INTEL_TLV_GIT_SHA1:
+ return sizeof(u32);
+ case INTEL_TLV_DEV_REV_ID:
+ case INTEL_TLV_TIME_STAMP:
+ return sizeof(u16);
+ case INTEL_TLV_IMAGE_TYPE:
+ case INTEL_TLV_BUILD_TYPE:
+ case INTEL_TLV_SECURE_BOOT:
+ case INTEL_TLV_OTP_LOCK:
+ case INTEL_TLV_API_LOCK:
+ case INTEL_TLV_DEBUG_LOCK:
+ case INTEL_TLV_LIMITED_CCE:
+ case INTEL_TLV_SBE_TYPE:
+ return sizeof(u8);
+ case INTEL_TLV_MIN_FW:
+ return 3;
+ case INTEL_TLV_OTP_BDADDR:
+ return sizeof(bdaddr_t);
+ default:
+ return 0;
+ }
+}
+
int btintel_parse_version_tlv(struct hci_dev *hdev,
struct intel_version_tlv *version,
struct sk_buff *skb)
{
/* Consume Command Complete Status field */
- skb_pull(skb, 1);
+ if (!skb_pull(skb, 1))
+ return -EINVAL;
/* Event parameters contain multiple TLVs. Read each of them
* and only keep the required data. Also, it use existing legacy
@@ -595,6 +627,9 @@ int btintel_parse_version_tlv(struct hci_dev *hdev,
if (skb->len < tlv->len + sizeof(*tlv))
return -EINVAL;
+ if (tlv->len < btintel_version_tlv_min_len(tlv->type))
+ return -EINVAL;
+
switch (tlv->type) {
case INTEL_TLV_CNVI_TOP:
version->cnvi_top = get_unaligned_le32(tlv->val);
--
2.51.2
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v2 2/3] Bluetooth: btintel: bound firmware ID by TLV length
2026-08-14 17:15 [PATCH v2 0/3] Bluetooth: btintel: harden version TLV parsing Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 1/3] Bluetooth: btintel: validate version TLV value lengths Laxman Acharya Padhya
@ 2026-08-14 17:15 ` Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 3/3] Bluetooth: btintel: propagate version TLV parsing errors Laxman Acharya Padhya
2 siblings, 0 replies; 6+ messages in thread
From: Laxman Acharya Padhya @ 2026-08-14 17:15 UTC (permalink / raw)
To: linux-bluetooth
Cc: marcel, luiz.dentz, linux-kernel, ali, raghuram.hegde, kiraank,
kiran.k, ravishankar.srivatsa, amit.k.bag
The firmware ID is treated as a NUL-terminated string even though the
TLV length is its only boundary. If the value does not contain a NUL
terminator, snprintf() can read beyond the received response.
Limit the conversion to the advertised TLV value length.
Fixes: 164c62f958f8 ("Bluetooth: btintel: Add firmware ID to firmware name")
Reviewed-by: Ali Ahmet Memis <ali@iusegentoo.com>
Assisted-by: Codex:gpt-5 sparse
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
---
drivers/bluetooth/btintel.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btintel.c b/drivers/bluetooth/btintel.c
index 26435e41f1ce..c204e9a1cd0f 100644
--- a/drivers/bluetooth/btintel.c
+++ b/drivers/bluetooth/btintel.c
@@ -701,7 +701,7 @@ int btintel_parse_version_tlv(struct hci_dev *hdev,
break;
case INTEL_TLV_FW_ID:
snprintf(version->fw_id, sizeof(version->fw_id),
- "%s", tlv->val);
+ "%.*s", tlv->len, tlv->val);
break;
default:
/* Ignore rest of information */
--
2.51.2
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v2 3/3] Bluetooth: btintel: propagate version TLV parsing errors
2026-08-14 17:15 [PATCH v2 0/3] Bluetooth: btintel: harden version TLV parsing Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 1/3] Bluetooth: btintel: validate version TLV value lengths Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 2/3] Bluetooth: btintel: bound firmware ID by TLV length Laxman Acharya Padhya
@ 2026-08-14 17:15 ` Laxman Acharya Padhya
2026-08-14 18:46 ` Ali Ahmet Memis
2 siblings, 1 reply; 6+ messages in thread
From: Laxman Acharya Padhya @ 2026-08-14 17:15 UTC (permalink / raw)
To: linux-bluetooth
Cc: marcel, luiz.dentz, linux-kernel, ali, raghuram.hegde, kiraank,
kiran.k, ravishankar.srivatsa, amit.k.bag
btintel_read_version_tlv() ignores the parser return value, so setup
continues with partially initialized version data after a malformed TLV
causes parsing to stop.
Return the parser error to the caller so an invalid response fails setup
instead of being treated as successful. Keep this behavioral change
separate from the bounds checks so it can be reverted independently if
an existing controller sends malformed data.
Assisted-by: Codex:gpt-5 sparse
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
---
drivers/bluetooth/btintel.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/bluetooth/btintel.c b/drivers/bluetooth/btintel.c
index c204e9a1cd0f..934775e449db 100644
--- a/drivers/bluetooth/btintel.c
+++ b/drivers/bluetooth/btintel.c
@@ -720,6 +720,7 @@ static int btintel_read_version_tlv(struct hci_dev *hdev,
{
struct sk_buff *skb;
const u8 param[1] = { 0xFF };
+ int err;
if (!version)
return -EINVAL;
@@ -738,10 +739,10 @@ static int btintel_read_version_tlv(struct hci_dev *hdev,
return -EIO;
}
- btintel_parse_version_tlv(hdev, version, skb);
+ err = btintel_parse_version_tlv(hdev, version, skb);
kfree_skb(skb);
- return 0;
+ return err;
}
/* ------- REGMAP IBT SUPPORT ------- */
--
2.51.2
^ permalink raw reply related [flat|nested] 6+ messages in thread
* RE: Bluetooth: btintel: harden version TLV parsing
2026-08-14 17:15 ` [PATCH v2 1/3] Bluetooth: btintel: validate version TLV value lengths Laxman Acharya Padhya
@ 2026-08-14 18:29 ` bluez.test.bot
0 siblings, 0 replies; 6+ messages in thread
From: bluez.test.bot @ 2026-08-14 18:29 UTC (permalink / raw)
To: linux-bluetooth, acharyalaxman8848
[-- Attachment #1: Type: text/plain, Size: 1181 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/project/bluetooth/list/?series=1146215
---Test result---
Test Summary:
CheckPatch PASS 1.77 seconds
VerifyFixes PASS 0.07 seconds
VerifySignedoff PASS 0.07 seconds
GitLint PASS 0.60 seconds
SubjectPrefix PASS 0.18 seconds
BuildKernel PASS 27.89 seconds
CheckAllWarning PASS 31.18 seconds
CheckSparse PASS 29.20 seconds
BuildKernel32 PASS 26.92 seconds
CheckKernelLLVM SKIP 0.00 seconds
TestRunnerSetup PASS 510.91 seconds
IncrementalBuild PASS 30.52 seconds
Details
##############################
Test: CheckKernelLLVM - SKIP
Desc: Build kernel with LLVM + context analysis
Output:
Clang not found
https://github.com/bluez/bluetooth-next/pull/583
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2 3/3] Bluetooth: btintel: propagate version TLV parsing errors
2026-08-14 17:15 ` [PATCH v2 3/3] Bluetooth: btintel: propagate version TLV parsing errors Laxman Acharya Padhya
@ 2026-08-14 18:46 ` Ali Ahmet Memis
0 siblings, 0 replies; 6+ messages in thread
From: Ali Ahmet Memis @ 2026-08-14 18:46 UTC (permalink / raw)
To: Laxman Acharya Padhya
Cc: linux-bluetooth, marcel, luiz.dentz, linux-kernel, raghuram.hegde,
kiraank, kiran.k, ravishankar.srivatsa, amit.k.bag
This looks good to me. Propagating the parser error here keeps the
version TLV handling consistent with the other setup path and avoids
continuing with partially initialized version data.
Reviewed-by: Ali Ahmet Memis <ali@iusegentoo.com>
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-08-14 18:47 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-14 17:15 [PATCH v2 0/3] Bluetooth: btintel: harden version TLV parsing Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 1/3] Bluetooth: btintel: validate version TLV value lengths Laxman Acharya Padhya
2026-08-14 18:29 ` Bluetooth: btintel: harden version TLV parsing bluez.test.bot
2026-08-14 17:15 ` [PATCH v2 2/3] Bluetooth: btintel: bound firmware ID by TLV length Laxman Acharya Padhya
2026-08-14 17:15 ` [PATCH v2 3/3] Bluetooth: btintel: propagate version TLV parsing errors Laxman Acharya Padhya
2026-08-14 18:46 ` Ali Ahmet Memis
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).