* [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
@ 2026-09-15 9:13 Zijun Hu
2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
2026-09-15 9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu
0 siblings, 2 replies; 5+ messages in thread
From: Zijun Hu @ 2026-09-15 9:13 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz
Cc: Linux Bluetooth, linux-kernel, Zijun Hu
This series fixes heap-buffer-overflows in btmon and btmon-logger
triggered by HCI devcoredump.
---
Previous discussion link:
https://lore.kernel.org/all/20260913-misc_fix-v1-2-558c1e4028b9@oss.qualcomm.com
---
Zijun Hu (2):
monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump
monitor/control.c | 3 +++
tools/btmon-logger.c | 3 +++
2 files changed, 6 insertions(+)
---
base-commit: c8e2b951b07fc9b84fa7f3e70dcde2b61aab3ad8
change-id: 20260915-fix_heap_overflow-4e93e9ed9063
Best regards,
--
Zijun Hu <zijun.hu@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
2026-09-15 9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu
@ 2026-09-15 9:13 ` Zijun Hu
2026-09-15 11:25 ` monitor: Fix heap-buffer-overflows " bluez.test.bot
2026-09-30 14:09 ` bluez.test.bot
2026-09-15 9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu
1 sibling, 2 replies; 5+ messages in thread
From: Zijun Hu @ 2026-09-15 9:13 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz
Cc: Linux Bluetooth, linux-kernel, Zijun Hu
Kernel HCI devcoredump can accumulate a large amount of dump data from MANY
packets, then send it as a SINGLE DIAG packet to the monitor channel, so
cause payload length @len in the header exceed BTSNOOP_MAX_PACKET_SIZE, but
btmon uses @len to access the payload in @buf without validating that
@len fits within @buf, causing a heap-buffer-overflow.
Kernel:
include/net/bluetooth/hci_mon.h
struct hci_mon_hdr {
__le16 opcode;
__le16 index;
__le16 len;
} __packed;
BlueZ:
src/shared/btsnoop.h
#define BTSNOOP_MAX_PACKET_SIZE (1486 + 4)
monitor/control.c
struct control_data {
uint16_t channel;
int fd;
unsigned char buf[BTSNOOP_MAX_PACKET_SIZE];
uint16_t offset;
};
The heap-buffer-overflow Issue:
ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088
READ of size 17916 at 0x51b00000065c thread T0
#0 0x7f50b987a028 in write ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:1096
#1 0x5b4f3443ae3a in btsnoop_write ../src/shared/btsnoop.c:289
#2 0x5b4f3429cbf0 in data_callback ../monitor/control.c:969
#3 0x5b4f3444fa9d in mainloop_run ../src/shared/mainloop.c:104
#4 0x5b4f34451da6 in mainloop_run_with_signal ../src/shared/mainloop-notify.c:196
#5 0x5b4f342953fc in main ../monitor/main.c:303
#6 0x7f50b8c2a1c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
#7 0x7f50b8c2a28a in __libc_start_main_impl ../csu/libc-start.c:360
#8 0x5b4f34295ed4 in _start (/usr/bin/btmon+0x29fed4) (BuildId: b41caafb24db693946c283eaea48112186863d2d)
Fix by clamping @len to the amount of data received before accessing
@buf.
---
monitor/control.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/monitor/control.c b/monitor/control.c
index 83347d5dbc3e..1eab9c4fe0bd 100644
--- a/monitor/control.c
+++ b/monitor/control.c
@@ -961,16 +961,19 @@ static void data_callback(int fd, uint32_t events, void *user_data)
pktlen = le16_to_cpu(hdr.len);
switch (data->channel) {
case HCI_CHANNEL_CONTROL:
packet_control(tv, cred, index, opcode,
data->buf, pktlen);
break;
case HCI_CHANNEL_MONITOR:
+ if (pktlen > (len - MGMT_HDR_SIZE))
+ pktlen = (len - MGMT_HDR_SIZE);
+
btsnoop_write_hci(btsnoop_file, tv, index, opcode, 0,
data->buf, pktlen);
ellisys_inject_hci(tv, index, opcode,
data->buf, pktlen);
packet_monitor(tv, cred, index, opcode,
data->buf, pktlen);
break;
}
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump
2026-09-15 9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu
2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
@ 2026-09-15 9:13 ` Zijun Hu
1 sibling, 0 replies; 5+ messages in thread
From: Zijun Hu @ 2026-09-15 9:13 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz
Cc: Linux Bluetooth, linux-kernel, Zijun Hu
Kernel HCI devcoredump can accumulate a large amount of dump data from MANY
packets, then send it as a SINGLE DIAG packet to the monitor channel, so
cause payload length @len in the header exceed BTSNOOP_MAX_PACKET_SIZE, but
btmon-logger uses @len to access the payload in @buf without validating that
@len fits within @buf, causing a heap-buffer-overflow.
Kernel:
include/net/bluetooth/hci_mon.h
struct hci_mon_hdr {
__le16 opcode;
__le16 index;
__le16 len;
} __packed;
BlueZ:
src/shared/btsnoop.h
#define BTSNOOP_MAX_PACKET_SIZE (1486 + 4)
tools/btmon-logger.c
uint8_t buf[BTSNOOP_MAX_PACKET_SIZE];
Fix by clamping the payload length to the amount of data received before
accessing @buf.
---
tools/btmon-logger.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/tools/btmon-logger.c b/tools/btmon-logger.c
index 261d998a6664..b9a81965a464 100644
--- a/tools/btmon-logger.c
+++ b/tools/btmon-logger.c
@@ -94,16 +94,19 @@ static void data_callback(int fd, uint32_t events, void *user_data)
tv = &ctv;
}
}
opcode = le16_to_cpu(hdr.opcode);
index = le16_to_cpu(hdr.index);
pktlen = le16_to_cpu(hdr.len);
+ if (pktlen > (len - sizeof(hdr)))
+ pktlen = (len - sizeof(hdr));
+
btsnoop_write_hci(btsnoop_file, tv, index, opcode, 0, buf,
pktlen);
}
}
static bool open_monitor_channel(void)
{
struct sockaddr_hci addr;
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* RE: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
@ 2026-09-15 11:25 ` bluez.test.bot
2026-09-30 14:09 ` bluez.test.bot
1 sibling, 0 replies; 5+ messages in thread
From: bluez.test.bot @ 2026-09-15 11:25 UTC (permalink / raw)
To: linux-bluetooth, zijun.hu
[-- Attachment #1: Type: text/plain, Size: 8593 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1165307/
---Test result---
Test Summary:
CheckPatch FAIL 0.69 seconds
GitLint FAIL 0.49 seconds
BuildEll PASS 19.19 seconds
BluezMake PASS 373.53 seconds
MakeCheck PASS 0.85 seconds
MakeDistcheck PASS 138.00 seconds
CheckValgrind PASS 144.17 seconds
CheckSmatch PASS 291.46 seconds
bluezmakeextell PASS 92.06 seconds
TestFunctional FAIL 1075.56 seconds
IncrementalBuild PASS 380.35 seconds
ScanBuild PASS 1107.21 seconds
Details
##############################
Test: CheckPatch - FAIL
Desc: Run checkpatch.pl script
Output:
[BlueZ,1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
WARNING:COMMIT_COMMENT_SYMBOL: Commit log lines starting with '#' are dropped by git as comments
#172:
#define BTSNOOP_MAX_PACKET_SIZE (1486 + 4)
WARNING:COMMIT_LOG_LONG_LINE: Prefer a maximum 75 chars per line (possible unwrapped commit description?)
#182:
ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088
/github/workspace/src/patch/14817038.patch total: 0 errors, 2 warnings, 19 lines checked
NOTE: For some of the reported defects, checkpatch may be able to
mechanically convert to the typical style using --fix or --fix-inplace.
/github/workspace/src/patch/14817038.patch has style problems, please review.
NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO
NOTE: If any of the errors are false positives, please report
them to the maintainer, see CHECKPATCH in MAINTAINERS.
[BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump
WARNING:COMMIT_LOG_LONG_LINE: Prefer a maximum 75 chars per line (possible unwrapped commit description?)
#160:
btmon-logger uses @len to access the payload in @buf without validating that
WARNING:COMMIT_COMMENT_SYMBOL: Commit log lines starting with '#' are dropped by git as comments
#173:
#define BTSNOOP_MAX_PACKET_SIZE (1486 + 4)
/github/workspace/src/patch/14817037.patch total: 0 errors, 2 warnings, 19 lines checked
NOTE: For some of the reported defects, checkpatch may be able to
mechanically convert to the typical style using --fix or --fix-inplace.
/github/workspace/src/patch/14817037.patch has style problems, please review.
NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO
NOTE: If any of the errors are false positives, please report
them to the maintainer, see CHECKPATCH in MAINTAINERS.
##############################
Test: GitLint - FAIL
Desc: Run gitlint
Output:
[BlueZ,1/2] monitor: Fix btmon heap-buffer-overflow triggered by HCI devcoredump
12: B3 Line contains hard tab characters (\t): " __le16 opcode;"
13: B3 Line contains hard tab characters (\t): " __le16 index;"
14: B3 Line contains hard tab characters (\t): " __le16 len;"
21: B3 Line contains hard tab characters (\t): " uint16_t channel;"
22: B3 Line contains hard tab characters (\t): " int fd;"
23: B3 Line contains hard tab characters (\t): " unsigned char buf[BTSNOOP_MAX_PACKET_SIZE];"
24: B3 Line contains hard tab characters (\t): " uint16_t offset;"
28: B1 Line exceeds max length (128>80): "ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51b00000065c at pc 0x7f50b987a029 bp 0x7ffde88dc8d0 sp 0x7ffde88dc088"
30: B1 Line exceeds max length (115>80): " #0 0x7f50b987a028 in write ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:1096"
34: B1 Line exceeds max length (85>80): " #4 0x5b4f34451da6 in mainloop_run_with_signal ../src/shared/mainloop-notify.c:196"
36: B1 Line exceeds max length (89>80): " #6 0x7f50b8c2a1c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58"
38: B1 Line exceeds max length (109>80): " #8 0x5b4f34295ed4 in _start (/usr/bin/btmon+0x29fed4) (BuildId: b41caafb24db693946c283eaea48112186863d2d)"
[BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump
1: T1 Title exceeds max length (85>80): "[BlueZ,2/2] tools: Fix btmon-logger heap-buffer-overflow triggered by HCI devcoredump"
12: B3 Line contains hard tab characters (\t): " __le16 opcode;"
13: B3 Line contains hard tab characters (\t): " __le16 index;"
14: B3 Line contains hard tab characters (\t): " __le16 len;"
##############################
Test: TestFunctional - FAIL
Desc: Run test-functional
Output:
FAIL functional.test_kernel_testers::test_kernel_selftest[hosts11-vm1-noc]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_adv_monitor::test_adv_monitor_GHSA_hhgc_hfgf_8m4x[hosts1-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_btmgmt::test_btmgmt_info[hosts10-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection"
FAIL functional.test_bluetoothctl::test_bluetoothctl_show[hosts7-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_bluetoothctl::test_bluetoothctl_list[hosts7-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection"
FAIL functional.test_bluetoothctl::test_bluetoothctl_script_show[hosts7-vm1]: failed on setup with "ConnectionResetError: [Errno 104] Connection reset by peer"
FAIL functional.test_bluetoothctl::test_bluetoothctl_script_list[hosts7-vm1]: failed on setup with "pytest_bluezenv.rpc.RemoteTimeoutError: Failed to establish connection"
FAIL functional.test_a2dp::test_a2dp_transport_created[hosts0-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_a2dp::test_a2dp_transport_acquire[hosts0-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_obex::test_obex_ftp_list[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_obex::test_obex_ftp_get[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_obex::test_obexctl_list[hosts12-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_agent::test_agent_pair_bredr[accept-hosts2-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_agent::test_agent_pair_bredr[reject-hosts2-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_avrcp::test_avrcp_GHSA_m2vx_pw5f_rc8v[hosts3-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_unicast_transport_created[hosts4-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_unicast_transport_acquire[hosts4-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_created[lc3-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_created[pbp-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_acquire[lc3-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bap_broadcast_transport_acquire[pbp-hosts5-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bap::test_bass_past_transport_acquire[hosts6-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bluetoothctl::test_bluetoothctl_pair_bredr[hosts8-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
FAIL functional.test_bluetoothctl::test_bluetoothctl_pair_le[hosts9-vm2]: failed on setup with "RuntimeError: Process exited unexpectedly"
https://github.com/bluez/bluez/pull/2530
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 5+ messages in thread
* RE: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
2026-09-15 11:25 ` monitor: Fix heap-buffer-overflows " bluez.test.bot
@ 2026-09-30 14:09 ` bluez.test.bot
1 sibling, 0 replies; 5+ messages in thread
From: bluez.test.bot @ 2026-09-30 14:09 UTC (permalink / raw)
To: linux-bluetooth, zijun.hu
[-- Attachment #1: Type: text/plain, Size: 703 bytes --]
This is an automated email and please do not reply to this email.
Dear Submitter,
This series was picked up by the CI more than 2 weeks ago and the pull
request created for it is still open, which means the series was never
applied to the tree.
Series: monitor: Fix heap-buffer-overflows triggered by HCI devcoredump
Pull Request: https://github.com/bluez/bluez/pull/2530
Created: 2026-09-15 10:23:13+00:00
The pull request has been closed and no further action is taken on this
series.
If the change should still be considered, it must be resent to the Linux
Bluetooth mailing list (linux-bluetooth@vger.kernel.org) so that it is
picked up again.
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-30 14:09 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-15 9:13 [PATCH BlueZ 0/2] monitor: Fix heap-buffer-overflows triggered by HCI devcoredump Zijun Hu
2026-09-15 9:13 ` [PATCH BlueZ 1/2] monitor: Fix btmon heap-buffer-overflow " Zijun Hu
2026-09-15 11:25 ` monitor: Fix heap-buffer-overflows " bluez.test.bot
2026-09-30 14:09 ` bluez.test.bot
2026-09-15 9:13 ` [PATCH BlueZ 2/2] tools: Fix btmon-logger heap-buffer-overflow " Zijun Hu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox