From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 03E0651D513; Wed, 30 Sep 2026 17:33:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789617; cv=none; b=UdRLw3+I0UtDgUdtiKHrpofuHIz8lvR7NGrRKjJkiNo0CQLOqtnOupLa2aAcOp153v5ibtmvP232UurSMiWXOZQk8nELvEHtNGopR9XV+boOSXrlgnFKhNF7bqhEwXMQkBRl7QV9ZfyfrYxOM5xL3lZrry2Ow4mYXcZl8ZY+7ME= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789617; c=relaxed/simple; bh=3KBEuIVPIKQdI7gTF8S3DGuwUHLR2cC76qHMJ0YVQwI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MPj03m4ySXFE//pcUUsNLqkrrbAg4ZHF8fpLnyUH1cn+Q+zn2wlXHRfbxTA6m8mPb8bhk+UpDXKnezraattAgLDgAhS7WpegmTYxlNOL7SF5MESIR06EkpCrknQliJ4zpV2FrkFrNWcQSoaRCeQbLgNJrfWc1f1ARtIgJbbJ6pA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=wcxEW2rc; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="wcxEW2rc" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 523521F000FF; Wed, 30 Sep 2026 17:33:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789615; bh=DMfduXnLgegNbTzwEWv0rIAx1Ag++lVxNkMomRZojyU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=wcxEW2rcBBDWx+UuC9QaVfg2R4ntwUAmL5c5mpYZxQrh/PxUNSwv3sLxTjK3yGOA1 V/mumO3kMFeiJMWyLLrSNHMjtCDK6C2gkY4i4YInV2kK2f3DWMJM5rz+bYKQVJbavs X8xfI1LXaZbW8W8bFVDvOREIXZcsn+gxhhYYup2Y= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Aldo Ariel Panzardo , Luiz Augusto von Dentz Subject: [PATCH 6.12 538/877] Bluetooth: hci_sock: validate event length before filtering Date: Wed, 30 Sep 2026 17:24:09 +0200 Message-ID: <20260930152426.253121970@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Aldo Ariel Panzardo commit b0a6cf99afd57a39598b1beca0e86ef5004980de upstream. is_filtered_packet() reads the event code from skb->data[0] without first checking that the skb is nonempty. When an opcode filter is configured, it also reads the command opcode at offsets 3 or 4 without checking that a Command Complete or Command Status event is long enough. hci_send_to_sock() invokes the filter before hci_event_packet() validates the event header. A malformed event supplied by a controller or a vhci device can therefore cause an out-of-bounds read. Keep the unmasked event code for the opcode checks. The masked value is needed for the 64-bit event bitmap, but using it to identify command events aliases event codes above 0x3f. In particular, Synchronous Train Complete (0x4f) was treated as Command Status (0x0f) even though its payload has no opcode. Reject actual command events that are too short for the field being inspected. A truncated command event cannot match a configured opcode. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Signed-off-by: Aldo Ariel Panzardo Signed-off-by: Luiz Augusto von Dentz Signed-off-by: Greg Kroah-Hartman --- net/bluetooth/hci_sock.c | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) --- a/net/bluetooth/hci_sock.c +++ b/net/bluetooth/hci_sock.c @@ -166,6 +166,7 @@ static bool is_filtered_packet(struct so { struct hci_filter *flt; int flt_type, flt_event; + u8 event; /* Apply filter */ flt = &hci_pi(sk)->filter; @@ -179,7 +180,11 @@ static bool is_filtered_packet(struct so if (hci_skb_pkt_type(skb) != HCI_EVENT_PKT) return false; - flt_event = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS); + if (skb->len < 1) + return true; + + event = *(__u8 *)skb->data; + flt_event = event & HCI_FLT_EVENT_BITS; if (!hci_test_bit(flt_event, &flt->event_mask)) return true; @@ -188,11 +193,17 @@ static bool is_filtered_packet(struct so if (!flt->opcode) return false; - if (flt_event == HCI_EV_CMD_COMPLETE && + if (event == HCI_EV_CMD_COMPLETE && skb->len < 5) + return true; + + if (event == HCI_EV_CMD_COMPLETE && flt->opcode != get_unaligned((__le16 *)(skb->data + 3))) return true; - if (flt_event == HCI_EV_CMD_STATUS && + if (event == HCI_EV_CMD_STATUS && skb->len < 6) + return true; + + if (event == HCI_EV_CMD_STATUS && flt->opcode != get_unaligned((__le16 *)(skb->data + 4))) return true;