From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f49.google.com (mail-yx1-f49.google.com [74.125.224.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F02453C98B5 for ; Thu, 30 Jul 2026 08:32:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785400350; cv=none; b=W5GTz9wcUTNQg7LpeobKT/fl9QxpqanFvamIT5ZajWNgwkw2xK2oGVd9ai7lTEtLZb0dP/B7jpYrA49VTL9TFjdksR9OAYK6lksdZRn0EV42PIbxcTu4iFCMkJzF3jlgrcJ/uXmulScMBcsLAOLmClfW/EDrpoMcApS2SYluX84= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785400350; c=relaxed/simple; bh=IcOFbQECrGsg+BWMAa4idv9EVssko8UWfTMGlMoCtaY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IGVZweCGmfKo6S0segjbDy8DKOf9UWujBbHNaqeRJFOYDRnAGT94Ag1wB7pyeMj0eBqMrpP8NxOd8UYyD3DJbJGNMlCZUV2wwvFXkyGKPu+QFfsudIls0joe1uPeSpsg+K1AH3itlbj3Y/+DohUwUSGGjN4uzaVHvj+Cp2UAR5A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nslRQb40; arc=none smtp.client-ip=74.125.224.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nslRQb40" Received: by mail-yx1-f49.google.com with SMTP id 956f58d0204a3-664b1bab782so243008d50.1 for ; Thu, 30 Jul 2026 01:32:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785400347; x=1786005147; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Vgievnc30p13gh89t//6TkQGWNlUGXGtKcqogQzVYjU=; b=nslRQb40UlimLZ9ohhz7Qsj8lutt4mAyvPSEFUlFDuGGJJ1CKKkwABKRy02WsTX6Wg SXIxaT+iqSvTSJ2glCOyxqzgtPB1atXk8W36xeIzIeP7ZWMfdhc0LECLrmwDO1JBdqQH xVuoy0So6HczWzJQHnsfhpIWe4geG7sX3tvInBJpvt2rDiuGWahY8xE6NG+9v3PriWdm 9lukEgr+og3ULBz53XD4pUT8MTuF6aiEEdZe+cPCzeiH7vDUgGe79rW7ZvGke5/+NwKG wSvJntC7wIOLf6/XgwYNz8gtPTtkRexhepa2EHs+O/jdyRFokQn6wt5cov+vvigMANzL Uebw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785400347; x=1786005147; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Vgievnc30p13gh89t//6TkQGWNlUGXGtKcqogQzVYjU=; b=DH42dJVsLLmmORA9nJhx8jH56v0kyYhVIdcvZkISoQf62wWxJPhB/QcU6ipOQ4ii/5 ahpmzUUzUYWmNgGFnU/1zqThoO0/Uh/Kv0fiuvZu4spFYB7B5/B+dImqRnWLeqRItxaQ 3cTPxX8SJv/syWkXfITeLsv7nIq9F4pTSBLmjQBAPxxImdZow1We9cZ+9qPPaMDJhtzZ m07tAQpgxXSgZOL5SpWBBaKV5KmrWnPM8o0DVLRnaGE8+AU0iPZrg/sWv2eoXhNN9C/e 2UuwvdAeGlpanMsN0Tz8QovzoFH7Ye5Qtw2KWWwT11R7LwIbdYej9PVYtpLzbWkzZZNH Njhw== X-Forwarded-Encrypted: i=1; AHgh+Ro3hn9+Bv3nTX2Ob6y4zY+0/uUUT+CL7SQd4VryFLqkCaZB2G4FotRXqp0yMVMMB98q4SaSuFrmBfU14nc=@vger.kernel.org X-Gm-Message-State: AOJu0Yy/YP7aXiE/4RLi8751hZjTfmfwjgru+W6D0+13w/3j6EJIlfu1 r15TmMGUyZockbqPy1RIwR3AI2aJIFxyZAV5RK0SzmJNko81d/W4wEKc X-Gm-Gg: AR+sD13A+LYWiABALJ+hM6IDo5c611CUsXY+kVk+5czMSyVJEl8pbhk2Qf0BO/JH7Zy RsrT1P1YFddqSuQ06CTs1SZc6GcVYN4fSrzuibkuJvCRyC0uyvjNKLKZPGVy1DKgqv3C5FbAVZJ ofKCcWx3GfG6eBep3ELBFGeQ1U9wjTD0fO+fK51VqJp9XGN9SQ3tEtccpsbqvpuclCKR2iRIje0 9S+z3JS21kCxqBvZV9hDheTK7L4hvtbIgpWlaghrJt6gMFLxBhHh4QysP1cKcK/dZkQSPLZ5Hgv xWw2ZFK7ldyQW/08mtRHvC+xLSoCmi+yQ/Ugf9Wk17oe9MeBg4iHyEVS36g83R/FU9pm8773fk+ GPMEqMFr3UUyn2+OusJ+fIm/jjJjh6vlxKqRTOGGJtzUwa+oKp+7czhMy0CfQKP8pTico4GKNUG /o/RI045mNpwqdDaIkJTySPWgHB2idCDOIhQ5+1tACa51cZZyAmP+0lyj7jt8ek9W+FDgDEZ4Eo GDATe4aj4XR/tKvdkFu+cZG1bXatpzSAGbu73chDFbt+ZBp/vtGFvY= X-Received: by 2002:a05:690c:d8e:b0:81e:ba5b:97d2 with SMTP id 00721157ae682-81fb8a85be8mr18762137b3.2.1785400346780; Thu, 30 Jul 2026 01:32:26 -0700 (PDT) Received: from localhost.localdomain (45.78.65.84.16clouds.com. [45.78.65.84]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81fb8b2975csm6206277b3.48.2026.07.30.01.32.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 01:32:26 -0700 (PDT) From: Chengfeng Ye To: Marcel Holtmann , Luiz Augusto von Dentz , Johan Hedberg , Ankit Navik Cc: linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, Chengfeng Ye , stable@vger.kernel.org Subject: [PATCH] Bluetooth: hci_event: fix LE list UAF on reset Date: Thu, 30 Jul 2026 16:32:02 +0800 Message-ID: <20260730083202.2065336-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit hci_cc_reset() clears the LE accept and resolving lists without taking hdev->lock. Other command-complete handlers serialize updates to these lists with that lock, and the debugfs readers hold it while walking them. This permits the reset completion and a debugfs read to interleave as follows: hci_rx_work debugfs reader ----------- -------------- lock hdev->lock fetch current entry list_del(entry) kfree(entry) read entry fields The reader then dereferences a freed list entry and may follow its stale next pointer. KASAN reported: BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180 Read of size 1 at addr ffff8881015dab16 by task poc/95 Call Trace: white_list_show+0x15f/0x180 seq_read_iter+0x3ff/0x1190 seq_read+0x267/0x3d0 vfs_read+0x177/0xa20 ksys_read+0xf7/0x1c0 Allocated by task 91: hci_bdaddr_list_add+0x1a6/0x3a0 hci_cc_le_add_to_accept_list+0xab/0x140 hci_cmd_complete_evt+0x26c/0x9a0 hci_event_packet+0x454/0xb20 hci_rx_work+0x293/0x730 Freed by task 90: kfree+0x131/0x3c0 hci_bdaddr_list_clear+0xd8/0x160 hci_cc_reset+0x28a/0x370 hci_cmd_complete_evt+0x26c/0x9a0 hci_event_packet+0x454/0xb20 hci_rx_work+0x293/0x730 Take hdev->lock around both list clears. This matches the existing mutation and traversal locking convention. Fixes: a4d5504d5c39 ("Bluetooth: Clear LE white list when resetting controller") Fixes: cfdb0c2d095a ("Bluetooth: Store Resolv list size") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- net/bluetooth/hci_event.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c index 741d658e9630..00e2683f99ed 100644 --- a/net/bluetooth/hci_event.c +++ b/net/bluetooth/hci_event.c @@ -294,8 +294,10 @@ static u8 hci_cc_reset(struct hci_dev *hdev, void *data, struct sk_buff *skb) hdev->ssp_debug_mode = 0; + hci_dev_lock(hdev); hci_bdaddr_list_clear(&hdev->le_accept_list); hci_bdaddr_list_clear(&hdev->le_resolv_list); + hci_dev_unlock(hdev); return rp->status; } -- 2.43.0