From: Greg KH <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk, Johan Hovold <jhovold@gmail.com>,
Marcel Holtmann <marcel@holtmann.org>,
Johan Hedberg <johan.hedberg@intel.com>
Subject: [ 15/75] Bluetooth: hci_ldisc: fix NULL-pointer dereference on tty_close
Date: Thu, 19 Apr 2012 14:03:18 -0700 [thread overview]
Message-ID: <20120419210304.418483855@linuxfoundation.org> (raw)
In-Reply-To: <20120419210322.GA6478@kroah.com>
3.3-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <jhovold@gmail.com>
commit 33b69bf80a3704d45341928e4ff68b6ebd470686 upstream.
Do not close protocol driver until device has been unregistered.
This fixes a race between tty_close and hci_dev_open which can result in
a NULL-pointer dereference.
The line discipline closes the protocol driver while we may still have
hci_dev_open sleeping on the req_lock mutex resulting in a NULL-pointer
dereference when lock is acquired and hci_init_req called.
Bug is 100% reproducible using hciattach and a disconnected serial port:
0. # hciattach -n ttyO1 any noflow
1. hci_dev_open called from hci_power_on grabs req lock
2. hci_init_req executes but device fails to initialise (times out
eventually)
3. hci_dev_open is called from hci_sock_ioctl and sleeps on req lock
4. hci_uart_tty_close detaches protocol driver and cancels init req
5. hci_dev_open (1) releases req lock
6. hci_dev_open (3) grabs req lock, calls hci_init_req, which triggers oops
when request is prepared in hci_uart_send_frame
[ 137.201263] Unable to handle kernel NULL pointer dereference at virtual address 00000028
[ 137.209838] pgd = c0004000
[ 137.212677] [00000028] *pgd=00000000
[ 137.216430] Internal error: Oops: 17 [#1]
[ 137.220642] Modules linked in:
[ 137.223846] CPU: 0 Tainted: G W (3.3.0-rc6-dirty #406)
[ 137.230529] PC is at __lock_acquire+0x5c/0x1ab0
[ 137.235290] LR is at lock_acquire+0x9c/0x128
[ 137.239776] pc : [<c0071490>] lr : [<c00733f8>] psr: 20000093
[ 137.239776] sp : cf869dd8 ip : c0529554 fp : c051c730
[ 137.251800] r10: 00000000 r9 : cf8673c0 r8 : 00000080
[ 137.257293] r7 : 00000028 r6 : 00000002 r5 : 00000000 r4 : c053fd70
[ 137.264129] r3 : 00000000 r2 : 00000000 r1 : 00000000 r0 : 00000001
[ 137.270965] Flags: nzCv IRQs off FIQs on Mode SVC_32 ISA ARM Segment kernel
[ 137.278717] Control: 10c5387d Table: 8f0f4019 DAC: 00000015
[ 137.284729] Process kworker/u:1 (pid: 7, stack limit = 0xcf8682e8)
[ 137.291229] Stack: (0xcf869dd8 to 0xcf86a000)
[ 137.295776] 9dc0: c0529554 00000000
[ 137.304351] 9de0: cf8673c0 cf868000 d03ea1ef cf868000 000001ef 00000470 00000000 00000002
[ 137.312927] 9e00: cf8673c0 00000001 c051c730 c00716ec 0000000c 00000440 c0529554 00000001
[ 137.321533] 9e20: c051c730 cf868000 d03ea1f3 00000000 c053b978 00000000 00000028 cf868000
[ 137.330078] 9e40: 00000000 00000000 00000002 00000000 00000000 c00733f8 00000002 00000080
[ 137.338684] 9e60: 00000000 c02a1d50 00000000 00000001 60000013 c0969a1c 60000093 c053b96c
[ 137.347259] 9e80: 00000002 00000018 20000013 c02a1d50 cf0ac000 00000000 00000002 cf868000
[ 137.355834] 9ea0: 00000089 c0374130 00000002 00000000 c02a1d50 cf0ac000 0000000c cf0fc540
[ 137.364410] 9ec0: 00000018 c02a1d50 cf0fc540 00000000 cf0fc540 c0282238 c028220c cf178d80
[ 137.372985] 9ee0: 127525d8 c02821cc 9a1fa451 c032727c 9a1fa451 127525d8 cf0fc540 cf0ac4ec
[ 137.381561] 9f00: cf0ac000 cf0fc540 cf0ac584 c03285f4 c0328580 cf0ac4ec cf85c740 c05510cc
[ 137.390136] 9f20: ce825400 c004c914 00000002 00000000 c004c884 ce8254f5 cf869f48 00000000
[ 137.398712] 9f40: c0328580 ce825415 c0a7f914 c061af64 00000000 c048cf3c cf8673c0 cf85c740
[ 137.407287] 9f60: c05510cc c051a66c c05510ec c05510c4 cf85c750 cf868000 00000089 c004d6ac
[ 137.415863] 9f80: 00000000 c0073d14 00000001 cf853ed8 cf85c740 c004d558 00000013 00000000
[ 137.424438] 9fa0: 00000000 00000000 00000000 c00516b0 00000000 00000000 cf85c740 00000000
[ 137.433013] 9fc0: 00000001 dead4ead ffffffff ffffffff c0551674 00000000 00000000 c0450aa4
[ 137.441589] 9fe0: cf869fe0 cf869fe0 cf853ed8 c005162c c0013b30 c0013b30 00ffff00 00ffff00
[ 137.450164] [<c0071490>] (__lock_acquire+0x5c/0x1ab0) from [<c00733f8>] (lock_acquire+0x9c/0x128)
[ 137.459503] [<c00733f8>] (lock_acquire+0x9c/0x128) from [<c0374130>] (_raw_spin_lock_irqsave+0x44/0x58)
[ 137.469360] [<c0374130>] (_raw_spin_lock_irqsave+0x44/0x58) from [<c02a1d50>] (skb_queue_tail+0x18/0x48)
[ 137.479339] [<c02a1d50>] (skb_queue_tail+0x18/0x48) from [<c0282238>] (h4_enqueue+0x2c/0x34)
[ 137.488189] [<c0282238>] (h4_enqueue+0x2c/0x34) from [<c02821cc>] (hci_uart_send_frame+0x34/0x68)
[ 137.497497] [<c02821cc>] (hci_uart_send_frame+0x34/0x68) from [<c032727c>] (hci_send_frame+0x50/0x88)
[ 137.507171] [<c032727c>] (hci_send_frame+0x50/0x88) from [<c03285f4>] (hci_cmd_work+0x74/0xd4)
[ 137.516204] [<c03285f4>] (hci_cmd_work+0x74/0xd4) from [<c004c914>] (process_one_work+0x1a0/0x4ec)
[ 137.525604] [<c004c914>] (process_one_work+0x1a0/0x4ec) from [<c004d6ac>] (worker_thread+0x154/0x344)
[ 137.535278] [<c004d6ac>] (worker_thread+0x154/0x344) from [<c00516b0>] (kthread+0x84/0x90)
[ 137.543975] [<c00516b0>] (kthread+0x84/0x90) from [<c0013b30>] (kernel_thread_exit+0x0/0x8)
[ 137.552734] Code: e59f4e5c e5941000 e3510000 0a000031 (e5971000)
[ 137.559234] ---[ end trace 1b75b31a2719ed1e ]---
Signed-off-by: Johan Hovold <jhovold@gmail.com>
Acked-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Johan Hedberg <johan.hedberg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/hci_ldisc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/bluetooth/hci_ldisc.c
+++ b/drivers/bluetooth/hci_ldisc.c
@@ -309,11 +309,11 @@ static void hci_uart_tty_close(struct tt
hci_uart_close(hdev);
if (test_and_clear_bit(HCI_UART_PROTO_SET, &hu->flags)) {
- hu->proto->close(hu);
if (hdev) {
hci_unregister_dev(hdev);
hci_free_dev(hdev);
}
+ hu->proto->close(hu);
}
kfree(hu);
}
next prev parent reply other threads:[~2012-04-19 21:03 UTC|newest]
Thread overview: 76+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-04-19 21:03 [ 00/75] 3.3.3-stable review Greg KH
2012-04-19 21:03 ` [ 01/75] Btrfs: fix regression in scrub path resolving Greg KH
2012-04-19 21:03 ` [ 02/75] drm/radeon/kms: fix DVO setup on some r4xx chips Greg KH
2012-04-19 21:03 ` [ 03/75] drm/i915: Removed IVB forced enable of sprite dest key Greg KH
2012-04-19 21:03 ` [ 04/75] drm/i915/ringbuffer: Exclude last 2 cachlines of ring on 845g Greg KH
2012-04-19 21:03 ` [ 05/75] drm/radeon: only add the mm i2c bus if the hw_i2c module param is set Greg KH
2012-04-19 21:03 ` [ 06/75] drm/i915: properly compute dp dithering for user-created modes Greg KH
2012-04-19 21:03 ` [ 07/75] drm/i915: make rc6 module parameter read-only Greg KH
2012-04-19 21:03 ` [ 08/75] rtlwifi: Preallocate USB read buffers and eliminate kalloc in read routine Greg KH
2012-04-19 21:03 ` [ 09/75] rtlwifi: Add missing DMA buffer unmapping for PCI drivers Greg KH
2012-04-19 21:03 ` [ 10/75] ARM: 7379/1: DT: fix atags_to_fdt() second call site Greg KH
2012-04-19 21:03 ` [ 11/75] ARM: 7384/1: ThumbEE: Disable userspace TEEHBR access for !CONFIG_ARM_THUMBEE Greg KH
2012-04-19 21:03 ` [ 12/75] md/raid1,raid10: Fix calculation of vcnt when processing error recovery Greg KH
2012-04-19 21:03 ` [ 13/75] md/bitmap: prevent bitmap_daemon_work running while initialising bitmap Greg KH
2012-04-19 21:03 ` [ 14/75] [PATCH] Bluetooth: uart-ldisc: Fix memory leak Greg KH
2012-04-19 21:03 ` Greg KH [this message]
2012-04-19 21:03 ` [ 16/75] Bluetooth: hci_core: fix NULL-pointer dereference at unregister Greg KH
2012-04-19 21:03 ` [ 17/75] Bluetooth: Remove unneeded locking Greg KH
2012-04-19 21:03 ` [ 18/75] Revert "Btrfs: increase the global block reserve estimates" Greg KH
2012-04-19 21:03 ` [ 19/75] ALSA: hda/realtek - Add a fixup entry for Acer Aspire 8940G Greg KH
2012-04-19 21:03 ` [ 20/75] ext4: address scalability issue by removing extent cache statistics Greg KH
2012-04-19 21:03 ` [ 21/75] ia64: fix futex_atomic_cmpxchg_inatomic() Greg KH
2012-04-19 21:03 ` [ 22/75] panic: fix stack dump print on direct call to panic() Greg KH
2012-04-19 21:03 ` [ 23/75] drivers/rtc/rtc-pl031.c: enable clock on all ST variants Greg KH
2012-04-19 21:03 ` [ 24/75] hugetlb: fix race condition in hugetlb_fault() Greg KH
2012-04-19 21:03 ` [ 25/75] staging: iio: hmc5843: Fix crash in probe function Greg KH
2012-04-19 21:03 ` [ 26/75] Revert "serial/8250_pci: init-quirk msi support for kt serial controller" Greg KH
2012-04-19 21:03 ` [ 27/75] serial: samsung: fix omission initialize ulcon in reset port fn() Greg KH
2012-04-19 21:03 ` [ 28/75] Revert "serial/8250_pci: setup-quirk workaround for the kt serial controller" Greg KH
2012-04-19 21:03 ` [ 29/75] serial/8250_pci: add a "force background timer" flag and use it for the "kt" serial port Greg KH
2012-04-19 21:03 ` [ 30/75] tty: serial: altera_uart: Check for NULL platform_data in probe Greg KH
2012-04-19 21:03 ` [ 31/75] sparc64: Eliminate obsolete __handle_softirq() function Greg KH
2012-04-19 21:03 ` [ 32/75] sparc64: Fix bootup crash on sun4v Greg KH
2012-04-19 21:03 ` [ 33/75] cciss: Initialize scsi host max_sectors for tape drive support Greg KH
2012-04-19 21:03 ` [ 34/75] cciss: Fix scsi tape io with more than 255 scatter gather elements Greg KH
2012-04-19 21:03 ` [ 35/75] perf hists: Catch and handle out-of-date hist entry maps Greg KH
2012-04-19 21:03 ` [ 36/75] video:uvesafb: Fix oops that uvesafb try to execute NX-protected page Greg KH
2012-04-19 21:03 ` [ 37/75] IB/srpt: Set srq_type to IB_SRQT_BASIC Greg KH
2012-04-19 21:03 ` [ 38/75] nohz: Fix stale jiffies update in tick_nohz_restart() Greg KH
2012-04-19 21:03 ` [ 39/75] pch_uart: Fix MSI setting issue Greg KH
2012-04-19 21:03 ` [ 40/75] x86: Use correct byte-sized register constraint in __xchg_op() Greg KH
2012-04-19 21:03 ` [ 41/75] x86: Use correct byte-sized register constraint in __add() Greg KH
2012-04-19 21:03 ` [ 42/75] USB: serial: fix race between probe and open Greg KH
2012-04-19 21:03 ` [ 43/75] USB: pl2303: fix DTR/RTS being raised on baud rate change Greg KH
2012-04-19 21:03 ` [ 44/75] USB: option: re-add NOVATELWIRELESS_PRODUCT_HSPA_HIGHSPEED to option_id array Greg KH
2012-04-19 21:03 ` [ 45/75] USB: ftdi_sio: fix status line change handling for TIOCMIWAIT and TIOCGICOUNT Greg KH
2012-04-19 21:03 ` [ 46/75] USB: ftdi_sio: fix race condition in TIOCMIWAIT, and abort of TIOCMIWAIT when the device is removed Greg KH
2012-04-19 21:03 ` [ 47/75] USB: sierra: add support for Sierra Wireless MC7710 Greg KH
2012-04-19 21:03 ` [ 48/75] USB: dont clear urb->dev in scatter-gather library Greg KH
2012-04-19 21:03 ` [ 49/75] USB: dont ignore suspend errors for root hubs Greg KH
2012-04-19 21:03 ` [ 50/75] xhci: dont re-enable IE constantly Greg KH
2012-04-19 21:03 ` [ 51/75] xhci: Dont write zeroed pointers to xHC registers Greg KH
2012-04-19 21:03 ` [ 52/75] xhci: Restore event ring dequeue pointer on resume Greg KH
2012-04-19 21:03 ` [ 53/75] USB: fix bug of device descriptor got from superspeed device Greg KH
2012-04-19 21:03 ` [ 54/75] xHCI: add XHCI_RESET_ON_RESUME quirk for VIA xHCI host Greg KH
2012-04-19 21:03 ` [ 55/75] xHCI: Correct the #define XHCI_LEGACY_DISABLE_SMI Greg KH
2012-04-19 21:03 ` [ 56/75] [S390] fix tlb flushing for page table pages Greg KH
2012-04-19 21:04 ` [ 57/75] memcg: fix Bad page state after replace_page_cache Greg KH
2012-04-19 21:04 ` [ 58/75] serial: PL011: clear pending interrupts Greg KH
2012-04-19 21:04 ` [ 59/75] serial: PL011: move interrupt clearing Greg KH
2012-04-19 21:04 ` [ 60/75] fcaps: clear the same personality flags as suid when fcaps are used Greg KH
2012-04-19 21:04 ` [ 61/75] xhci: Fix register save/restore order Greg KH
2012-04-19 21:04 ` [ 62/75] usb: gadget: pch_udc: Fix disconnect issue Greg KH
2012-04-19 21:04 ` [ 63/75] usb: gadget: pch_udc: Fix wrong return value Greg KH
2012-04-19 21:04 ` [ 64/75] usb: gadget: pch_udc: Fix USB suspend issue Greg KH
2012-04-19 21:04 ` [ 65/75] usb: gadget: pch_udc: Fix usb/gadget/pch_udc: Fix ether gadget connect/disconnect issue Greg KH
2012-04-19 21:04 ` [ 66/75] usb: gadget: pch_udc: Reduce redundant interrupt Greg KH
2012-04-19 21:04 ` [ 67/75] security: fix compile error in commoncap.c Greg KH
2012-04-19 21:04 ` [ 68/75] spi-topcliff-pch: fix -Wuninitialized warning Greg KH
2012-04-19 21:04 ` [ 69/75] Bluetooth: Adding USB device 13d3:3375 as an Atheros AR3012 Greg KH
2012-04-19 21:04 ` [ 70/75] Bluetooth: Add Atheros maryann PIDVID support Greg KH
2012-04-19 21:04 ` [ 71/75] futex: Do not leak robust list to unprivileged process Greg KH
2012-04-19 21:04 ` [ 72/75] drm/i915: Hold mode_config lock whilst changing mode for lastclose() Greg KH
2012-04-19 21:04 ` [ 73/75] drm/radeon/kms: fix the regression of DVI connector check Greg KH
2012-04-19 21:04 ` [ 74/75] drm/radeon: disable MSI on RV515 Greg KH
2012-04-19 21:04 ` [ 75/75] drm/radeon: fix load detect on rn50 with hardcoded EDIDs Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120419210304.418483855@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=jhovold@gmail.com \
--cc=johan.hedberg@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=marcel@holtmann.org \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).