]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/commit
Bluetooth: prefetch channel before killing sock
authorHillf Danton <hdanton@sina.com>
Wed, 5 Feb 2020 02:31:59 +0000 (10:31 +0800)
committerStefan Bader <stefan.bader@canonical.com>
Mon, 9 Nov 2020 13:47:30 +0000 (14:47 +0100)
commit49df06f7d5c88304d09b3bfc4da1030b4fe3f23c
tree49daafb0e0a59930494dc4dd17f9a89c600a3331
parent246f79052acbf9fdf638855ad3098832e91db690
Bluetooth: prefetch channel before killing sock

BugLink: https://bugs.launchpad.net/bugs/1900624
[ Upstream commit 2a154903cec20fb64ff4d7d617ca53c16f8fd53a ]

Prefetch channel before killing sock in order to fix UAF like

 BUG: KASAN: use-after-free in l2cap_sock_release+0x24c/0x290 net/bluetooth/l2cap_sock.c:1212
 Read of size 8 at addr ffff8880944904a0 by task syz-fuzzer/9751

Reported-by: syzbot+c3c5bdea7863886115dc@syzkaller.appspotmail.com
Fixes: 6c08fc896b60 ("Bluetooth: Fix refcount use-after-free issue")
Cc: Manish Mandlik <mmandlik@google.com>
Signed-off-by: Hillf Danton <hdanton@sina.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
Signed-off-by: Ian May <ian.may@canonical.com>
net/bluetooth/l2cap_sock.c