* [PATCH] Bluetooth: MGMT: Fix memory leak in set_ssp_complete
@ 2026-01-21 5:29 Jianpeng Chang
2026-01-21 21:50 ` patchwork-bot+bluetooth
0 siblings, 1 reply; 2+ messages in thread
From: Jianpeng Chang @ 2026-01-21 5:29 UTC (permalink / raw)
To: marcel, johan.hedberg, luiz.dentz
Cc: linux-bluetooth, linux-kernel, Jianpeng Chang
Fix memory leak in set_ssp_complete() where mgmt_pending_cmd structures
are not freed after being removed from the pending list.
Commit 302a1f674c00 ("Bluetooth: MGMT: Fix possible UAFs") replaced
mgmt_pending_foreach() calls with individual command handling but missed
adding mgmt_pending_free() calls in both error and success paths of
set_ssp_complete(). Other completion functions like set_le_complete()
were fixed correctly in the same commit.
This causes a memory leak of the mgmt_pending_cmd structure and its
associated parameter data for each SSP command that completes.
Add the missing mgmt_pending_free(cmd) calls in both code paths to fix
the memory leak. Also fix the same issue in set_advertising_complete().
Fixes: 302a1f674c00 ("Bluetooth: MGMT: Fix possible UAFs")
Signed-off-by: Jianpeng Chang <jianpeng.chang.cn@windriver.com>
---
net/bluetooth/mgmt.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index 5be9b8c91949..0e46f9e08b10 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -1966,6 +1966,7 @@ static void set_ssp_complete(struct hci_dev *hdev, void *data, int err)
}
mgmt_cmd_status(cmd->sk, cmd->hdev->id, cmd->opcode, mgmt_err);
+ mgmt_pending_free(cmd);
return;
}
@@ -1984,6 +1985,7 @@ static void set_ssp_complete(struct hci_dev *hdev, void *data, int err)
sock_put(match.sk);
hci_update_eir_sync(hdev);
+ mgmt_pending_free(cmd);
}
static int set_ssp_sync(struct hci_dev *hdev, void *data)
@@ -6438,6 +6440,7 @@ static void set_advertising_complete(struct hci_dev *hdev, void *data, int err)
hci_dev_clear_flag(hdev, HCI_ADVERTISING);
settings_rsp(cmd, &match);
+ mgmt_pending_free(cmd);
new_settings(hdev, match.sk);
--
2.52.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] Bluetooth: MGMT: Fix memory leak in set_ssp_complete
2026-01-21 5:29 [PATCH] Bluetooth: MGMT: Fix memory leak in set_ssp_complete Jianpeng Chang
@ 2026-01-21 21:50 ` patchwork-bot+bluetooth
0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+bluetooth @ 2026-01-21 21:50 UTC (permalink / raw)
To: Jianpeng Chang
Cc: marcel, johan.hedberg, luiz.dentz, linux-bluetooth, linux-kernel
Hello:
This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@intel.com>:
On Wed, 21 Jan 2026 13:29:26 +0800 you wrote:
> Fix memory leak in set_ssp_complete() where mgmt_pending_cmd structures
> are not freed after being removed from the pending list.
>
> Commit 302a1f674c00 ("Bluetooth: MGMT: Fix possible UAFs") replaced
> mgmt_pending_foreach() calls with individual command handling but missed
> adding mgmt_pending_free() calls in both error and success paths of
> set_ssp_complete(). Other completion functions like set_le_complete()
> were fixed correctly in the same commit.
>
> [...]
Here is the summary with links:
- Bluetooth: MGMT: Fix memory leak in set_ssp_complete
https://git.kernel.org/bluetooth/bluetooth-next/c/efa3d7c22e98
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-01-21 21:50 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-01-21 5:29 [PATCH] Bluetooth: MGMT: Fix memory leak in set_ssp_complete Jianpeng Chang
2026-01-21 21:50 ` patchwork-bot+bluetooth
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®