From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f174.google.com (mail-pl1-f174.google.com [209.85.214.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 09603363C6F for ; Thu, 23 Jul 2026 03:28:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784777296; cv=none; b=M8Sdc8UObvcm/A4ajXB2oH/zYIIGDeDUVy0dpZ3JyRIbCnEHc2P3c4VqY6097PdzGzFAYTM+J4yXFoMxzz6wdWDmetRmjqJUQi8FtqOSDqZV975dy10HJXVtv3k66G9P5hVvwlGSI1P7wRIWjYgpKvFp4Y846b+DqQ6m/LSlgRU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784777296; c=relaxed/simple; bh=jQvSLtfuIPDAKmmLDRJEf2naowzs8N4VS6D/XoOOehY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=o/ZKkGNLcv2eA5kbO4rL+PxROotyETZQzv15Kl6Vp3rKoS1fxktPSujcGRjqPQLn6MkFxOgoV+U5MwwqQYYtdOvSUNj50A2i5mSAL7ZorliWS7H0khdHwdINOESpFYObVbv+DKAaLY09KUXdcWc8ldVDpTZKjRw/+P7xWfoiqgE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GSGSyjqI; arc=none smtp.client-ip=209.85.214.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GSGSyjqI" Received: by mail-pl1-f174.google.com with SMTP id d9443c01a7336-2cace91f112so2177585ad.0 for ; Wed, 22 Jul 2026 20:28:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784777291; x=1785382091; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=tHZVZTCMmEvKPugPr8dJCpxRM4kbAf/u/60KC50+QaY=; b=GSGSyjqIiFq5uydRcWwkYbrXnonABdb9GK8OTHn0Oz2Wv8rqHAmO6u7wA8OFvV6ruR qo2YS8VgkRwCMYZBlG8OsWYyZxP7qqHBkGLHJGYmMZ1tR/dCoEt1rXoAt7nBj6eglRR5 FPdHubzrTACYAGtIVgYo29aXEN03St+Tjdpg7Ev9kfcmYH8hzymEJE9P05CLqX4K4ysl U5iWF7ERe9jMaofWMKLxdHClSdk7qbuL84bo+gdKwgEAujl/SkYMEvhAv9VpiDyFuUEH nr8BEFZue5C7edtkNnO2ekgL/CaRdOyt0Qf7GcubhahxQCEetz/14gzdWtyaZ5xhGX3h iNqA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784777291; x=1785382091; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tHZVZTCMmEvKPugPr8dJCpxRM4kbAf/u/60KC50+QaY=; b=DcCd8UlACU4pICr/DHmT5U30JglrRAht+JCj5fCmwd2G9jUKkRof9dE2f2tfvcn+mY NcLs+ssxr9xYg0sp+4gbL6y6ICepMd4v15kAmVAs8VTMEqoWg8/RFoowWdSykpqvCaDz 0HEDYSmDQAafmfvdIWOHZzUloIKPHwQs3WAHgoQLyyLJXIPY/gxNuYSqVvPkN64tyiIk LiOAf1+cvh1bUSq3rjpkhNlUOtnNYQCGTZcdnlYlYdpLaJqbr62S+/y18BFfMJ4AGRIe DQuc/oCyMS6Jhvjs3a6RQQGzyoQhRBNh9FOtn3OQUCpsrnnneVPCj2hommla+4ZbEhIr lQiA== X-Forwarded-Encrypted: i=1; AHgh+Rpm+9vcW+GjsAIxQlo+CvGUNKTftCB+/3yE1Zp6wvqm1dTzKJ6BE3o7YKST72CKy3PRz1EoTwYVQYzvJrA=@vger.kernel.org X-Gm-Message-State: AOJu0Yy2U+8oePu2oCQ3Cs1eC6W5y+6trODf2KftEfp8muyvY6IrYqau w+R0eaQXjIhsjP9VjWPRc0OrPGlqiJxlbup68LfgX9zGda4KcOxeyc1d X-Gm-Gg: AR+sD12ixgKto1Ql6guSFGRNy/8n/VPidF7o+QjoTQ5Q850n3jL5IcPeLaXaqLB5bsN oOqAG5jt9kRqfi8o51xQUUIQB9rVqONmEvUHIag6Akj7tBoGKeF79eH3N+LjIVWsIlAqBCuuxlo DOVllMjfWhpPt2W99NEobnH6xysn8/Xl3tJrkIvOtrmPukagJ/9YBuhaCdRRlYCLTT4Lt7Mv6Ku pEbyLjfP+lyPAkhRh1NSPGYCIxddJEhP50FEp40R75VplMwMoVutYaBRD+8zVFhPbFmzs3LsF1v cetAnf0A6prIJiekmKIwYEYtRWvcGI9x6ip1w1By81gf/lsO46CFCfAlHJ5VQkhX2LPRjNhV6Q3 4+DFeTotKQh4FIBTsEIPiBQTOxDQEHA9myrK5y3KJZiKyF5HwcW12wtKOLdrrFTJua/Qb/7qtwk RGpnVuTT9wpYPQLa1IPXshMQzJ/89WzHYA7vLVnHYWC+pYaJaY2Rh5 X-Received: by 2002:a17:903:244a:b0:2cb:ea0b:9164 with SMTP id d9443c01a7336-2cfa6a51b43mr16909445ad.6.1784777291143; Wed, 22 Jul 2026 20:28:11 -0700 (PDT) Received: from DESKTOP-L3Q0GIV.localdomain ([203.230.195.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd7157sm24538485ad.18.2026.07.22.20.28.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 20:28:10 -0700 (PDT) From: Sangho Lee To: luiz.dentz@gmail.com, marcel@holtmann.org, linux-bluetooth@vger.kernel.org Cc: jikos@kernel.org, alan@signal11.us, padovan@profusion.mobi, linux-kernel@vger.kernel.org, stable@vger.kernel.org, kudo3228@gmail.com Subject: [PATCH 0/2] Bluetooth: HIDP: validate short receive frames Date: Thu, 23 Jul 2026 12:28:05 +0900 Message-ID: <20260723032807.1616487-1-kudo3228@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The HIDP control and interrupt receive paths assume that every L2CAP SDU contains a transaction header. The raw-report return path also assumes that a numbered DATA response contains a report ID. Both assumptions allow a connected peer to make HIDP consume data beyond the logical skb boundary. The tests used two BlueZ 5.87 btvirt BR/EDR controllers, real L2CAP PSM 0x11/0x13 channels, HIDPCONNADD, and HIDIOCGFEATURE on bluetooth.git at df541cd485ff. The series also applies without changes to bluetooth-next at 6f55ad8fb0ac. On the unpatched KMSAN kernel, an empty control SDU produced two uninitialized-value reports in hidp_session_run(), an empty interrupt SDU produced one, and a DATA | FEATURE header without a report payload produced one. Patch 1 removed only the first three reports; applying both patches removed all four. The tests also placed a controlled byte after the declared L2CAP PDU. A trailing 0x15 after a zero-length control SDU was interpreted as virtual cable unplug and terminated the unpatched HIDP session. The patched session rejected the frame and completed a later feature report request. A trailing report ID after a header-only DATA response made the unpatched raw-report request complete with a zero-byte result; the patched kernel rejected it. Finally, each path received 10,000 malformed responses on KASAN and UBSAN kernels. No KASAN, UBSAN, Oops, or kernel BUG was observed. The KASAN runs and all patched UBSAN runs accepted a subsequent valid feature report. The unpatched UBSAN numbered-report run instead completed requests from queued short responses, which further exposed the missing payload validation. No information disclosure or code execution is claimed. Sangho Lee (2): Bluetooth: HIDP: reject frames without a transaction header Bluetooth: HIDP: validate numbered report payloads net/bluetooth/hidp/core.c | 30 ++++++++++++++++++------------ 1 file changed, 18 insertions(+), 12 deletions(-) -- 2.43.0