From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 92941351C11 for ; Thu, 23 Jul 2026 03:28:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784777299; cv=none; b=orH8OPZ+y6urfvG9+p4+CnOgUwS5LWZn24ruLvC4icp1vcUKQlR0QXvHgSn9xnCIQOn322YFeav5pB4uLZR5jCmGbxHL7dEpt1IzJIjEcXlRge1HWLlIruo8swdyN2jrqxWXLlg21SG9tR07qJl8tlfaenCq0PqKCib7w5HoMwg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784777299; c=relaxed/simple; bh=sdhxvo7B/ZpOCnMBhGBNFRimfFAigIMZ6Qr2obutEG8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XrWEf6q4kwvbjBnWAZqibZfAh7qBWm0nIyLkMM0az+SjHZNuHt+pQJWkl64lRQExzPTbhNU3QQ2R3cv0aCZYIUNwatulnyRoimvWE9nRIT6hHTfOv2QJVYgLDxxnjn+OG1w392ErugxtGLyKjJc9kUQVvh9NfMoMuk2uBu87O0E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fknpjgUE; arc=none smtp.client-ip=209.85.214.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fknpjgUE" Received: by mail-pl1-f169.google.com with SMTP id d9443c01a7336-2cea3004256so2220765ad.0 for ; Wed, 22 Jul 2026 20:28:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784777294; x=1785382094; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DHNwKqm3c1H0XvuQxYM3/7tpki/tKxwX9sSDYJq0L48=; b=fknpjgUEPQ1IHhcK5tB3lcQoerHj78uLAK2HOmW4Qry1mi/gt+8alecR3jJ8jJHZ/+ qn5fVCGC9arx/btHCx6hjhF2Cd7OLB0ZzZYsqdCsYOgvy+3iyj11YCz+/eXyroGDutub EzALZXQKLs/ny0WOarEIeKvUqvoUzUT0QE6an4l7Fs1+DgG3pYTL7rKfwTD6AXCfBkLj kXd//G/N05T8QNex/egtmuD5f6qoNE8Ey7Rpe87tiTdYvNjrnUx5YLK7hxt6pdsAz5ah SUVFl+G3e5z6r7tnEf5H6exX7R1bP7heWrpoC3QvJNUHNW5OtOg9qfKH96/dI5Ta+3ME VedQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784777294; x=1785382094; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=DHNwKqm3c1H0XvuQxYM3/7tpki/tKxwX9sSDYJq0L48=; b=Pcrx33rNeGheRpJqqPFktjXxIaxBQ7DE+6Q5Hvek0oOs61Jvng+QQPwHsg2I+xvmTt KMt9hF3EU/QO9J6nnAnoTBEtPEsJGCbrAYjOMIFuTvZpCOqIwVPtmCZAL6hB1p6DZOMD Fj/9vjjJhRLlClfMl0pcIy9WSoBqZiy74j3Zri7KRjuCMWQ/2AYwXtchxjd39cyZ70VR ELmX6PgbloFm0na9aR2j66yh4JO99M0n4kfN2jtk3+n0iVDXRU13lbQcmfSQNzaSWTKD 3CLr6ANDN0uFqh4kFzJd355blmjtHM6JRpqLyXLrdPzeMtVrWX/vFRNYE06/xsarAm9W RiLQ== X-Forwarded-Encrypted: i=1; AHgh+RpQShPBXGQjA8x8z1nINV/HnXb6IumFsNA1IIz4415D6zV1J+g96dRx5781PV+sRzHFWQXbeOiuV6EH1xM=@vger.kernel.org X-Gm-Message-State: AOJu0YxMcbUqF0mYRf9DDspD+qXKABmN51NVQqWQdyz8Kr1iJrih6ogM 5ICAiYm75wzkg9OHaOH8LLHRXjbxve5cHnd5caN0LuQXEJCHVuVq2M6j X-Gm-Gg: AR+sD13iW0yabGfFJ6X9DsF8HR/umUk+83svsk91KwWL9q+BYP0UrzcXZbTNM7zw4x5 7MvXdx2D0BpVN+jAAUHjc1ZMXFrqp9j4qEN5VDsY3LTumR1GTFn9Acj1bG42dISngHZxP2HicM5 FTX9PdTYnui+kgO9Ra7E74YVw/xV4HRpz/yhK6dN75BjgTIKEJhH+Dliaz6IPosfB/Fsn+braOg yEY/5SlLX+bnLeUdH0zYZrWaQXU+X1CrnHmRhzZHfZYg3RlffSMpoWaQ6xxPbouxEU/+uehN/cT aqMedOxLHAPp5CTuK3Q/eoipnvXAxdHMAqTKNGGlPqZVt4KGjwybV53jZExcFgdGaItYAQ1BNLf 1uRB7O5ggMpwyVsnBY/RjMqKker4op4ALMvgyiSpfcPRFackMe4iJfU/zFfl2MQHBccNwGkidvS 08jWFxeT3bD69FtbRzeXaY4i7mjvCf0JO9Swk2um2yCuEPEcptcszjiyzP0CwgayE= X-Received: by 2002:a17:902:f605:b0:2cc:864b:539 with SMTP id d9443c01a7336-2cfa6a4395amr16049325ad.6.1784777293692; Wed, 22 Jul 2026 20:28:13 -0700 (PDT) Received: from DESKTOP-L3Q0GIV.localdomain ([203.230.195.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd7157sm24538485ad.18.2026.07.22.20.28.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 20:28:13 -0700 (PDT) From: Sangho Lee To: luiz.dentz@gmail.com, marcel@holtmann.org, linux-bluetooth@vger.kernel.org Cc: jikos@kernel.org, alan@signal11.us, padovan@profusion.mobi, linux-kernel@vger.kernel.org, stable@vger.kernel.org, kudo3228@gmail.com Subject: [PATCH 1/2] Bluetooth: HIDP: reject frames without a transaction header Date: Thu, 23 Jul 2026 12:28:06 +0900 Message-ID: <20260723032807.1616487-2-kudo3228@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723032807.1616487-1-kudo3228@gmail.com> References: <20260723032807.1616487-1-kudo3228@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0] before checking that the L2CAP SDU contains a transaction header. A connected HIDP peer can send an empty basic-mode SDU and make both paths use an uninitialized byte from skb tailroom. KMSAN reports the use in hidp_session_run(), with the uninitialized value originating in __alloc_skb() through vhci_write(). The control path produces two reports and the interrupt path produces one. The byte can also be controlled by a malformed lower-layer packet. If an HCI ACL packet contains an L2CAP PDU with a declared zero-length payload followed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to the declared PDU length before dispatch. The current HIDP path nevertheless consumes the extra byte as HIDP_TRANS_HID_CONTROL | HIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this change, the same packet is discarded and a subsequent feature report request succeeds. Pull the transaction header with skb_pull_data() and discard frames that do not contain it. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Signed-off-by: Sangho Lee --- net/bluetooth/hidp/core.c | 25 +++++++++++++++---------- 1 file changed, 15 insertions(+), 10 deletions(-) diff --git a/net/bluetooth/hidp/core.c b/net/bluetooth/hidp/core.c index 0e24c5e2955e..194208d03d18 100644 --- a/net/bluetooth/hidp/core.c +++ b/net/bluetooth/hidp/core.c @@ -560,16 +560,18 @@ static int hidp_process_data(struct hidp_session *session, struct sk_buff *skb, static void hidp_recv_ctrl_frame(struct hidp_session *session, struct sk_buff *skb) { - unsigned char hdr, type, param; + unsigned char type, param; + u8 *hdr; int free_skb = 1; BT_DBG("session %p skb %p len %u", session, skb, skb->len); - hdr = skb->data[0]; - skb_pull(skb, 1); + hdr = skb_pull_data(skb, 1); + if (!hdr) + goto free; - type = hdr & HIDP_HEADER_TRANS_MASK; - param = hdr & HIDP_HEADER_PARAM_MASK; + type = *hdr & HIDP_HEADER_TRANS_MASK; + param = *hdr & HIDP_HEADER_PARAM_MASK; switch (type) { case HIDP_TRANS_HANDSHAKE: @@ -590,6 +592,7 @@ static void hidp_recv_ctrl_frame(struct hidp_session *session, break; } +free: if (free_skb) kfree_skb(skb); } @@ -597,14 +600,15 @@ static void hidp_recv_ctrl_frame(struct hidp_session *session, static void hidp_recv_intr_frame(struct hidp_session *session, struct sk_buff *skb) { - unsigned char hdr; + u8 *hdr; BT_DBG("session %p skb %p len %u", session, skb, skb->len); - hdr = skb->data[0]; - skb_pull(skb, 1); + hdr = skb_pull_data(skb, 1); + if (!hdr) + goto free; - if (hdr == (HIDP_TRANS_DATA | HIDP_DATA_RTYPE_INPUT)) { + if (*hdr == (HIDP_TRANS_DATA | HIDP_DATA_RTYPE_INPUT)) { hidp_set_timer(session); if (session->input) @@ -616,9 +620,10 @@ static void hidp_recv_intr_frame(struct hidp_session *session, BT_DBG("report len %d", skb->len); } } else { - BT_DBG("Unsupported protocol header 0x%02x", hdr); + BT_DBG("Unsupported protocol header 0x%02x", *hdr); } +free: kfree_skb(skb); } -- 2.43.0