From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f172.google.com (mail-yw1-f172.google.com [209.85.128.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0A2F432AABA for ; Fri, 7 Aug 2026 07:09:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086567; cv=none; b=Px2W3LSlDG2Tzj7oJzwVeM/H7yWoxh1BrEi0C6DJ074CqGmRbR/PIuNsyl23HyhndLfQo6mGXsDXTsKnav/KC5wpcE8WV1IrtkjglCCCb+sQx8Swvgt0VKo56XQ6GdTEIxtLnZRrXdnIsILnSXEk+YLrEYwK1HWYhGWds/LHegw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086567; c=relaxed/simple; bh=cs+sCnn7xWiEgcV9ZSxKwtCGXZUQ9wbMPoLQAd9HEts=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Ol4cegTyczFnGK1YojeqPGfQbFGZYMUleNPF5nq+5AAqFoX/4351pK5UJX3CkMXTDHlLzcQrUQF2psOTgD4VtkKLJyU4iIOoiEUSrWtIjNXxpJvP9fn81pFG/Qrq87aiNpD0toAGxgOWbSkI7bOYAgKr56lGK5GKxtj8wWh88qg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com; spf=pass smtp.mailfrom=xbow.com; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b=ZVE73slM; arc=none smtp.client-ip=209.85.128.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xbow.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b="ZVE73slM" Received: by mail-yw1-f172.google.com with SMTP id 00721157ae682-80e2cfe6918so34929507b3.0 for ; Fri, 07 Aug 2026 00:09:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xbow.com; s=google; t=1786086564; x=1786691364; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=G7gB99jopYOI8TNqTIZ3KOn+F7j/uZRYCXYb3SJDHNc=; b=ZVE73slM2iSPT9P/Bo1pcg7ZLuJREBXejbMiTHysbfpeeKrSNimG3C7FC9aapU3bA1 BKmEEJF+5HNIIXPMbw12NExY9BM20PWd+Ef2xTc7ChBk8regOpOUt2mCMZEShNsz79VX pR3no+L1bFmvuxf3I3DOFje5QfScQWGA6UC0JFwwLJJMqPL9EOfBJQwyugdE5W+yankV /8Uh1/Ko6axwshAL1SzIIt5icIjc2+RC1YSCjfstFcSJIJoSpxyU+RE4Tpd0WXq3h/2h Pe8aAqZ5nEBUmUQCJIL2UUeiUt+QovYfjmmrddHWFC3BWY0xfLw+hSn6jgKTyTt/n0D3 VMnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786086564; x=1786691364; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=G7gB99jopYOI8TNqTIZ3KOn+F7j/uZRYCXYb3SJDHNc=; b=lfQrsBfkZIBRlexZ7q68jtySUmGSkYKjxG29zFjOuooSn0EbSsFhiISkn9268Ply6P PJvS1D9AC+1GUfYxMuEtPf/kgdPo/Pn/S85NwoJoJlDVc9udJFKt3eIPnE0hiJZowko+ /dTuJ0e65SmX6VZp918VyV/cTk9xw7IrgmE1eJLPCqeXTBiIwKa4OO7y3PwVkQzJjjjI 9o9c8kT4HgbhqTYz2gHTJnesVJvEh+LPNZCcDA6qrfts1koyr2xtSGSOH/JR8/qlfhbF nUvGfrZL5xYgrOE7RlnrprAmGO7ZlOISAetRI1XYjy5xx+b7HibD0msmVt+m+423tR6l M+vw== X-Forwarded-Encrypted: i=1; AHgh+Rq/Lsjg1Iuw+SQzST0lG21CwrjyEHfPoelmRr/lWnH9NX7yAeJWJOjB8aBcWbXMgrJ3J83s8BUFINFjfGs=@vger.kernel.org X-Gm-Message-State: AOJu0YxfsbVaOm6g+fTqI1fgUC+a59/riDIBXFjQsm93X725sPpeT4mY /i1vP0K2Zt/HrNaa0Nkv+/FgUGhOuoMcxAJL8EH7qkx+KGfPxBfJ4fbx8z7xETDv3Ys= X-Gm-Gg: AR+sD13BSB/0X0qrlrh20y0Phrgvf9cg7NuujDPyCgj1FcuwB8xskqS0jhNdsNEpR6a GmP4hDxxrlcFz0c6W4g8VBK8NYPHt08hOnv15aKxm5ls/8EyS6pEicS0v9BXUnp/uaX7pAGYYtv xJBnOx0hEGq55u7cA55dgC5B39gnap5B4GGjy/zEk+luHYn5U9Bcgw0oSY8v9uf92JpqxcygtRn nFnr1HC9n6SpDKtqgkdGEwEcKBsV09mJGtXO3UrK7NlhRaJp3dlvHQLCzHK301Xiwno1eF+0Wuw enE7ncvUoSK0iXCo5xAzprNYBAym1LL5jCfnaU1fgTVTB5Eud1CfSxAdTI5LYSo2udl34J7y7mA kNFWE32oEMJgI4uQVJcs4u/YOr/9HsM37raRR+NA53KsTS4MH1DQ2mM5C4eBIZmnWufRISkSBqE vlCaK3OfZ0eIAeazlzZzxWnLkZej0nsXOGg+u5kkTPT7kbNXcPPYVh37t0FqV9O64Y3EMdlSAmv 12oZgBhISI6Ke090Nogy+RzVziwhe799VwbfffDBLhw1lHTdxiV6tQUkGXi5JOSy2M2/zj6Gjri NB0fN9ZEVtK3A7nzWsffrhT2Bz1vi7BRJb8= X-Received: by 2002:a05:690c:6602:b0:80b:a1c7:9f95 with SMTP id 00721157ae682-8201bccf906mr129185607b3.5.1786086563843; Fri, 07 Aug 2026 00:09:23 -0700 (PDT) Received: from buildmachine.tailf331da.ts.net (ec2-3-14-143-233.us-east-2.compute.amazonaws.com. [3.14.143.233]) by smtp.gmail.com with ESMTPSA id 00721157ae682-823f0e64324sm5230367b3.19.2026.08.07.00.09.20 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 07 Aug 2026 00:09:23 -0700 (PDT) From: Baul Lee To: Luiz Augusto von Dentz , Marcel Holtmann , Brian Gix Cc: Baul Lee , Luiz Augusto von Dentz , Dmitry Antipov , linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, federico.kirschbaum@xbow.com Subject: [PATCH 0/3] Bluetooth: MGMT: fix use-after-free of struct mgmt_mesh_tx Date: Fri, 7 Aug 2026 16:09:13 +0900 Message-ID: <20260807070916.85771-1-baul.lee@xbow.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit hdev->mesh_pending is extended and walked from syscall context under hdev->lock, and unlinked and freed from the hci_cmd_sync worker under hci_req_sync_lock, so the list has no protection; the objects on it are also handed to hci_cmd_sync_queue() as raw pointers, and those work entries outlive the list. Three use-after-frees follow, all reproduced under KASAN. Patch 1 removes mgmt_cleanup(), the one walker of the list that cannot take hdev->lock. Patch 2 puts the list under hdev->lock on the worker side and asserts it in the helpers. Patch 3 gives the object a reference count for the work entry. The order matters: the assertions in patch 2 have no violating caller left once patch 1 is in, and the reference in patch 3 is only well defined once every unlink happens under one lock. Reaching any of this needs CAP_NET_ADMIN in the init user namespace. hci_sock.c sets HCI_SOCK_TRUSTED at bind under capable() rather than ns_capable() and gates every later mgmt command on it, and the mesh commands additionally need HCI_MESH_EXPERIMENTAL. Nothing in hci_event.c touches hdev->mesh_pending. Each reproducer was run at identical parameters on the unpatched and the patched kernel, built with KASAN, PROVE_LOCKING, DEBUG_LIST and DEBUG_ATOMIC_SLEEP: every splat the unpatched kernel produces is gone. Baul Lee (3): Bluetooth: MGMT: remove the mesh walk from the socket destructor Bluetooth: MGMT: protect hdev->mesh_pending with hdev->lock Bluetooth: MGMT: reference-count struct mgmt_mesh_tx include/net/bluetooth/bluetooth.h | 1 - net/bluetooth/hci_sock.c | 1 - net/bluetooth/mgmt.c | 72 ++++++++++++++++++++++++--------------- net/bluetooth/mgmt_util.c | 31 +++++++++++++++-- net/bluetooth/mgmt_util.h | 3 ++ 5 files changed, 76 insertions(+), 32 deletions(-) -- 2.50.1 (Apple Git-155)