From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CD8702F12CE for ; Sat, 22 Aug 2026 16:43:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787417037; cv=none; b=PZ2gzEc6PDY2cCd05Sb5CHf+e7QGrS9aCj/NQ/rtfu2KewnBPW+8QcHaxuJEZllWjHMb6RMa6LgNCXu3pTLbnpsO4KiB0ixUc12jgTIWvGuRV9itIkHN3n7cYc2SbLOBHdbel5Fe8fGepSbrR0Z9r7ut+c1RaLolrcWUNNG+p1s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787417037; c=relaxed/simple; bh=mwQAzqbsY34MJJJ//jyRmVtC88MoO19pi+kZvnQm+bw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dylqLpz9uyGMB6qoAi//rVv1bYREivSRUlSLmACbO6UidWXIbJRGKKt1kMgloATvv27qOR4SPO4AhkoQJirwIZVuD9fs82jV3zIrjVl7xPXjB5fcveSua2t7gkfNtXh4qa1VP9NZgvDJbxm5xbDFliH2IILD9HLjFSqFsUu2k1E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BKSGbup5; arc=none smtp.client-ip=209.85.216.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BKSGbup5" Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-392af6bda98so239513a91.0 for ; Sat, 22 Aug 2026 09:43:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787417034; x=1788021834; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=QqQxHcVBopXEQ06zq5Skt24LbTPkQa3qzjdve2v5WwY=; b=BKSGbup5VgXRKacbKtm4fajZg+qXV8xw79abf67R6tZehbRksAP1JTLJuejQhjJqmY 5muyjXzgpAEfo86gRamCsNtC7ldeNmL1NDIzY6vYIths5rt9w9fLRZLFVkZMmF1iDWKs a8dKU/+3ubFFgrzSh3ugTSAXS7Z060Q89ibH4dT7GgAyTsrbXnNZt2CuRW9Kx8J8EnGa u5iP6XKtBsO3Pd3lhKOVlMM0qyJSX6KSJo+9MAtX6FUktMOa2gc3ns5MJcsgaMPzaA9d 5vZcVoqhKXrTW7hauH7hB7EEXRT3wJh0rnmdyBD4Hp+e4aplrY/P0vNh1FHkkZPtUc02 yjTg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787417034; x=1788021834; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QqQxHcVBopXEQ06zq5Skt24LbTPkQa3qzjdve2v5WwY=; b=nGxABvLcCLOuHNRKYz2fI6oPh296WTjzpAMLuRyQEmkXGHR3sqxOejNjyMugABIx3Y BmXPpnV75eaXQqnUtblhYHbzx0c8PbmHK+ii3yoY9VD2cT/oQZPGqiL9zztvW1yKZcrQ SkSh2aAP+LVNusqWwIpCsOK5jVPJEgq9hrYDa0rkHk5EFiB1Vho6oevAimhU5whTLGGu /SdaIkeiJYQTxG7rIlhgP7SrH7kFEAkBi48A6513X41yfsJPdgfTd/qJeijrEWtxuFLr ZmQQE7uGRFaABV/b4XT2nEYZRLNg0hG+EF721bYmt1Lm9lUmSFDhsmI3OUjhVdq9WHgs 2gMw== X-Forwarded-Encrypted: i=1; AHgh+RpnTNO6FuMm8hA/Ufw/7zH1onKy+UJ5VaJAT8rq7AKl1taTEzm5hOcbJQvNV28itAkYuglOyJXgP9JgWH0=@vger.kernel.org X-Gm-Message-State: AFuF++mi6Lr6pa4ZzXk8mExlsH+jxz/c+DERaRrxRCFw9zbPL+gbyVd1 9hPlY9iV91JM7tIwYbnl05Qu6tSsB54tNZdhU/xN0tVTc1xoWPmqanXK X-Gm-Gg: AR+sD11CxpF8c5jfXcTe5aCBHaEug5YpajsZ7dxyJUz924dhXWUFUS2eOWYPK54voyC WryTrM81i1gLQLoGn2sYFEzj9jjJcdIdCJ3WS0eTggx/jHhhB0KapOG9XoVUipcCUPuGGjG+sic E8uopIl588ZPetmK9Z0jSGbVKdaucmekD7YPTvxpNGvo0dal7C04qJ3hl14BHq0XvyRrb99rBjf mzyyAcTSQftbEgCa79SsYinsKidZ0X1ylUZ3Wx+pUdN8YF/F2mc6kejT/uGapzpD8zDXKn8hed2 EApXlVR6SfSHI6jWyj3yINeackWNv2kt2K3+ZWkF1h/74m4JFk3nMPphz27gzia5AC26KSfctwR 8kSKohEowCMU12mhc6mY41lEcgQcJrInGAeeTpUTrM1upuU5OdnxOiHB/8NP4O4DVzJ6nUhysk0 mTdLv7JZQbNn14ikVed9dxXigQJGyT8vfTLU8rm7LiWkMUXV+Ee+HPa3CRKDQhT3F2s/0BIOFTF SMSFlTWF7vfVQ9xi0SZre17ps+AEw/N/IYr4jewDdGSSRwxkea55PY= X-Received: by 2002:a17:903:1b65:b0:2d5:3f09:4126 with SMTP id d9443c01a7336-2d64b13195dmr134623425ad.4.1787417033874; Sat, 22 Aug 2026 09:43:53 -0700 (PDT) Received: from localhost.localdomain (45.78.65.84.16clouds.com. [45.78.65.84]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327f90c0dd3sm8622622eec.7.2026.08.22.09.43.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 22 Aug 2026 09:43:53 -0700 (PDT) From: Chengfeng Ye To: Marcel Holtmann , Luiz Augusto von Dentz , Kees Cook , Jakub Kicinski , Chengfeng Ye , Ali Ahmet Memis , Tim Bird , SeungJu Cheon , Gustavo Padovan , Dean Jenkins Cc: linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] Bluetooth: RFCOMM: serialize security confirmation handling Date: Sun, 23 Aug 2026 00:43:41 +0800 Message-ID: <20260822164341.3750491-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit rfcomm_security_cfm() looks up a session on session_list and then walks its DLC list without holding rfcomm_mutex. Since RFCOMM session teardown uses rfcomm_mutex, krfcommd can close and free the same session and DLCs concurrently: hci_rx_work krfcommd ----------- --------- rfcomm_session_get() rfcomm_lock() rfcomm_session_close() rfcomm_dlc_unlink() rfcomm_session_del() kfree(s) rfcomm_unlock() walk s->dlcs The callback can then read a freed session list head and touch freed DLCs while updating their flags or timers. Serialize the session lookup and DLC traversal in rfcomm_security_cfm() with rfcomm_mutex. This matches the existing RFCOMM session lifetime rules and prevents concurrent rfcomm_session_del() / rfcomm_dlc_unlink() from tearing the objects down while the callback is using them. KASAN reported: BUG: KASAN: slab-use-after-free in rfcomm_security_cfm+0x41c/0x440 Read of size 8 at addr ffff888111fb3960 by task kworker/u17:1/89 Workqueue: hci0 hci_rx_work Call Trace: rfcomm_security_cfm+0x41c/0x440 hci_encrypt_cfm+0x139/0x590 hci_encrypt_change_evt+0x37b/0xc40 hci_event_packet+0x71b/0xb20 hci_rx_work+0x293/0x730 Allocated by task 69: rfcomm_session_add+0x9e/0x2f0 rfcomm_run+0x44b/0x41e0 Freed by task 69: kfree+0x131/0x3c0 rfcomm_session_del+0x188/0x220 rfcomm_run+0x1985/0x41e0 Fixes: 08c30aca9e698faddebd34f81e1196295f9dc063 ("Bluetooth: Remove RFCOMM session refcnt") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- net/bluetooth/rfcomm/core.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/net/bluetooth/rfcomm/core.c b/net/bluetooth/rfcomm/core.c index 9cdfea666a2c..5d150e8623d5 100644 --- a/net/bluetooth/rfcomm/core.c +++ b/net/bluetooth/rfcomm/core.c @@ -2213,9 +2213,13 @@ static void rfcomm_security_cfm(struct hci_conn *conn, u8 status, u8 encrypt) BT_DBG("conn %p status 0x%02x encrypt 0x%02x", conn, status, encrypt); + rfcomm_lock(); + s = rfcomm_session_get(&conn->hdev->bdaddr, &conn->dst); - if (!s) + if (!s) { + rfcomm_unlock(); return; + } list_for_each_entry_safe(d, n, &s->dlcs, list) { if (test_and_clear_bit(RFCOMM_SEC_PENDING, &d->flags)) { @@ -2247,6 +2251,8 @@ static void rfcomm_security_cfm(struct hci_conn *conn, u8 status, u8 encrypt) set_bit(RFCOMM_AUTH_REJECT, &d->flags); } + rfcomm_unlock(); + rfcomm_schedule(); } -- 2.43.0