From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f70.google.com (mail-oo1-f70.google.com [209.85.161.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D84C33E37A for ; Sun, 8 Feb 2026 20:03:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.70 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770581013; cv=none; b=PuVTwdqLqQEQjoVnZtFK6rc0VsNkhurwKmJIXrMgKssB8QqDkHN/tOhxVQss3e3Z/bT3fVw/NJTWfmJ+Idh/hj1hBMjXrhDF92pPpIEYh+2T/HFMmvQWap5DMeHUUZ+0ceJFIfzF0XpUqe5AAHH/+nfd74opfn9pS3nERG2L0cg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770581013; c=relaxed/simple; bh=TYdHDj9Y6G0MMZGhyyHg2ZEtAAEsYCNlPttgJIIK/Og=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To:Cc: Content-Type; b=sbGPc9b7IGbBFP/L0RyFD53l7WfBEcmTKCf9qGCCvJ9rE4L1mLD99EuXoUlM08mEe0NiUuU4X71jDIBp1Iv+uZNm9mEKgaQcdx3cZxHcRbO0K0NaiA4DRthS02Mzi5Ht9khvkK4S+rtSYN+kkn4nc2JtAdKSNGPkZoOC38mebsA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.161.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oo1-f70.google.com with SMTP id 006d021491bc7-66cc1133633so5311495eaf.1 for ; Sun, 08 Feb 2026 12:03:32 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770581012; x=1771185812; h=cc:to:from:subject:message-id:in-reply-to:date:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=2b+h5SIvhGtwwyx7Qj2HU3VbrKkijUTllhD2uTYZIX4=; b=YPNAcMfC1YIVno5f2pA1wa2xCu9CI+Hie/IvmHGd6GopEiBzuCmgwWlYLF9zjGnBQu 2AQgns4BGqEBdUgn4sgioQhCvE+j5N7tCIvSlsskfGLKtp0raIUCozQb0ZuDZxwsIw5U ua0Z4oFRS5W092IjH/cv7Fn/jt8kWojhoVx7TK+0P44/v2V+HZsLVH1AXKtyCU5mPYY4 BAcNaTpRxUNaW/Jbp1Ptf+92oPfmBpw7jqHZwCzlkabFHKYDWbLqqyHnCajoNugQSgQG Fs9ZQAPuG5G+ivlVL1BFNMKnorTN9kNf/5Cnoo9hJx/YVn7CceFLizIJhY2athZ/kiQH Yqow== X-Forwarded-Encrypted: i=1; AJvYcCVmnEc1hkNW1X18aeTsKWV7AaxNymvL6bsy9pNNNQAfBStRmlJ4Rzj/dOj9F82vFalVrknj6SC6WujyU0I=@vger.kernel.org X-Gm-Message-State: AOJu0Yzcu0qSazwPoLHwi737cvEsevcvEpwXRg5jJm78+mPvqYCpqCj5 Npahq8XfZsnbJdVRojUPIVwbr2ZgrVFjLfk2Z0zsrrtSaJQUIBkW9JZljUdRcAXvUJz5muIUJIO h9qF6cjAcz1NLV/rMtv87LDx4xH7rJK04QuxETLgWzzHfmFzWlTk9hmHck6I= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:1614:b0:668:d715:108f with SMTP id 006d021491bc7-66d0d20481bmr3694392eaf.73.1770581012130; Sun, 08 Feb 2026 12:03:32 -0800 (PST) Date: Sun, 08 Feb 2026 12:03:32 -0800 In-Reply-To: X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6988ec14.050a0220.1ad825.0006.GAE@google.com> Subject: Re: #syz test From: syzbot To: youjingxiaogao2@gmail.com Cc: youjingxiaogao2@gmail.com, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" > #syz test git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git > master > > From d5153b84b90fa80ee0d041d1bd28bd465f7913ec Mon Sep 17 00:00:00 2001 > From: Masahiro Kawada > Date: Mon, 9 Feb 2026 04:47:14 +0900 > Subject: [PATCH] Bluetooth: fix use-after-free in hci_conn_drop > > Fix a use-after-free in hci_conn_drop triggered via hci_cmd_sync_work. > > In hci_conn_del(), hci_cmd_sync_dequeue() is called after > hci_conn_cleanup() which may have already freed the conn pointer. > Fix by moving the dequeue before cleanup. > > Additionally, le_read_features_complete() calls hci_conn_drop(conn) > without checking whether conn is still valid. When > hci_le_read_remote_features_sync() blocks waiting for an HCI event, > another thread can free conn through hci_conn_del(). Fix by adding > a hci_conn_valid() check before calling hci_conn_drop(). > > Reported-by: syzbot+3609b9b48e68e1fe47fd@syzkaller.appspotmail.com > Closes: https://syzkaller.appspot.com/bug?extid=3609b9b48e68e1fe47fd > Signed-off-by: Masahiro Kawada > --- > net/bluetooth/hci_conn.c | 6 +++--- > net/bluetooth/hci_sync.c | 3 +++ > 2 files changed, 6 insertions(+), 3 deletions(-) > > diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c > index 0795818963a..aa3607327ad 100644 > --- a/net/bluetooth/hci_conn.c > +++ b/net/bluetooth/hci_conn.c > @@ -1232,15 +1232,15 @@ void hci_conn_del(struct hci_conn *conn) > skb_queue_purge(&conn->data_q); > skb_queue_purge(&conn->tx_q.queue); > > + /* Dequeue callbacks using connection pointer as data */ > + hci_cmd_sync_dequeue(hdev, NULL, conn, NULL); > + > /* Remove the connection from the list and cleanup its remaining > * state. This is a separate function since for some cases like > * BT_CONNECT_SCAN we *only* want the cleanup part without the > * rest of hci_conn_del. > */ > hci_conn_cleanup(conn); > - > - /* Dequeue callbacks using connection pointer as data */ > - hci_cmd_sync_dequeue(hdev, NULL, conn, NULL); > } > > struct hci_dev *hci_get_route(bdaddr_t *dst, bdaddr_t *src, uint8_t > src_type) > diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c > index f04a90bce4a..f31086c187f 100644 > --- a/net/bluetooth/hci_sync.c > +++ b/net/bluetooth/hci_sync.c > @@ -7371,6 +7371,9 @@ static void le_read_features_complete(struct hci_dev > *hdev, void *data, int err) > if (err == -ECANCELED) > return; > > + if (!hci_conn_valid(hdev, conn)) > + return; > + > hci_conn_drop(conn); > } > > -- > 2.43.0 Command #2: I've failed to parse your command. Did you perhaps forget to provide the branch name, or added an extra ':'? Please use one of the two supported formats: 1. #syz test 2. #syz test: repo branch-or-commit-hash Note the lack of ':' in option 1.