mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Cen Zhang <zzzccc427@gmail.com>
To: marcel@holtmann.org, luiz.dentz@gmail.com
Cc: linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org,
	baijiaju1990@gmail.com, jjzuming@gmail.com, zzzccc427@gmail.com
Subject: [PATCH] Bluetooth: MSFT: Serialize handle map cleanup with event processing
Date: Thu,  8 Oct 2026 14:03:55 +0800	[thread overview]
Message-ID: <pm-bluetooth-objects-candidate-0242-v6-e48e08db5265b66aeda9@gmail.com> (raw)

MSFT monitor handle mappings must remain valid while vendor events look
up and use them under hdev->lock. msft_do_close() removes and frees the
mappings without that lock.

hci_dev_close_sync() clears HCI_UP and drains the RX workqueue before
MSFT cleanup. However, a transport callback that already passed
hci_recv_frame()'s state check can queue a vendor event after the drain
returns, if no earlier shutdown callback has quiesced reception. The
driver close callback runs after MSFT cleanup, so event processing can
overlap the unlocked removal. msft_monitor_device_evt() can then
traverse freed list entries or read handle_data->mgmt_handle after it is
freed.

Take hdev->lock while resetting monitor states and removing handle
mappings in msft_do_close(), as normal monitor cancellation already
does. An active event reader then finishes before its mapping is freed,
and later lookups see an empty handle map.

An instrumented kernel produced the following report:

    BUG: KASAN: slab-use-after-free in msft_vendor_evt+0x1906/0x1990
        [Thu Oct  1 15:01:51 2026] Read of size 2 at addr ffff888104df3602
    by task kworker/u17:2/502
    [...]
    [Thu Oct  1 15:01:51 2026] Workqueue: hci0 hci_rx_work
    [Thu Oct  1 15:01:51 2026] Call Trace:
    [...]
    [Thu Oct  1 15:01:51 2026]  msft_vendor_evt+0x1906/0x1990
    [Thu Oct  1 15:01:51 2026]  hci_vendor_evt+0x6f/0x90
    [Thu Oct  1 15:01:51 2026]  hci_event_packet+0x894/0xc70
    [...]
    [Thu Oct  1 15:01:51 2026]  hci_rx_work+0x3f8/0xfa0
    [...]
    [Thu Oct  1 15:01:51 2026] Freed by task 499:
    [...]
    [Thu Oct  1 15:01:51 2026]  kfree+0x307/0x580
    [Thu Oct  1 15:01:51 2026]  msft_do_close+0x238/0x750
    [Thu Oct  1 15:01:51 2026]  hci_dev_close_sync+0x546/0x1380
    [...]
        [Thu Oct  1 15:01:51 2026] The buggy address belongs to the object
    at ffff888104df3600
                                                                which
                                belongs to the cache kmalloc-32 of size 32
        [Thu Oct  1 15:01:51 2026] The buggy address is located 2 bytes
    inside of
                                                                freed
                                32-byte region [ffff888104df3600,
                                ffff888104df3620)
    [...]

Fixes: 145373cb1b1f ("Bluetooth: Add framework for Microsoft vendor extension")
Assisted-by: LLM
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
---
diff --git a/net/bluetooth/msft.c b/net/bluetooth/msft.c
index d9dd722db3..667c9951c3 100644
--- a/net/bluetooth/msft.c
+++ b/net/bluetooth/msft.c
@@ -681,6 +681,8 @@ void msft_do_close(struct hci_dev *hdev)
 
 	bt_dev_dbg(hdev, "Cleanup of MSFT extension");
 
+	hci_dev_lock(hdev);
+
 	/* The controller will silently remove all monitors on power off.
 	 * Therefore, remove handle_data mapping and reset monitor state.
 	 */
@@ -695,6 +697,8 @@ void msft_do_close(struct hci_dev *hdev)
 		kfree(handle_data);
 	}
 
+	hci_dev_unlock(hdev);
+
 	mutex_lock(&msft->filter_lock);
 	list_for_each_entry_safe(address_filter, n, &msft->address_filters,
 				 list) {

                 reply	other threads:[~2026-10-08  6:04 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=pm-bluetooth-objects-candidate-0242-v6-e48e08db5265b66aeda9@gmail.com \
    --to=zzzccc427@gmail.com \
    --cc=baijiaju1990@gmail.com \
    --cc=jjzuming@gmail.com \
    --cc=linux-bluetooth@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luiz.dentz@gmail.com \
    --cc=marcel@holtmann.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®