Sungwoo Kim
9fdc79b571
Bluetooth: L2CAP: Fix u8 overflow
[ Upstream commit bcd70260ef56e0aee8a4fc6cd214a419900b0765 ]
By keep sending L2CAP_CONF_REQ packets, chan->num_conf_rsp increases
multiple times and eventually it will wrap around the maximum number
(i.e., 255).
This patch prevents this by adding a boundary check with
L2CAP_MAX_CONF_RSP
Btmon log:
Bluetooth monitor ver 5.64
= Note: Linux version 6.1.0-rc2 (x86_64) 0.264594
= Note: Bluetooth subsystem version 2.22 0.264636
@ MGMT Open: btmon (privileged) version 1.22 {0x0001} 0.272191
= New Index: 00:00:00:00:00:00 (Primary,Virtual,hci0) [hci0] 13.877604
@ RAW Open: 9496 (privileged) version 2.22 {0x0002} 13.890741
= Open Index: 00:00:00:00:00:00 [hci0] 13.900426
(...)
> ACL Data RX: Handle 200 flags 0x00 dlen 1033 #32 [hci0] 14.273106
invalid packet size (12 != 1033)
08 00 01 00 02 01 04 00 01 10 ff ff ............
> ACL Data RX: Handle 200 flags 0x00 dlen 1547 #33 [hci0] 14.273561
invalid packet size (14 != 1547)
0a 00 01 00 04 01 06 00 40 00 00 00 00 00 ........@.....
> ACL Data RX: Handle 200 flags 0x00 dlen 2061 #34 [hci0] 14.274390
invalid packet size (16 != 2061)
0c 00 01 00 04 01 08 00 40 00 00 00 00 00 00 04 ........@.......
> ACL Data RX: Handle 200 flags 0x00 dlen 2061 #35 [hci0] 14.274932
invalid packet size (16 != 2061)
0c 00 01 00 04 01 08 00 40 00 00 00 07 00 03 00 ........@.......
= bluetoothd: Bluetooth daemon 5.43 14.401828
> ACL Data RX: Handle 200 flags 0x00 dlen 1033 #36 [hci0] 14.275753
invalid packet size (12 != 1033)
08 00 01 00 04 01 04 00 40 00 00 00 ........@...
Signed-off-by: Sungwoo Kim <iam@sung-woo.kim>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2023-01-18 11:40:49 +01:00 |
| .. |
|
6lowpan
|
|
|
|
9p
|
9p/xen: check logical size for buffer size
|
2022-12-14 11:30:41 +01:00 |
|
802
|
|
|
|
8021q
|
|
|
|
appletalk
|
|
|
|
atm
|
net/atm: fix proc_mpc_write incorrect return value
|
2022-10-29 10:20:35 +02:00 |
|
ax25
|
ax25: Fix UAF bugs in ax25 timers
|
2022-04-20 09:19:40 +02:00 |
|
batman-adv
|
batman-adv: Don't skb_split skbuffs with frag_list
|
2022-05-18 09:47:24 +02:00 |
|
bluetooth
|
Bluetooth: L2CAP: Fix u8 overflow
|
2023-01-18 11:40:49 +01:00 |
|
bpf
|
bpf, test_run: Fix alignment problem in bpf_prog_test_run_skb()
|
2022-11-25 17:42:21 +01:00 |
|
bpfilter
|
|
|
|
bridge
|
netfilter: ebtables: fix memory leak when blob is malformed
|
2022-09-28 11:04:07 +02:00 |
|
caif
|
net: caif: fix double disconnect client in chnl_net_open()
|
2022-11-25 17:42:15 +01:00 |
|
can
|
can: af_can: fix NULL pointer dereference in can_rcv_filter
|
2022-12-14 11:30:44 +01:00 |
|
ceph
|
|
|
|
core
|
net: bpf: Allow TC programs to call BPF_FUNC_skb_change_head
|
2022-12-19 12:24:15 +01:00 |
|
dcb
|
|
|
|
dccp
|
dccp/tcp: Reset saddr on failure after inet6?_hash_connect().
|
2022-12-08 11:22:59 +01:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
net: dsa: ksz: Check return value
|
2022-12-14 11:30:45 +01:00 |
|
ethernet
|
|
|
|
hsr
|
net: hsr: Fix potential use-after-free
|
2022-12-08 11:23:03 +01:00 |
|
ieee802154
|
net: ieee802154: fix error return code in dgram_bind()
|
2022-11-03 23:56:54 +09:00 |
|
ife
|
|
|
|
ipv4
|
ipv4: Fix incorrect route flushing when table ID 0 is used
|
2022-12-14 11:30:47 +01:00 |
|
ipv6
|
ipv6: avoid use-after-free in ip6_fragment()
|
2022-12-14 11:30:48 +01:00 |
|
iucv
|
|
|
|
kcm
|
kcm: close race conditions on sk_receive_queue
|
2022-11-25 17:42:21 +01:00 |
|
key
|
af_key: Fix send_acquire race with pfkey_register
|
2022-12-08 11:22:57 +01:00 |
|
l2tp
|
ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg
|
2022-06-22 14:11:21 +02:00 |
|
l3mdev
|
l3mdev: l3mdev_master_upper_ifindex_by_index_rcu should be using netdev_master_upper_dev_get_rcu
|
2022-04-27 13:50:47 +02:00 |
|
lapb
|
|
|
|
llc
|
|
|
|
mac80211
|
wifi: mac80211: Fix ack frame idr leak when mesh has no route
|
2022-12-08 11:22:57 +01:00 |
|
mac802154
|
mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add()
|
2022-12-14 11:30:45 +01:00 |
|
mpls
|
|
|
|
ncsi
|
|
|
|
netfilter
|
ipvs: fix WARNING in ip_vs_app_net_cleanup()
|
2022-11-10 17:57:51 +01:00 |
|
netlabel
|
netlabel: fix out-of-bounds memory accesses
|
2022-04-15 14:18:35 +02:00 |
|
netlink
|
netlink: do not reset transport header in netlink_recvmsg()
|
2022-05-18 09:47:25 +02:00 |
|
netrom
|
|
|
|
nfc
|
NFC: nci: Bounds check struct nfc_target arrays
|
2022-12-14 11:30:46 +01:00 |
|
nsh
|
|
|
|
openvswitch
|
openvswitch: switch from WARN to pr_warn
|
2022-11-03 23:56:56 +09:00 |
|
packet
|
packet: do not set TP_STATUS_CSUM_VALID on CHECKSUM_COMPLETE
|
2022-12-08 11:23:03 +01:00 |
|
phonet
|
|
|
|
psample
|
|
|
|
qrtr
|
|
|
|
rds
|
net: rds: don't hold sock lock when cancelling work from rds_tcp_reset_callbacks()
|
2022-10-26 13:22:26 +02:00 |
|
rfkill
|
|
|
|
rose
|
rose: Fix NULL pointer dereference in rose_send_frame()
|
2022-11-10 17:57:51 +01:00 |
|
rxrpc
|
rxrpc: Fix calc of resend age
|
2022-09-28 11:03:58 +02:00 |
|
sched
|
net: sched: Fix use after free in red_enqueue()
|
2022-11-10 17:57:50 +01:00 |
|
sctp
|
sctp: fix memory leak in sctp_stream_outq_migrate()
|
2022-12-08 11:23:03 +01:00 |
|
smc
|
net/smc: Remove redundant refcount increase
|
2022-09-15 12:04:50 +02:00 |
|
strparser
|
|
|
|
sunrpc
|
SUNRPC: RPC level errors should set task->tk_rpc_status
|
2022-09-05 10:27:40 +02:00 |
|
switchdev
|
|
|
|
tipc
|
tipc: Fix potential OOB in tipc_link_proto_rcv()
|
2022-12-14 11:30:47 +01:00 |
|
tls
|
net/tls: Fix race in TLS device down flow
|
2022-07-29 17:14:12 +02:00 |
|
unix
|
af_unix: Get user_ns from in_skb in unix_diag_get_exact().
|
2022-12-14 11:30:44 +01:00 |
|
vmw_vsock
|
vhost/vsock: Use kvmalloc/kvfree for larger packets.
|
2022-10-26 13:22:25 +02:00 |
|
wimax
|
|
|
|
wireless
|
wifi: cfg80211: fix buffer overflow in elem comparison
|
2022-12-08 11:23:03 +01:00 |
|
x25
|
net/x25: Fix skb leak in x25_lapb_receive_frame()
|
2022-11-25 17:42:16 +01:00 |
|
xdp
|
|
|
|
xfrm
|
xfrm: Update ipcomp_scratches with NULL when freed
|
2022-10-26 13:22:49 +02:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
net: Fix a data-race around sysctl_somaxconn.
|
2022-09-05 10:27:42 +02:00 |
|
sysctl_net.c
|
|
|