Luiz Augusto von Dentz
7d6f9cb24d
Bluetooth: L2CAP: Fix user-after-free
[ Upstream commit 35fcbc4243aad7e7d020b7c1dfb14bb888b20a4f ]
This uses l2cap_chan_hold_unless_zero() after calling
__l2cap_get_chan_blah() to prevent the following trace:
Bluetooth: l2cap_core.c:static void l2cap_chan_destroy(struct kref
*kref)
Bluetooth: chan 0000000023c4974d
Bluetooth: parent 00000000ae861c08
==================================================================
BUG: KASAN: use-after-free in __mutex_waiter_is_first
kernel/locking/mutex.c:191 [inline]
BUG: KASAN: use-after-free in __mutex_lock_common
kernel/locking/mutex.c:671 [inline]
BUG: KASAN: use-after-free in __mutex_lock+0x278/0x400
kernel/locking/mutex.c:729
Read of size 8 at addr ffff888006a49b08 by task kworker/u3:2/389
Link: https://lore.kernel.org/lkml/20220622082716.478486-1-lee.jones@linaro.org
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sungwoo Kim <iam@sung-woo.kim>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2022-10-26 13:22:51 +02:00 |
| .. |
|
6lowpan
|
6lowpan: iphc: Fix an off-by-one check of array index
|
2021-09-15 09:47:31 +02:00 |
|
9p
|
net/9p: Initialize the iounit field during fid creation
|
2022-08-25 11:18:17 +02:00 |
|
802
|
|
|
|
8021q
|
net: vlan: fix underflow for the real_dev refcnt
|
2021-12-01 09:23:34 +01:00 |
|
appletalk
|
|
|
|
atm
|
|
|
|
ax25
|
ax25: Fix UAF bugs in ax25 timers
|
2022-04-20 09:19:40 +02:00 |
|
batman-adv
|
batman-adv: Don't skb_split skbuffs with frag_list
|
2022-05-18 09:47:24 +02:00 |
|
bluetooth
|
Bluetooth: L2CAP: Fix user-after-free
|
2022-10-26 13:22:51 +02:00 |
|
bpf
|
bpf: Don't redirect packets with invalid pkt_len
|
2022-09-05 10:27:46 +02:00 |
|
bpfilter
|
|
|
|
bridge
|
netfilter: ebtables: fix memory leak when blob is malformed
|
2022-09-28 11:04:07 +02:00 |
|
caif
|
net-caif: avoid user-triggerable WARN_ON(1)
|
2021-09-22 12:26:40 +02:00 |
|
can
|
can: bcm: check the result of can_send() in bcm_can_tx()
|
2022-10-26 13:22:50 +02:00 |
|
ceph
|
|
|
|
core
|
net: If sock is dead don't access sock's sk_wq in sk_stream_wait_memory
|
2022-10-26 13:22:51 +02:00 |
|
dcb
|
net: dcb: disable softirqs in dcbnl_flush_dev()
|
2022-03-08 19:07:51 +01:00 |
|
dccp
|
dccp: put dccp_qpolicy_full() and dccp_qpolicy_push() in the same lock
|
2022-08-25 11:17:49 +02:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
net: dsa: Add missing of_node_put() in dsa_port_parse_of
|
2022-03-23 09:12:07 +01:00 |
|
ethernet
|
|
|
|
hsr
|
|
|
|
ieee802154
|
net/ieee802154: reject zero-sized raw_sendmsg()
|
2022-10-26 13:22:26 +02:00 |
|
ife
|
|
|
|
ipv4
|
tcp: annotate data-race around tcp_md5sig_pool_populated
|
2022-10-26 13:22:48 +02:00 |
|
ipv6
|
netfilter: nft_fib: Fix for rpath check with VRF devices
|
2022-10-26 13:22:25 +02:00 |
|
iucv
|
|
|
|
kcm
|
kcm: fix strp_init() order and cleanup
|
2022-09-15 12:04:50 +02:00 |
|
key
|
af_key: Do not call xfrm_probe_algs in parallel
|
2022-09-05 10:27:40 +02:00 |
|
l2tp
|
ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg
|
2022-06-22 14:11:21 +02:00 |
|
l3mdev
|
l3mdev: l3mdev_master_upper_ifindex_by_index_rcu should be using netdev_master_upper_dev_get_rcu
|
2022-04-27 13:50:47 +02:00 |
|
lapb
|
|
|
|
llc
|
llc: only change llc->dev when bind() succeeds
|
2022-03-28 08:46:48 +02:00 |
|
mac80211
|
wifi: mac80211: allow bw change during channel switch in mesh
|
2022-10-26 13:22:22 +02:00 |
|
mac802154
|
net: mac802154: Fix a condition in the receive path
|
2022-09-15 12:04:53 +02:00 |
|
mpls
|
net: mpls: Fix notifications when deleting a device
|
2021-12-08 09:01:12 +01:00 |
|
ncsi
|
net/ncsi: check for error return from call to nla_put_u32
|
2022-01-05 12:37:45 +01:00 |
|
netfilter
|
netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find()
|
2022-09-28 11:04:05 +02:00 |
|
netlabel
|
netlabel: fix out-of-bounds memory accesses
|
2022-04-15 14:18:35 +02:00 |
|
netlink
|
netlink: do not reset transport header in netlink_recvmsg()
|
2022-05-18 09:47:25 +02:00 |
|
netrom
|
|
|
|
nfc
|
NFC: NULL out the dev->rfkill to prevent UAF
|
2022-06-14 18:11:33 +02:00 |
|
nsh
|
|
|
|
openvswitch
|
openvswitch: Fix overreporting of drops in dropwatch
|
2022-10-26 13:22:48 +02:00 |
|
packet
|
net/af_packet: check len when min_header_len equals to 0
|
2022-09-05 10:27:48 +02:00 |
|
phonet
|
phonet: refcount leak in pep_sock_accep
|
2022-01-11 15:23:33 +01:00 |
|
psample
|
|
|
|
qrtr
|
|
|
|
rds
|
net: rds: don't hold sock lock when cancelling work from rds_tcp_reset_callbacks()
|
2022-10-26 13:22:26 +02:00 |
|
rfkill
|
|
|
|
rose
|
rose: check NULL rose_loopback_neigh->loopback
|
2022-09-05 10:27:40 +02:00 |
|
rxrpc
|
rxrpc: Fix calc of resend age
|
2022-09-28 11:03:58 +02:00 |
|
sched
|
net: sched: fix possible refcount leak in tc_new_tfilter()
|
2022-09-28 11:04:07 +02:00 |
|
sctp
|
sctp: handle the error returned from sctp_auth_asoc_init_active_key
|
2022-10-26 13:22:26 +02:00 |
|
smc
|
net/smc: Remove redundant refcount increase
|
2022-09-15 12:04:50 +02:00 |
|
strparser
|
bpf: sockmap, strparser, and tls are reusing qdisc_skb_cb and colliding
|
2021-11-17 09:48:48 +01:00 |
|
sunrpc
|
SUNRPC: RPC level errors should set task->tk_rpc_status
|
2022-09-05 10:27:40 +02:00 |
|
switchdev
|
net: switchdev: do not propagate bridge updates across bridges
|
2021-10-27 09:54:24 +02:00 |
|
tipc
|
tipc: fix shift wrapping bug in map_get()
|
2022-09-15 12:04:55 +02:00 |
|
tls
|
net/tls: Fix race in TLS device down flow
|
2022-07-29 17:14:12 +02:00 |
|
unix
|
af_unix: Fix a data-race in unix_dgram_peer_wake_me().
|
2022-06-14 18:11:57 +02:00 |
|
vmw_vsock
|
vhost/vsock: Use kvmalloc/kvfree for larger packets.
|
2022-10-26 13:22:25 +02:00 |
|
wimax
|
|
|
|
wireless
|
wifi: cfg80211: update hidden BSSes to avoid WARN_ON
|
2022-10-15 07:54:41 +02:00 |
|
x25
|
net/x25: Fix null-ptr-deref caused by x25_disconnect
|
2022-04-15 14:18:21 +02:00 |
|
xdp
|
Revert "xsk: Do not sleep in poll() when need_wakeup set"
|
2021-12-22 09:29:40 +01:00 |
|
xfrm
|
xfrm: Update ipcomp_scratches with NULL when freed
|
2022-10-26 13:22:49 +02:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
net: Fix a data-race around sysctl_somaxconn.
|
2022-09-05 10:27:42 +02:00 |
|
sysctl_net.c
|
|
|