[SRU][N][PATCH 1/1] Bluetooth: MGMT: Fix possible deadlocks
Cengiz Can
cengiz.can at canonical.com
Mon Sep 7 17:08:49 UTC 2026
From: Luiz Augusto von Dentz <luiz.von.dentz at intel.com>
This fixes possible deadlocks like the following caused by
hci_cmd_sync_dequeue causing the destroy function to run:
INFO: task kworker/u19:0:143 blocked for more than 120 seconds.
Tainted: G W O 6.8.0-2024-03-19-intel-next-iLS-24ww14 #1
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:kworker/u19:0 state:D stack:0 pid:143 tgid:143 ppid:2 flags:0x00004000
Workqueue: hci0 hci_cmd_sync_work [bluetooth]
Call Trace:
<TASK>
__schedule+0x374/0xaf0
schedule+0x3c/0xf0
schedule_preempt_disabled+0x1c/0x30
__mutex_lock.constprop.0+0x3ef/0x7a0
__mutex_lock_slowpath+0x13/0x20
mutex_lock+0x3c/0x50
mgmt_set_connectable_complete+0xa4/0x150 [bluetooth]
? kfree+0x211/0x2a0
hci_cmd_sync_dequeue+0xae/0x130 [bluetooth]
? __pfx_cmd_complete_rsp+0x10/0x10 [bluetooth]
cmd_complete_rsp+0x26/0x80 [bluetooth]
mgmt_pending_foreach+0x4d/0x70 [bluetooth]
__mgmt_power_off+0x8d/0x180 [bluetooth]
? _raw_spin_unlock_irq+0x23/0x40
hci_dev_close_sync+0x445/0x5b0 [bluetooth]
hci_set_powered_sync+0x149/0x250 [bluetooth]
set_powered_sync+0x24/0x60 [bluetooth]
hci_cmd_sync_work+0x90/0x150 [bluetooth]
process_one_work+0x13e/0x300
worker_thread+0x2f7/0x420
? __pfx_worker_thread+0x10/0x10
kthread+0x107/0x140
? __pfx_kthread+0x10/0x10
ret_from_fork+0x3d/0x60
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1b/0x30
</TASK>
Tested-by: Kiran K <kiran.k at intel.com>
Fixes: f53e1c9c726d ("Bluetooth: MGMT: Fix possible crash on mgmt_index_removed")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz at intel.com>
(backported from commit a66dfaf18fd61bb75ef8cee83db46b2aadf153d0)
[bot_kybele: Tree already had this fix for listed cmds via the refactored idiom
"err == -ECANCELED || !mgmt_pending_valid(hdev, cmd)"; kept that for the
pending_find hunks. For set_default_phy_complete and
read_local_oob_ext_data_complete the cmd uses mgmt_pending_new (never on the
list), so mgmt_pending_valid/pending_find would always fail; added a bare "if
(err == -ECANCELED) return;" guard matching mgmt_remove_adv_monitor_complete's
idiom.]
CVE-2024-53207
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <cengiz.can at canonical.com>
---
net/bluetooth/mgmt.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index cbfbd6830892..be53eb1a5301 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -4060,6 +4060,9 @@ static void set_default_phy_complete(struct hci_dev *hdev, void *data, int err)
struct sk_buff *skb;
u8 status = mgmt_status(err);
+ if (err == -ECANCELED)
+ return;
+
skb = cmd->skb;
if (!status) {
@@ -8214,6 +8217,9 @@ static void read_local_oob_ext_data_complete(struct hci_dev *hdev, void *data,
u8 status = mgmt_status(err);
u16 eir_len;
+ if (err == -ECANCELED)
+ return;
+
if (!status) {
if (!skb)
status = MGMT_STATUS_FAILED;
--
2.53.0
More information about the kernel-team
mailing list