]> git.baikalelectronics.ru Git - kernel.git/commit
Bluetooth: don't try to cancel uninitialized works at mgmt_index_removed()
authorTetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Fri, 5 Aug 2022 07:12:18 +0000 (16:12 +0900)
committerLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Tue, 9 Aug 2022 00:06:23 +0000 (17:06 -0700)
commit06d77979a78b99031a0890bedda7914b89098c3e
tree20ee507add3fcdf66792108aa676b60cc102a8c1
parent5b073dc0e212b6cd41b44e040f1a01f1240f5f7f
Bluetooth: don't try to cancel uninitialized works at mgmt_index_removed()

syzbot is reporting attempt to cancel uninitialized work at
mgmt_index_removed() [1], for calling cancel_delayed_work_sync() without
INIT_DELAYED_WORK() is not permitted.

INIT_DELAYED_WORK() is called from mgmt_init_hdev() via chan->hdev_init()
 from hci_mgmt_cmd(), but cancel_delayed_work_sync() is unconditionally
called from mgmt_index_removed().

Call cancel_delayed_work_sync() only if HCI_MGMT flag was set, for
mgmt_init_hdev() sets HCI_MGMT flag when calling INIT_DELAYED_WORK().

Link: https://syzkaller.appspot.com/bug?extid=b8ddd338a8838e581b1c
Reported-by: syzbot <syzbot+b8ddd338a8838e581b1c@syzkaller.appspotmail.com>
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Fixes: 0f1d081cd2f4f73d ("Bluetooth: Convert delayed discov_off to hci_sync")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
net/bluetooth/mgmt.c