Bluetooth: hci_conn: hold conn reference in abort_conn_sync()

There is theoretical UAF if the conn is freed while the hci_sync task is
running.

Hold refcount to avoid that.

Fixes: 227a0cdf4a ("Bluetooth: MGMT: Fix not generating command complete for MGMT_OP_DISCONNECT")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
This commit is contained in:
Pauli Virtanen
2026-07-28 16:13:12 -04:00
committed by Luiz Augusto von Dentz
parent b640ff9af3
commit 5761d003da
+11 -1
View File
@@ -3165,6 +3165,13 @@ static int abort_conn_sync(struct hci_dev *hdev, void *data)
return hci_abort_conn_sync(hdev, conn, conn->abort_reason);
}
static void abort_conn_destroy(struct hci_dev *hdev, void *data, int err)
{
struct hci_conn *conn = data;
hci_conn_put(conn);
}
int hci_abort_conn(struct hci_conn *conn, u8 reason)
{
struct hci_dev *hdev = conn->hdev;
@@ -3190,7 +3197,10 @@ int hci_abort_conn(struct hci_conn *conn, u8 reason)
* as a result to MGMT_OP_DISCONNECT/MGMT_OP_UNPAIR which does
* already queue its callback on cmd_sync_work.
*/
err = hci_cmd_sync_run_once(hdev, abort_conn_sync, conn, NULL);
err = hci_cmd_sync_run_once(hdev, abort_conn_sync, hci_conn_get(conn),
abort_conn_destroy);
if (err)
hci_conn_put(conn);
return (err == -EEXIST) ? 0 : err;
}