Thread (2 messages) read the whole thread 2 messages, 2 authors, 2020-06-29

Re: [PATCH] Bluetooth: fix kernel null pointer dereference error on suspend

From: Marcel Holtmann <marcel@holtmann.org>
Date: 2020-06-29 21:14:22
Also in: lkml, netdev

Hi Vamshi,
BUG Call Trace:
 queue_work_on+0x39/0x40
 hci_adv_monitors_clear+0x71/0x90 [bluetooth]
 hci_unregister_dev+0x18a/0x2f0 [bluetooth]
 btusb_disconnect+0x68/0x150 [btusb]
 usb_unbind_interface+0x7f/0x260
 device_release_driver_internal+0xec/0x1b0
 device_release_driver+0x12/0x20
 bus_remove_device+0xe1/0x150
 device_del+0x17d/0x3e0
 usb_disable_device+0x9f/0x250
 usb_disconnect+0xc6/0x270
 hub_event+0x6da/0x18d0
 process_one_work+0x20c/0x400
 worker_thread+0x34/0x400

RIP: 0010:__queue_work+0x92/0x3f0

NULL deference occurs in hci_update_background_scan() while it tries
to queue_work on already destroyed workqueues.

Change hci_unregister_dev() to invoke destroy_workqueues after the
call to hci_adv_monitors_clear().

Signed-off-by: Vamshi K Sthambamkadi <redacted>
---
net/bluetooth/hci_core.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
patch has been applied to bluetooth-next tree.

Regards

Marcel
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help