Thread (3 messages) 3 messages, 3 authors, 2021-08-30

Re: [PATCH] Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg()

From: Marcel Holtmann <marcel@holtmann.org>
Date: 2021-08-30 14:49:08
Also in: lkml

Hi Takashi,
The sco_send_frame() also takes lock_sock() during memcpy_from_msg()
call that may be endlessly blocked by a task with userfaultd
technique, and this will result in a hung task watchdog trigger.

Just like the similar fix for hci_sock_sendmsg() in commit
92c685dc5de0 ("Bluetooth: reorganize functions..."), this patch moves
the  memcpy_from_msg() out of lock_sock() for addressing the hang.

This should be the last piece for fixing CVE-2021-3640 after a few
already queued fixes.

Signed-off-by: Takashi Iwai <redacted>
---
net/bluetooth/sco.c | 23 +++++++++++++++--------
1 file changed, 15 insertions(+), 8 deletions(-)
patch has been applied to bluetooth-next tree.

Regards

Marcel
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help