Received: by 10.213.65.68 with SMTP id h4csp220239imn; Fri, 23 Mar 2018 03:11:39 -0700 (PDT) X-Google-Smtp-Source: AG47ELvRajTsfiwsibExAKiOufD6fdaIcI7rJkpmvTej8C4c9mMGoNTPZTZPl3TBKZrzoDR9gPt+ X-Received: by 2002:a17:902:8688:: with SMTP id g8-v6mr25193565plo.340.1521799899244; Fri, 23 Mar 2018 03:11:39 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1521799899; cv=none; d=google.com; s=arc-20160816; b=NFwyTZpfrZ9/Uct1DeZfz5eK7hkhX/oiwLjaZM2tSoiEIM50lPP0Tv2jcPvBdp1cGS xPY/yGW9IBdMXqbfTdCUaK/+P5s4XmT+FAwVo9z8lOxRbNPGr9gm+3nHYwQnqno8g3z5 DqKJFNpilLi8Iw6ho6i5mJbo9v1lsDtuBnrJVeNNzk/DcbS05GGaD5BhaxRewcQFY+0b iq0zpuE2dl77obnQoQi8DdDBjdCSR0TlxU11pFXFKTwwWH3i11t60DizuJmaRRHgvXhG gKVm+P9TfCNlF/z1EXAq3/Cqi98LmXXn/VPL5CldhdyuPX3+cy0l6MD2jGdMjCb0t1eo qfkA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :in-reply-to:message-id:date:subject:cc:to:from :arc-authentication-results; bh=FQts0s2eyJ4eNCzZ6oqN/8U3BixMD90uyk83ddqpcus=; b=iBGw2R3MEQkrhu2g2kBbHVLsONFYUeeLudlGrwv8b7uUdAnoX9mRNn2B/p4HRgV0zd 1FrcQTL3ylt8D3VX8z72gHWmB4TzxqZuW+/M0gFB7YW0p7MXfAzP7gJX3XM6IXgjrhm/ p3qkZrJGGBRSdrN1+KUbzc7C+lrATqU0kjwIeF5q6zyDEstvyH/XroXe5L5JSp7/oox9 t8awW4oDxmUuGS0f/jPBp7bZigX1otJXiPTByeUJHPOeqEGZD40wBbLsyW97WCQA9uEn UreFccso5X7BlPjI59qDp394L+0ghbDgZPno3NYnZm7mRZ3GUijqbFmue2XuVMp6DTCg 8Vxw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id m133si5934923pga.483.2018.03.23.03.11.24; Fri, 23 Mar 2018 03:11:39 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932715AbeCWKK3 (ORCPT + 99 others); Fri, 23 Mar 2018 06:10:29 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:42522 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932684AbeCWKKZ (ORCPT ); Fri, 23 Mar 2018 06:10:25 -0400 Received: from localhost (LFbn-1-12247-202.w90-92.abo.wanadoo.fr [90.92.61.202]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id 7C05A1063; Fri, 23 Mar 2018 10:10:24 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Loic Poulain , Marcel Holtmann , Sasha Levin Subject: [PATCH 4.9 135/177] Bluetooth: btqcomsmd: Fix skb double free corruption Date: Fri, 23 Mar 2018 10:54:23 +0100 Message-Id: <20180323094211.166951345@linuxfoundation.org> X-Mailer: git-send-email 2.16.2 In-Reply-To: <20180323094205.090519271@linuxfoundation.org> References: <20180323094205.090519271@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.9-stable review patch. If anyone has any objections, please let me know. ------------------ From: Loic Poulain [ Upstream commit 67b8fbead4685b36d290a0ef91c6ddffc4920ec9 ] In case of hci send frame failure, skb is still owned by the caller (hci_core) and then should not be freed. This fixes crash on dragonboard-410c when sending SCO packet. skb is freed by both btqcomsmd and hci_core. Fixes: 1511cc750c3d ("Bluetooth: Introduce Qualcomm WCNSS SMD based HCI driver") Signed-off-by: Loic Poulain Signed-off-by: Marcel Holtmann Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- drivers/bluetooth/btqcomsmd.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) --- a/drivers/bluetooth/btqcomsmd.c +++ b/drivers/bluetooth/btqcomsmd.c @@ -85,7 +85,8 @@ static int btqcomsmd_send(struct hci_dev break; } - kfree_skb(skb); + if (!ret) + kfree_skb(skb); return ret; }