Received: by 2002:a05:6a10:af89:0:0:0:0 with SMTP id iu9csp2505710pxb; Sun, 23 Jan 2022 06:53:27 -0800 (PST) X-Google-Smtp-Source: ABdhPJzVEnv5KaO2pI1ad4m+uFoVKNe7vL8eLycpdPTEsY7U8K24gVPyAUQXd8lNM7kO4jtz9TdW X-Received: by 2002:aa7:9f5c:0:b0:4c8:fc66:e4a1 with SMTP id h28-20020aa79f5c000000b004c8fc66e4a1mr2114013pfr.22.1642949607457; Sun, 23 Jan 2022 06:53:27 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1642949607; cv=none; d=google.com; s=arc-20160816; b=ZL9Nnpej0hyVegFYQDnLyKR0m0Bfk6PVyaxOGmSiWcbebL/AKoLU0J/6UWclOuQ2oi tI0c3p7W5Ic+ak3yvBNuZjAkZP/UEUDVdmr0S3KMTy2T0FZ9THGxhBL9PUbAklmTYTGG Il9wPPAIcJjuy0b3WapzMYRuRW2+YRMktT6zlhZoc/DneUqB8RKwik07grX/99a3uOKd 2KLjNGvt6pU0/CkHgDpLKhqBABkhYEf9+bu58l2mTNpgtUFQctghCPUMlA3lp9BWwyD4 MtIztsckMDhyKSc27KS4DKh8gg+ecx86HLazMmrjGeRA5LkPphcOAa8i4i3zM46+hlOx aeuQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from; bh=YS94nm6cHoNfoHFW5kYMRVisMyA0zDJnUyHsJDuceq4=; b=jQqV8Vg4hwisMCPLdIDXQCiIOsXuicLcOifV2mSuexCPLbvN71tdeS4uecwav02UC+ oHFcCNS+1QTZ7NqJRWw7QXpD+4W9PyfOguZ77jA9r24cTH/zPodB01mR1KCHNjLRI6c0 8IC+hlPRFnK0TFZYxnUyVOgz/R19FlC2cqu4wRWptVNfICwnceESRAcxjwZU8Wi2vysF 7HsFHEFHiAqkO+yB6q8FmGY/9b7PRBuu2Z16EyH373yxxMBIPDPRqWpwOu2q4aGpv0yL 1PeJkIAXEBWpwj96dpwbitzKTI1AhJOtpRgEUGHEyBw1jKRnqnJtdpSCfjXipZEyS41o wbmw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id b8si1202141plh.526.2022.01.23.06.53.15; Sun, 23 Jan 2022 06:53:27 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232954AbiAVI3c (ORCPT + 99 others); Sat, 22 Jan 2022 03:29:32 -0500 Received: from giacobini.uberspace.de ([185.26.156.129]:56168 "EHLO giacobini.uberspace.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231954AbiAVI3b (ORCPT ); Sat, 22 Jan 2022 03:29:31 -0500 Received: (qmail 31532 invoked by uid 990); 22 Jan 2022 08:29:29 -0000 Authentication-Results: giacobini.uberspace.de; auth=pass (plain) From: Soenke Huster To: Marcel Holtmann , Johan Hedberg , Luiz Augusto von Dentz , "David S. Miller" , Jakub Kicinski Cc: Soenke Huster , linux-bluetooth@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] Bluetooth: msft: fix null pointer deref on msft_monitor_device_evt Date: Sat, 22 Jan 2022 09:27:52 +0100 Message-Id: <20220122082751.285478-1-soenke.huster@eknoes.de> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Rspamd-Bar: / X-Rspamd-Report: BAYES_HAM(-2.99999) R_MISSING_CHARSET(0.5) MIME_GOOD(-0.1) MID_CONTAINS_FROM(1) SUSPICIOUS_RECIPS(1.5) X-Rspamd-Score: -0.09999 Received: from unknown (HELO unkown) (::1) by giacobini.uberspace.de (Haraka/2.8.28) with ESMTPSA; Sat, 22 Jan 2022 09:29:29 +0100 Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org msft_find_handle_data returns NULL if it can't find the handle. Therefore, handle_data must be checked, otherwise a null pointer is dereferenced. Signed-off-by: Soenke Huster --- net/bluetooth/msft.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/net/bluetooth/msft.c b/net/bluetooth/msft.c index 484540855863..d2cf92e834f7 100644 --- a/net/bluetooth/msft.c +++ b/net/bluetooth/msft.c @@ -705,6 +705,9 @@ static void msft_monitor_device_evt(struct hci_dev *hdev, struct sk_buff *skb) handle_data = msft_find_handle_data(hdev, ev->monitor_handle, false); + if (!handle_data) + return; + switch (ev->addr_type) { case ADDR_LE_DEV_PUBLIC: addr_type = BDADDR_LE_PUBLIC; -- 2.34.1