Received: by 2002:a05:7412:da14:b0:e2:908c:2ebd with SMTP id fe20csp2303776rdb; Mon, 9 Oct 2023 22:37:16 -0700 (PDT) X-Google-Smtp-Source: AGHT+IFCl56CFwb0LGm2sEfRek8eDrLSkNbbxAm10QiTiideJXZKMSo2P8Y/q3g7h+7B3w/Ync/d X-Received: by 2002:a17:903:2348:b0:1c7:47ca:f07f with SMTP id c8-20020a170903234800b001c747caf07fmr15430229plh.21.1696916235745; Mon, 09 Oct 2023 22:37:15 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1696916235; cv=none; d=google.com; s=arc-20160816; b=px+xjoWbfd3xN0kAsTQFilyUd0n1eHLVCoP44WRJrvuH/Ew2Ptr8dR6jO0QPF74Tli ajUDrEs+xXuOcGXO+/krFd3xintV3R+P83JpZd4C7ctd9FimvW/SwvTkqmzzLIa2Z4ig 0z8IKI6lc/dymkDBUOl3tYtS0VR/qYoNhixDhg+8eln29N3dYQF/mGUQRg+BxYT0biFN SzgVOOsez0WfZHQiGUxMXGY7poaB5691In0cmYZV8dF/ud/mTqKlJ2IP+RUwyrjzW+Zf ZS41SaRfJw3M6uO0d165XpsIt4WWTxfo/oy4Avy2/eaJzqHbR4s8LdhcJ/lHn9yNPy4J XqQA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=3+ydGI7sff09G/7JETRhlsl6DkdhesL7wxe7Wc1ipso=; fh=9HuOo6quJpSdJFt4fCWC7hBjI438Osklaes5lX9cwNw=; b=Wm8I3pBlIKxF0ilFP3EGnzEotcYxaXIEU6Birq5tsEhvB/+qMMdKiysRxQXDSfK9Qg Seh1BJCmLAHPIn8N4+S1d+HY5cJ/735tFid3ng3peHUifXcfk/uhpNKEOCondb47e4hU 1hHCHEK9+CiaRWq4N7UjvfLMlqOfyY+znOTi6dx/ibVxjRl4iFVupPHN1u950XlROEv2 zkV/K4v8pT56oQ4aFIfYgVX8IvJv/QaUOmxKmSd9fH6la2sT/9CIUatzSh9454CNoVyb WLn4qnvNC/tkbXbLpOxcNMgXb63j4EVrMRNxc01Zrfx9yZ5Q7rW46wY/c2+e+jq+fB3+ nHyg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=NyGXX67r; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from howler.vger.email (howler.vger.email. [23.128.96.34]) by mx.google.com with ESMTPS id ld12-20020a170902facc00b001c7755dccc7si786158plb.632.2023.10.09.22.37.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 09 Oct 2023 22:37:15 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) client-ip=23.128.96.34; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=NyGXX67r; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by howler.vger.email (Postfix) with ESMTP id 401FC802D42C; Mon, 9 Oct 2023 22:37:10 -0700 (PDT) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.10 at howler.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1442111AbjJJFhI (ORCPT + 99 others); Tue, 10 Oct 2023 01:37:08 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:52842 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1442113AbjJJFhI (ORCPT ); Tue, 10 Oct 2023 01:37:08 -0400 Received: from mail-oa1-x30.google.com (mail-oa1-x30.google.com [IPv6:2001:4860:4864:20::30]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 9BE37AF; Mon, 9 Oct 2023 22:37:06 -0700 (PDT) Received: by mail-oa1-x30.google.com with SMTP id 586e51a60fabf-1dd71c0a41fso3550555fac.2; Mon, 09 Oct 2023 22:37:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696916226; x=1697521026; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=3+ydGI7sff09G/7JETRhlsl6DkdhesL7wxe7Wc1ipso=; b=NyGXX67rUNDetTjJkPKNiEevjYDyNjEGyGle1kwtvtf86bv3AQ6e8DTE4T8ffIYSNB cRmLJECQVcHhaMP6XjhGKUBpv2Xykds0denH4vAo5xoxEmA5DUXgyqbL4l1yhG3oomKH pT5PRPYw0b9RvRlrqKHEmKp+g3/Kvb609aw0HeCg0S9w088DbPVV+z51gFDCYMwkxdEh xrgCkG28iCASfzbXgnvyupPMXDjYP5lYIFSdzPB2T01x5gmfpyvjYLEiTnChANvr77fB U7CuwUyoxakHQSy/CIM1GHoWVx1DtQ82lnsuDOeLRXC+jEbX9h8l7mNghifU7/zSsbMV 4fKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696916226; x=1697521026; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=3+ydGI7sff09G/7JETRhlsl6DkdhesL7wxe7Wc1ipso=; b=AYxcDl9YJKXUgxfIWr9lNrhqC79aI/GCp1owJNJcT0atk9AisJyBWr1VB0xoH7kaGi uWXtDnguz9maMCeegMvyqB+P2uYW9t78AHdyEfPtyaX7AnisBOpUUderT5gC2gn0oOfq YzlTvM847E+qAXef3TMNMUtcFx0mNbhOzri4i8yhiSVSp+g9u5BK7pt8iKQCTSpTMro3 At2Fbj7lgZyUX2NQVn59yChfaXtGgNkKVrCNi3WpDLE2WgTEDzBqFMQBkuICqId0oV4a QyJcdF41TAQ4tt4leruH1IkURMgp5nlfK5qr/NR7pOqAg072sBgo68i/mLBFPrYoQraw mymw== X-Gm-Message-State: AOJu0YybPOoSZoSLqunYtCD3ns/h8+N6a8/AG6Ik5agGl1GAU1p1kZvT EOX/ITer9w92QuiV5eEVQMM= X-Received: by 2002:a05:6870:71ce:b0:1d6:51aa:13a2 with SMTP id p14-20020a05687071ce00b001d651aa13a2mr19869311oag.10.1696916225861; Mon, 09 Oct 2023 22:37:05 -0700 (PDT) Received: from pek-lxu-l1.wrs.com ([111.198.228.56]) by smtp.gmail.com with ESMTPSA id n9-20020aa79049000000b0068fe7c4148fsm7267060pfo.57.2023.10.09.22.37.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 09 Oct 2023 22:37:05 -0700 (PDT) From: Edward AD To: syzbot+c90849c50ed209d77689@syzkaller.appspotmail.com Cc: davem@davemloft.net, edumazet@google.com, johan.hedberg@gmail.com, kuba@kernel.org, linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, luiz.dentz@gmail.com, luiz.von.dentz@intel.com, marcel@holtmann.org, netdev@vger.kernel.org, pabeni@redhat.com, syzkaller-bugs@googlegroups.com Subject: [PATCH] Bluetooth: hci_sock: fix slab oob read in create_monitor_event Date: Tue, 10 Oct 2023 13:36:57 +0800 Message-ID: <20231010053656.2034368-2-twuufnxlz@gmail.com> X-Mailer: git-send-email 2.42.0 In-Reply-To: <000000000000ae9ff70607461186@google.com> References: <000000000000ae9ff70607461186@google.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: Yes, score=6.4 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,HK_RANDOM_FROM,MAILING_LIST_MULTI, RCVD_IN_SBL_CSS,SORTED_RECIPS,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Level: ****** X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on howler.vger.email Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (howler.vger.email [0.0.0.0]); Mon, 09 Oct 2023 22:37:10 -0700 (PDT) X-Spam-Report: * 3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS * [2620:137:e000:0:0:0:3:0 listed in] [zen.spamhaus.org] * 1.0 HK_RANDOM_FROM From username looks random * 0.2 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level * mail domains are different * 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record * 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail * provider * [twuufnxlz[at]gmail.com] * -0.0 SPF_PASS SPF: sender matches SPF record * 2.5 SORTED_RECIPS Recipient list is sorted by address * -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature * 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily * valid * -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from * author's domain * 0.2 FREEMAIL_FORGED_FROMDOMAIN 2nd level domains in From and * EnvelopeFrom freemail headers are different * -1.0 MAILING_LIST_MULTI Multiple indicators imply a widely-seen list * manager When accessing hdev->name, the actual string length should prevail Reported-by: syzbot+c90849c50ed209d77689@syzkaller.appspotmail.com Fixes: dcda165706b9 ("Bluetooth: hci_core: Fix build warnings") Signed-off-by: Edward AD --- net/bluetooth/hci_sock.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/bluetooth/hci_sock.c b/net/bluetooth/hci_sock.c index 5e4f718073b7..72abe54c45dd 100644 --- a/net/bluetooth/hci_sock.c +++ b/net/bluetooth/hci_sock.c @@ -488,7 +488,7 @@ static struct sk_buff *create_monitor_event(struct hci_dev *hdev, int event) ni->type = hdev->dev_type; ni->bus = hdev->bus; bacpy(&ni->bdaddr, &hdev->bdaddr); - memcpy(ni->name, hdev->name, 8); + memcpy(ni->name, hdev->name, strlen(hdev->name)); opcode = cpu_to_le16(HCI_MON_NEW_INDEX); break; -- 2.25.1