mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 11:03:07 -04:00
In rsi_hci_attach(), ops->set_bt_context() stores the newly allocated
h_adapter into common->bt_adapter before hci_alloc_dev() and
hci_register_dev() are called. If either of these fails, h_adapter
is freed but common->bt_adapter remains a non-NULL dangling pointer.
This causes a deterministically reachable use-after-free when the
device operates in a BT+WiFi coexistence mode and CONFIG_RSI_COEX
is enabled. The following software-only trigger paths exist:
1. SDIO driver .remove (rsi_disconnect)
2. USB driver .disconnect (rsi_disconnect)
3. SDIO driver .shutdown (rsi_shutdown)
4. Hibernation .freeze (rsi_freeze)
All four paths check:
if (IS_ENABLED(CONFIG_RSI_COEX) && coex_mode > 1 && bt_adapter)
rsi_bt_ops.detach(bt_adapter); // use-after-free
coex_mode is set during rsi_91x_init(), before rsi_hci_attach() is
called, and is not cleared on attach failure. Since set_bt_context()
already wrote bt_adapter before the failure, the deinit paths see a
non-NULL dangling pointer and proceed to detach it.
Fix this by moving set_bt_context() after hci_register_dev() succeeds.
On failure paths bt_adapter stays NULL, and the deinit callers correctly
skip the detach call.
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
187 lines
3.8 KiB
C
187 lines
3.8 KiB
C
// SPDX-License-Identifier: ISC
|
|
/*
|
|
* Copyright (c) 2017 Redpine Signals Inc.
|
|
*
|
|
*/
|
|
#include <linux/module.h>
|
|
#include <linux/kernel.h>
|
|
#include <net/bluetooth/bluetooth.h>
|
|
#include <net/bluetooth/hci_core.h>
|
|
#include <linux/unaligned.h>
|
|
#include <net/rsi_91x.h>
|
|
|
|
#define RSI_DMA_ALIGN 8
|
|
#define RSI_FRAME_DESC_SIZE 16
|
|
#define RSI_HEADROOM_FOR_BT_HAL (RSI_FRAME_DESC_SIZE + RSI_DMA_ALIGN)
|
|
|
|
struct rsi_hci_adapter {
|
|
void *priv;
|
|
struct rsi_proto_ops *proto_ops;
|
|
struct hci_dev *hdev;
|
|
};
|
|
|
|
static int rsi_hci_open(struct hci_dev *hdev)
|
|
{
|
|
return 0;
|
|
}
|
|
|
|
static int rsi_hci_close(struct hci_dev *hdev)
|
|
{
|
|
return 0;
|
|
}
|
|
|
|
static int rsi_hci_flush(struct hci_dev *hdev)
|
|
{
|
|
return 0;
|
|
}
|
|
|
|
static int rsi_hci_send_pkt(struct hci_dev *hdev, struct sk_buff *skb)
|
|
{
|
|
struct rsi_hci_adapter *h_adapter = hci_get_drvdata(hdev);
|
|
struct sk_buff *new_skb = NULL;
|
|
|
|
switch (hci_skb_pkt_type(skb)) {
|
|
case HCI_COMMAND_PKT:
|
|
hdev->stat.cmd_tx++;
|
|
break;
|
|
case HCI_ACLDATA_PKT:
|
|
hdev->stat.acl_tx++;
|
|
break;
|
|
case HCI_SCODATA_PKT:
|
|
hdev->stat.sco_tx++;
|
|
break;
|
|
}
|
|
|
|
if (skb_headroom(skb) < RSI_HEADROOM_FOR_BT_HAL) {
|
|
/* Insufficient skb headroom - allocate a new skb */
|
|
new_skb = skb_realloc_headroom(skb, RSI_HEADROOM_FOR_BT_HAL);
|
|
if (unlikely(!new_skb))
|
|
return -ENOMEM;
|
|
bt_cb(new_skb)->pkt_type = hci_skb_pkt_type(skb);
|
|
kfree_skb(skb);
|
|
skb = new_skb;
|
|
if (!IS_ALIGNED((unsigned long)skb->data, RSI_DMA_ALIGN)) {
|
|
u8 *skb_data = skb->data;
|
|
int skb_len = skb->len;
|
|
|
|
skb_push(skb, RSI_DMA_ALIGN);
|
|
skb_pull(skb, PTR_ALIGN(skb->data,
|
|
RSI_DMA_ALIGN) - skb->data);
|
|
memmove(skb->data, skb_data, skb_len);
|
|
skb_trim(skb, skb_len);
|
|
}
|
|
}
|
|
|
|
return h_adapter->proto_ops->coex_send_pkt(h_adapter->priv, skb,
|
|
RSI_BT_Q);
|
|
}
|
|
|
|
static int rsi_hci_recv_pkt(void *priv, const u8 *pkt)
|
|
{
|
|
struct rsi_hci_adapter *h_adapter = priv;
|
|
struct hci_dev *hdev = h_adapter->hdev;
|
|
struct sk_buff *skb;
|
|
int pkt_len = get_unaligned_le16(pkt) & 0x0fff;
|
|
|
|
skb = dev_alloc_skb(pkt_len);
|
|
if (!skb)
|
|
return -ENOMEM;
|
|
|
|
memcpy(skb->data, pkt + RSI_FRAME_DESC_SIZE, pkt_len);
|
|
skb_put(skb, pkt_len);
|
|
h_adapter->hdev->stat.byte_rx += skb->len;
|
|
|
|
hci_skb_pkt_type(skb) = pkt[14];
|
|
|
|
return hci_recv_frame(hdev, skb);
|
|
}
|
|
|
|
static int rsi_hci_attach(void *priv, struct rsi_proto_ops *ops)
|
|
{
|
|
struct rsi_hci_adapter *h_adapter = NULL;
|
|
struct hci_dev *hdev;
|
|
int err = 0;
|
|
|
|
h_adapter = kzalloc_obj(*h_adapter);
|
|
if (!h_adapter)
|
|
return -ENOMEM;
|
|
|
|
h_adapter->priv = priv;
|
|
h_adapter->proto_ops = ops;
|
|
|
|
hdev = hci_alloc_dev();
|
|
if (!hdev) {
|
|
BT_ERR("Failed to alloc HCI device");
|
|
goto err;
|
|
}
|
|
|
|
h_adapter->hdev = hdev;
|
|
|
|
if (ops->get_host_intf(priv) == RSI_HOST_INTF_SDIO)
|
|
hdev->bus = HCI_SDIO;
|
|
else
|
|
hdev->bus = HCI_USB;
|
|
|
|
hci_set_drvdata(hdev, h_adapter);
|
|
hdev->open = rsi_hci_open;
|
|
hdev->close = rsi_hci_close;
|
|
hdev->flush = rsi_hci_flush;
|
|
hdev->send = rsi_hci_send_pkt;
|
|
|
|
err = hci_register_dev(hdev);
|
|
if (err < 0) {
|
|
BT_ERR("HCI registration failed with errcode %d", err);
|
|
hci_free_dev(hdev);
|
|
goto err;
|
|
}
|
|
|
|
ops->set_bt_context(priv, h_adapter);
|
|
|
|
return 0;
|
|
err:
|
|
h_adapter->hdev = NULL;
|
|
kfree(h_adapter);
|
|
return -EINVAL;
|
|
}
|
|
|
|
static void rsi_hci_detach(void *priv)
|
|
{
|
|
struct rsi_hci_adapter *h_adapter = priv;
|
|
struct hci_dev *hdev;
|
|
|
|
if (!h_adapter)
|
|
return;
|
|
|
|
hdev = h_adapter->hdev;
|
|
if (hdev) {
|
|
hci_unregister_dev(hdev);
|
|
hci_free_dev(hdev);
|
|
h_adapter->hdev = NULL;
|
|
}
|
|
|
|
kfree(h_adapter);
|
|
}
|
|
|
|
const struct rsi_mod_ops rsi_bt_ops = {
|
|
.attach = rsi_hci_attach,
|
|
.detach = rsi_hci_detach,
|
|
.recv_pkt = rsi_hci_recv_pkt,
|
|
};
|
|
EXPORT_SYMBOL(rsi_bt_ops);
|
|
|
|
static int rsi_91x_bt_module_init(void)
|
|
{
|
|
return 0;
|
|
}
|
|
|
|
static void rsi_91x_bt_module_exit(void)
|
|
{
|
|
return;
|
|
}
|
|
|
|
module_init(rsi_91x_bt_module_init);
|
|
module_exit(rsi_91x_bt_module_exit);
|
|
MODULE_AUTHOR("Redpine Signals Inc");
|
|
MODULE_DESCRIPTION("RSI BT driver");
|
|
MODULE_LICENSE("Dual BSD/GPL");
|