Bluetooth: SCO: Fix UAF on sco_sock_timeout
conn->sk maybe have been unlinked/freed while waiting for sco_conn_lock so this checks if the conn->sk is still valid by checking if it part of sco_sk_list. Reported-by:<syzbot+4c0d0c4cde787116d465@syzkaller.appspotmail.com> Tested-by:
<syzbot+4c0d0c4cde787116d465@syzkaller.appspotmail.com> Closes: https://syzkaller.appspot.com/bug?extid=4c0d0c4cde787116d465 Fixes: ba316be1 ("Bluetooth: schedule SCO timeouts with delayed_work") Signed-off-by:
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Loading
Please register or sign in to comment