Bluetooth: stop proccessing malicious adv data
[ Upstream commit 3a56ef71 ] Syzbot reported slab-out-of-bounds read in hci_le_adv_report_evt(). The problem was in missing validaion check. We should check if data is not malicious and we can read next data block. If we won't check ptr validness, code can read a way beyond skb->end and it can cause problems, of course. Fixes: e95beb41 ("Bluetooth: hci_le_adv_report_evt code refactoring") Reported-and-tested-by:<syzbot+e3fcb9c4f3c2a931dc40@syzkaller.appspotmail.com> Signed-off-by:
Pavel Skripkin <paskripkin@gmail.com> Signed-off-by:
Marcel Holtmann <marcel@holtmann.org> Signed-off-by:
Sasha Levin <sashal@kernel.org>
Loading
Please sign in to comment