summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMike Pagano <mpagano@gentoo.org>2024-11-14 08:49:11 -0500
committerMike Pagano <mpagano@gentoo.org>2024-11-14 08:49:11 -0500
commit3e3358ec19faa4465e8fd12d2e884f345ed5a2fb (patch)
tree34eeca36d48d05a40beb939ab7e1f715e09cf869
parentAdd the BMQ(BitMap Queue) Scheduler. USE=experimental (diff)
downloadlinux-patches-3e3358ec19faa4465e8fd12d2e884f345ed5a2fb.tar.gz
linux-patches-3e3358ec19faa4465e8fd12d2e884f345ed5a2fb.tar.bz2
linux-patches-3e3358ec19faa4465e8fd12d2e884f345ed5a2fb.zip
Bluetooth: hci_core: Fix calling mgmt_device_connected
Bug: https://bugs.gentoo.org/942925 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
-rw-r--r--0000_README4
-rw-r--r--2400_bluetooth-mgmt-device-connected-fix.patch34
2 files changed, 38 insertions, 0 deletions
diff --git a/0000_README b/0000_README
index 9d412a8c..39ba643a 100644
--- a/0000_README
+++ b/0000_README
@@ -87,6 +87,10 @@ Patch: 2000_BT-Check-key-sizes-only-if-Secure-Simple-Pairing-enabled.patch
From: https://lore.kernel.org/linux-bluetooth/20190522070540.48895-1-marcel@holtmann.org/raw
Desc: Bluetooth: Check key sizes only when Secure Simple Pairing is enabled. See bug #686758
+Patch: 2400_bluetooth-mgmt-device-connected-fix.patch
+From: https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git
+Desc: Bluetooth: hci_core: Fix calling mgmt_device_connected
+
Patch: 2600_HID-revert-Y900P-fix-ThinkPad-L15-touchpad.patch
From: https://bugs.gentoo.org/942797
Desc: Revert: HID: multitouch: Add support for lenovo Y9000P Touchpad
diff --git a/2400_bluetooth-mgmt-device-connected-fix.patch b/2400_bluetooth-mgmt-device-connected-fix.patch
new file mode 100644
index 00000000..86cf10e9
--- /dev/null
+++ b/2400_bluetooth-mgmt-device-connected-fix.patch
@@ -0,0 +1,34 @@
+From 48adce305dc6d6c444fd00e40ad07d4a41acdfbf Mon Sep 17 00:00:00 2001
+From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
+Date: Fri, 8 Nov 2024 11:19:54 -0500
+Subject: Bluetooth: hci_core: Fix calling mgmt_device_connected
+
+Since 61a939c68ee0 ("Bluetooth: Queue incoming ACL data until
+BT_CONNECTED state is reached") there is no long the need to call
+mgmt_device_connected as ACL data will be queued until BT_CONNECTED
+state.
+
+Link: https://bugzilla.kernel.org/show_bug.cgi?id=219458
+Link: https://github.com/bluez/bluez/issues/1014
+Fixes: 333b4fd11e89 ("Bluetooth: L2CAP: Fix uaf in l2cap_connect")
+Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
+---
+ net/bluetooth/hci_core.c | 2 --
+ 1 file changed, 2 deletions(-)
+
+diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
+index f6cff34a85421c..f9e19f9cb5a386 100644
+--- a/net/bluetooth/hci_core.c
++++ b/net/bluetooth/hci_core.c
+@@ -3792,8 +3792,6 @@ static void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb)
+
+ hci_dev_lock(hdev);
+ conn = hci_conn_hash_lookup_handle(hdev, handle);
+- if (conn && hci_dev_test_flag(hdev, HCI_MGMT))
+- mgmt_device_connected(hdev, conn, NULL, 0);
+ hci_dev_unlock(hdev);
+
+ if (conn) {
+--
+cgit 1.2.3-korg
+