Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1624137
| From | Sebastian Reichel <sre@kernel.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH] Bluetooth: hci_ll: Fix NULL pointer deref on FW upload failure |
| Date | 2017-04-16 00:00 +0200 |
| Message-ID | <twDTz-3AT-7@gated-at.bofh.it> (permalink) |
| References | <twDTz-3AT-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Avoid NULL pointer dereference occurring due to freeing
skb containing an error pointer. It can easily be triggered
by using the driver with broken uart (i.e. due to misconfigured
pinmuxing).
Fixes: 371805522f87 ("bluetooth: hci_uart: add LL protocol serdev driver support")
Signed-off-by: Sebastian Reichel <sre@kernel.org>
---
drivers/bluetooth/hci_ll.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/bluetooth/hci_ll.c b/drivers/bluetooth/hci_ll.c
index 485e8eb04542..adc444f309a3 100644
--- a/drivers/bluetooth/hci_ll.c
+++ b/drivers/bluetooth/hci_ll.c
@@ -537,8 +537,7 @@ static int read_local_version(struct hci_dev *hdev)
if (IS_ERR(skb)) {
bt_dev_err(hdev, "Reading TI version information failed (%ld)",
PTR_ERR(skb));
- err = PTR_ERR(skb);
- goto out;
+ return PTR_ERR(skb);
}
if (skb->len != sizeof(*ver)) {
err = -EILSEQ;
--
2.11.0
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
[PATCH] Bluetooth: hci_ll: Fix NULL pointer deref on FW upload failure Sebastian Reichel <sre@kernel.org> - 2017-04-16 00:00 +0200 Re: [PATCH] Bluetooth: hci_ll: Fix NULL pointer deref on FW upload failure Marcel Holtmann <marcel@holtmann.org> - 2017-04-16 20:40 +0200
csiph-web