Re: [PATCH] Bluetooth: L2CAP: access chan->conn safely in get/setsockopt

From: patchwork-bot+bluetooth

Date: Tue Aug 11 2026 - 16:11:13 EST


Hello:

This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>:

On Sun, 9 Aug 2026 20:42:41 +0300 you wrote:
> Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref")
> l2cap_chan::conn has held reference and remains non-NULL also after the
> corresponding hci_conn is deleted. In this state accessing various
> fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in
> l2cap_sock_setsockopt() access of conn->hcon->hdev.
>
> Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before
> trying to use it in l2cap_sock.c. Hold l2cap_chan_lock() in
> getsockopt/setsockopt to ensure it stays alive, and to avoid data races
> in l2cap_chan fields.
>
> [...]

Here is the summary with links:
- Bluetooth: L2CAP: access chan->conn safely in get/setsockopt
https://git.kernel.org/bluetooth/bluetooth-next/c/d1b752f55289

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html