Re: [PATCH] Bluetooth: hci_core: Serialize fragmented ISO packet queueing

From: patchwork-bot+bluetooth

Date: Mon Sep 28 2026 - 11:46:48 EST


Hello:

This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>:

On Sun, 27 Sep 2026 01:29:35 +0800 you wrote:
> The fragmented path in hci_queue_iso() calls __skb_queue_tail() without
> holding conn->data_q.lock. The socket lock serializes senders, but the
> transmit worker can concurrently remove packets from this queue using
> skb_dequeue().
>
> After an insertion saves the old tail pointer, hci_sched_iso() can dequeue
> that packet and pass it to the driver. The driver can free the packet
> before the insertion resumes and writes to the old tail's next pointer,
> causing a use-after-free. Concurrent updates can also corrupt the queue.
>
> [...]

Here is the summary with links:
- Bluetooth: hci_core: Serialize fragmented ISO packet queueing
https://git.kernel.org/bluetooth/bluetooth-next/c/1a572db43c05

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html