Re: Missing signoff in the bluetooth tree

From: Luiz Augusto von Dentz

Date: Mon Sep 28 2026 - 11:14:55 EST


Weird, this should have been fixed in the last back merge, going in
the list of commits in bluetooth-next
https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/log/
they show as:

commit c9c15d4d8956df8c564f7c210e4dc5b9b820d97a (gitolite-bluetooth/master)
Author: Sai Teja Aluvala <aluvala.sai.teja@xxxxxxxxx>
Date: Tue Sep 22 18:33:11 2026 +0530

Bluetooth: btintel: validate DDC record lengths

Parse DDC record lengths in unsigned storage so 0xFF does not wrap.
Reject records smaller than the mandatory three-byte header, records
exceeding U8_MAX, and records exceeding remaining firmware bytes before
issuing Intel_Write_DDC.

This issue was reported by Claude Mythos.

Fixes: 145f2368c5fd ("Bluetooth: btintel: Add Device Configuration support")
Signed-off-by: Sai Teja Aluvala <aluvala.sai.teja@xxxxxxxxx>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>

commit d1ac915fb4184faad1b62148be50f317de7c24b5
Author: Sang-Hoon Choi <csh0052@xxxxxxxxx>
Date: Tue Sep 22 03:49:28 2026 +0900

Bluetooth: hci_core: free the HCI ID if naming fails

hci_register_dev() allocates an ID before calling dev_set_name().
If naming fails, it returns without releasing that ID. The device has
not been registered and hdev->id has not been assigned, so the normal
unregister path cannot release it.

Free the allocated ID before returning the naming error.

Fixes: dcda165706b9 ("Bluetooth: hci_core: Fix build warnings")
Reported-by: Changyul Lee <lcy8047@xxxxxxxxx>
Assisted-by: LLM
Signed-off-by: Sang-Hoon Choi <csh0052@xxxxxxxxx>
Reported-by: Changyul Lee <lcy8047@xxxxxxxxx>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>

commit 74847177eca5638827ab74cdf77f0b10fc40ca6c
Author: Linmao Li <lilinmao@xxxxxxxxxx>
Date: Tue Sep 22 10:01:41 2026 +0800

Bluetooth: hci_core: Fix inquiry cache timestamps on 64-bit systems

On 64-bit systems, outgoing BR/EDR connections always fall back to page
scan repetition mode R2 with no clock offset once the system has been
up for more than five minutes, even when inquiry found the peer only
seconds earlier. This lengthens paging and can increase the risk of a
Page Timeout.

The inquiry cache stores jiffies in __u32 timestamps, but its age
helpers subtract them from unsigned long jiffies. INITIAL_JIFFIES casts
-300 * HZ through unsigned int, so jiffies crosses 2^32 five minutes
after boot on 64-bit systems. Assigning it to __u32 then drops the upper
32 bits. In one trace, a 7.6-second-old entry (HZ=1000) was reported as
2^32 + 7620 ticks old and rejected by hci_acl_create_conn_sync().
hci_inquiry() is affected by the same truncation when checking the whole
cache. 32-bit systems are unaffected because unsigned long is 32 bits
wide there.

Use unsigned long for both timestamps so they have the same width as
jiffies on 32-bit and 64-bit systems, and update the debugfs format
specifier accordingly.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Linmao Li <lilinmao@xxxxxxxxxx>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>

commit f771f96557a4d953a7e4d045870547271e36e819
Author: Chandrashekar Devegowda <chandrashekar.devegowda@xxxxxxxxx>
Date: Tue Sep 22 12:10:22 2026 +0530

Bluetooth: btintel_pcie: reject oversized TX packets in send_frame()

btintel_pcie_send_frame() eventually copies skb->data into a fixed
BTINTEL_PCIE_BUFFER_SIZE (4096) DMA buffer via memcpy() in
btintel_pcie_prepare_tx(), with a 4-byte PCIe type header prepended.
A user-space process with HCI_CHANNEL_USER access can inject an
oversized packet and overflow the buffer.

Reject packets larger than
BTINTEL_PCIE_BUFFER_SIZE - BTINTEL_PCIE_HCI_TYPE_LEN on entry.

Fixes: 6e65a09f9275 ("Bluetooth: btintel_pcie: Add *setup*
function to download firmware")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Chandrashekar Devegowda <chandrashekar.devegowda@xxxxxxxxx>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>

commit 7dbeb6935ac331b0cba6c41cabd8e9d02d5f64ea
Author: Chandrashekar Devegowda <chandrashekar.devegowda@xxxxxxxxx>
Date: Tue Sep 22 12:10:21 2026 +0530

Bluetooth: btintel_pcie: fix plen overflow in btintel_pcie_recv_frame()

plen is u16 and computed as HDR_SIZE + dlen. For ACL/ISO frames dlen
is a 16-bit field, so a value >= 0xFFFC wraps the sum, bypassing the
"skb->len < plen" check and letting skb_trim() truncate the packet.

Widen plen to u32 so the addition cannot wrap.

Fixes: c2b636b3f788 ("Bluetooth: btintel_pcie: Add support for
PCIe transport")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Chandrashekar Devegowda <chandrashekar.devegowda@xxxxxxxxx>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>

commit 40eb4b18ad167b63644c27fa67a7400ba050379a
Author: Chandrashekar Devegowda <chandrashekar.devegowda@xxxxxxxxx>
Date: Tue Sep 22 12:10:20 2026 +0530

Bluetooth: btintel: fix buffer over-read in btintel_hw_error()

The "Exception info %s" print uses skb->data + 1, but the 12-byte
payload is not guaranteed to be NUL-terminated and can be read past
its end.

Bound the print with "%.*s" and skb->len - 1.

Fixes: 973bb97e5aee ("Bluetooth: btintel: Add generic function for
handling hardware errors")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Chandrashekar Devegowda <chandrashekar.devegowda@xxxxxxxxx>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>

On Mon, Sep 28, 2026 at 10:37 AM Mark Brown <broonie@xxxxxxxxxx> wrote:
>
> On Wed, Sep 23, 2026 at 10:22:37AM +0200, Mark Brown wrote:
> > Commits
> >
> > 4712bd9a14cbd ("Bluetooth: btintel: validate DDC record lengths")
> > 7348abd83a3b2 ("Bluetooth: hci_core: free the HCI ID if naming fails")
> > ea983244b99a3 ("Bluetooth: hci_core: Fix inquiry cache timestamps on 64-bit systems")
> > 2b036342b623c ("Bluetooth: btintel_pcie: reject oversized TX packets in send_frame()")
> > 6d21e89e69775 ("Bluetooth: btintel_pcie: fix plen overflow in btintel_pcie_recv_frame()")
> > 4145a13c1a044 ("Bluetooth: btintel: fix buffer over-read in btintel_hw_error()")
> >
> > are missing a Signed-off-by from their committers
>
> This issue is still present today.



--
Luiz Augusto von Dentz