Re: [PATCH v2] Bluetooth: ISO: Serialize concurrent connect calls
From: patchwork-bot+bluetooth
Date: Tue Oct 06 2026 - 10:31:20 EST
Hello:
This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>:
On Mon, 5 Oct 2026 15:50:31 +0800 you wrote:
> iso_sock_connect() checks the socket state before taking the socket lock
> and drops the lock again before setting up a connection. Two callers can
> both pass the admission check while the socket is open or bound.
>
> Caller A can copy its destination for route selection, then caller B can
> replace the socket destination before A binds or connects the CIS. A
> then uses B's destination with the route selected for its own request.
> B can also proceed after A attaches a connection and sets BT_CONNECT.
> For deferred BIS setup, B can bind a second BIS and overwrite
> iso_pi(sk)->conn, leaving the first connection's reference and conn->sk
> back-pointer stranded. Concurrent CIS connects can likewise replace the
> socket's connection. Later teardown only detaches the current connection,
> so a callback on the old connection can race with socket release and
> access a freed socket.
>
> [...]
Here is the summary with links:
- [v2] Bluetooth: ISO: Serialize concurrent connect calls
https://git.kernel.org/bluetooth/bluetooth-next/c/e32d80293a0e
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html