[PATCH] Bluetooth: coredump: Don't leak an active dump when the device is opened
From: Ali Ahmet Memiş
Date: Sat Oct 10 2026 - 15:47:40 EST
If the device is closed during a dump and opened again before the dump
timeout fires, hci_devcd_reset() in hci_dev_open_sync() clears
dump.head and cancels the timeout without freeing the buffer, so it is
leaked.
Free it instead after making sure the timeout is not running.
Fixes: 9695ef876fd1 ("Bluetooth: Add support for hci devcoredump")
Signed-off-by: Ali Ahmet Memiş <aliamemis@xxxxxxxxxxx>
---
On top of 860b93123309 ("Bluetooth: hci_sync: Serialize devcoredump
reset during device open")
Tested with hci_vhci. force_devcoredump in TIMEOUT state, then
"hciconfig hci0 up" before the timeout. Without the patch the buffer
stays in /proc/vmallocinfo, with it it is freed.
include/net/bluetooth/coredump.h | 2 ++
net/bluetooth/coredump.c | 9 +++++++++
net/bluetooth/hci_sync.c | 4 +---
3 files changed, 12 insertions(+), 3 deletions(-)
diff --git a/include/net/bluetooth/coredump.h b/include/net/bluetooth/coredump.h
index acc1849f6..b8bba9a8b 100644
--- a/include/net/bluetooth/coredump.h
+++ b/include/net/bluetooth/coredump.h
@@ -70,6 +70,7 @@ struct hci_devcoredump {
const char *hci_devcd_state_name(enum devcoredump_state state);
void hci_devcd_reset(struct hci_dev *hdev);
+void hci_devcd_discard(struct hci_dev *hdev);
void hci_devcd_shutdown(struct hci_dev *hdev);
void hci_devcd_rx(struct work_struct *work);
void hci_devcd_timeout(struct work_struct *work);
@@ -90,6 +91,7 @@ static inline const char *hci_devcd_state_name(enum devcoredump_state state)
}
static inline void hci_devcd_reset(struct hci_dev *hdev) {}
+static inline void hci_devcd_discard(struct hci_dev *hdev) {}
static inline void hci_devcd_shutdown(struct hci_dev *hdev) {}
static inline void hci_devcd_rx(struct work_struct *work) {}
static inline void hci_devcd_timeout(struct work_struct *work) {}
diff --git a/net/bluetooth/coredump.c b/net/bluetooth/coredump.c
index 71fc8dab4..b4283e6ae 100644
--- a/net/bluetooth/coredump.c
+++ b/net/bluetooth/coredump.c
@@ -104,6 +104,15 @@ static void hci_devcd_free(struct hci_dev *hdev)
hci_devcd_reset(hdev);
}
+void hci_devcd_discard(struct hci_dev *hdev)
+{
+ cancel_delayed_work_sync(&hdev->dump.dump_timeout);
+
+ hci_dev_lock(hdev);
+ hci_devcd_free(hdev);
+ hci_dev_unlock(hdev);
+}
+
void hci_devcd_shutdown(struct hci_dev *hdev)
{
unsigned long flags;
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index efbd2e538..cc2f81b62 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -5503,9 +5503,7 @@ int hci_dev_open_sync(struct hci_dev *hdev)
goto done;
}
- hci_dev_lock(hdev);
- hci_devcd_reset(hdev);
- hci_dev_unlock(hdev);
+ hci_devcd_discard(hdev);
set_bit(HCI_RUNNING, &hdev->flags);
hci_sock_dev_event(hdev, HCI_DEV_OPEN);
--
2.55.0