[lvc-project] [PATCH 6.1 0/1] Bluetooth: hci_sync: cancel cmd_timer if hci_open failed

Fedor Pchelkin pchelkin at ispras.ru
Thu Jan 26 16:36:12 MSK 2023


Syzkaller reports use-after-free in hci_cmd_timeout(). The bug was fixed
in the following patch and can be cleanly applied to 6.1 stable tree.

Due to some technical rearrangement, the fix for older stable branches
requires a different patch which I'll send you in another thread.



More information about the lvc-project mailing list