Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security
During our fuzz testing of the connection and disconnection process at the RFCOMM layer, we discovered this bug. By comparing the packets from a normal connection and disconnection process with the testcase that triggered a KASAN report. We analyzed the cause of this bug as follows:
-
In the packets captured during a normal connection, the host sends a
Read Encryption Key Sizetype ofHCI_CMDpacket (Command Opcode: 0x1408) to the controller to inquire the length of encryption key.After receiving this packet, the controller immediately replies with a Command Completepacket (Event Code: 0x0e) to return the Encryption Key Size. -
In our fuzz test case, the timing of the controller’s response to this packet was delayed to an unexpected point: after the RFCOMM and L2CAP layers had disconnected but before the HCI layer had disconnected.
-
After receiving the Encryption Key Size Response at the time described in point 2, the host still called the rfcomm_check_security function. However, by this time
struct l2cap_conn *conn = l2cap_pi(sk)->chan->conn;had already been released, and when the function executedreturn hci_conn_security(conn->hcon, d->sec_level, auth_type, d->out);, specifically when accessingconn->hcon, a null-ptr-deref error occurred.
To fix this bug, check if sk->sk_state is BT_CLOSED before calling
rfcomm_recv_frame in rfcomm_process_rx.
Details
- Affected product:
- AlmaLinux 9.2 ESU , CentOS 6 ELS , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , CloudLinux 6 ELS , CloudLinux 7 ELS , Oracle Linux 6 ELS , Oracle Linux 7 ELS , RHEL 7 ELS , TuxCare 9.6 ESU , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS
- Affected packages:
- linux @ 5.4.0 (+16 more)
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security
During our fuzz testing of the connection and disconnection process at the RFCOMM layer, we discovered this bug. By comparing the packets from a normal connection and disconnection process with the testcase that triggered a KASAN report. We analyzed the cause of this bug as follows:
-
In the packets captured during a normal connection, the host sends a
Read Encryption Key Sizetype ofHCI_CMDpacket (Command Opcode: 0x1408) to the controller to inquire the length of encryption key.After receiving this packet, the controller immediately replies with a Command Completepacket (Event Code: 0x0e) to return the Encryption Key Size. -
In our fuzz test case, the timing of the controller’s response to this packet was delayed to an unexpected point: after the RFCOMM and L2CAP layers had disconnected but before the HCI layer had disconnected.
-
After receiving the Encryption Key Size Response at the time described in point 2, the host still called the rfcomm_check_security function. However, by this time
struct l2cap_conn *conn = l2cap_pi(sk)->chan->conn;had already been released, and when the function executedreturn hci_conn_security(conn->hcon, d->sec_level, auth_type, d->out);, specifically when accessingconn->hcon, a null-ptr-deref error occurred.
To fix this bug, check if sk->sk_state is BT_CLOSED before calling
rfcomm_recv_frame in rfcomm_process_rx.
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 9 | Released |
33 kernels
|
| Debian 10 | Will Not Fix | — |
| Debian 10 cloud | Will Not Fix | — |
| Debian 11 | Released |
28 kernels
|
| Debian 11 cloud | Released |
8 kernels
|
| Oracle Linux 6 UEK 4 | Planned | — |
| Oracle Linux 7 UEK 4 | Planned | — |
| Oracle Linux 9 | Released |
39 kernels
|
| RHEL 9 | Released |
33 kernels
|
| Rocky Linux 9 | Released |
33 kernels
|
| Ubuntu 14.04 HWE ESM | Will Not Fix | — |
| Ubuntu 16.04 AWS ESM | Will Not Fix | — |
| Ubuntu 16.04 AWS HWE ESM | Will Not Fix | — |
| Ubuntu 16.04 Azure ESM | Will Not Fix | — |
| Ubuntu 16.04 ESM | Will Not Fix | — |
| Ubuntu 16.04 HWE ESM | Will Not Fix | — |
| Ubuntu 18.04 AWS Focal | Released |
56 kernels
|
| Ubuntu 18.04 Azure Focal | Released |
58 kernels
|
| Ubuntu 18.04 HWE Focal | Released |
69 kernels
|
| Ubuntu 18.04 HWE GCP | Released |
15 kernels
|
| Ubuntu 20.04 | Released |
110 kernels
|
| Ubuntu 20.04 AWS | Released |
93 kernels
|
| Ubuntu 20.04 Azure | Released |
84 kernels
|
| Ubuntu 20.04 GCP | Released |
16 kernels
|
| Ubuntu 20.04 HWE AWS | Will Not Fix | — |
| Ubuntu 22.04 | Ready For Release | — |
| Ubuntu 22.04 AWS | Will Not Fix | — |
| Ubuntu 22.04 Azure | Will Not Fix | — |