Skip to content

Commit

Permalink
Bluetooth: SCO: Fix sco_send_frame returning skb->len
Browse files Browse the repository at this point in the history
commit 037ce00 upstream.

The skb in modified by hci_send_sco which pushes SCO headers thus
changing skb->len causing sco_sock_sendmsg to fail.

Fixes: 0771cbb ("Bluetooth: SCO: Replace use of memcpy_from_msg with bt_skb_sendmsg")
Tested-by: Tedd Ho-Jeong An <tedd.an@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Cc: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
  • Loading branch information
Luiz Augusto von Dentz authored and Greg Kroah-Hartman committed Jul 29, 2022

Unverified

No user is associated with the committer email.
1 parent aa2d34c commit 836b47e
Showing 1 changed file with 6 additions and 4 deletions.
10 changes: 6 additions & 4 deletions net/bluetooth/sco.c
Original file line number Diff line number Diff line change
@@ -282,16 +282,17 @@ static int sco_connect(struct hci_dev *hdev, struct sock *sk)
static int sco_send_frame(struct sock *sk, struct sk_buff *skb)
{
struct sco_conn *conn = sco_pi(sk)->conn;
int len = skb->len;

/* Check outgoing MTU */
if (skb->len > conn->mtu)
if (len > conn->mtu)
return -EINVAL;

BT_DBG("sk %p len %d", sk, skb->len);
BT_DBG("sk %p len %d", sk, len);

hci_send_sco(conn->hcon, skb);

return skb->len;
return len;
}

static void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
@@ -731,7 +732,8 @@ static int sco_sock_sendmsg(struct socket *sock, struct msghdr *msg,
err = -ENOTCONN;

release_sock(sk);
if (err)

if (err < 0)
kfree_skb(skb);
return err;
}

0 comments on commit 836b47e

Please sign in to comment.