mirror of
https://github.com/apache/nuttx.git
synced 2026-08-17 09:33:18 +08:00
wireless/bluetooth/bt_hcicore.c: Balance conn and buffer refs in hci_acl().
hci_acl() looked up the connection with bt_conn_lookup_handle(), which returns a new reference, but never released it. This leaked one conn reference for every received ACL packet. bt_conn_receive() also consumes the buffer on every path: it forwards to l2cap (which releases) or stores the buffer in conn->rx without an addref. The hci_rx_work() worker then called bt_buf_release() on the same buffer, which caused a double free or use-after-free. Take an extra buffer reference for the worker to release, and release the connection reference from the lookup. Assisted-by: Fable Signed-off-by: AbhinavMir <atg271@gmail.com>
This commit is contained in:
@@ -265,7 +265,9 @@ static void hci_acl(FAR struct bt_buf_s *buf)
|
||||
return;
|
||||
}
|
||||
|
||||
bt_buf_addref(buf);
|
||||
bt_conn_receive(conn, buf, flags);
|
||||
bt_conn_release(conn);
|
||||
}
|
||||
|
||||
/* HCI event processing */
|
||||
|
||||
Reference in New Issue
Block a user