wireless/bluetooth/bt_hcicore.c: Balance conn and buffer refs in hci_acl().

hci_acl() looked up the connection with bt_conn_lookup_handle(), which
returns a new reference, but never released it. This leaked one conn
reference for every received ACL packet.

bt_conn_receive() also consumes the buffer on every path: it forwards
to l2cap (which releases) or stores the buffer in conn->rx without an
addref. The hci_rx_work() worker then called bt_buf_release() on the
same buffer, which caused a double free or use-after-free.

Take an extra buffer reference for the worker to release, and release
the connection reference from the lookup.

Assisted-by: Fable
Signed-off-by: AbhinavMir <atg271@gmail.com>
This commit is contained in:
AbhinavMir
2026-08-15 11:51:19 +08:00
committed by Xiang Xiao
parent 36a971567a
commit a79734d6df
+2
View File
@@ -265,7 +265,9 @@ static void hci_acl(FAR struct bt_buf_s *buf)
return;
}
bt_buf_addref(buf);
bt_conn_receive(conn, buf, flags);
bt_conn_release(conn);
}
/* HCI event processing */