mirror of
https://github.com/apache/nuttx.git
synced 2026-08-17 09:33:18 +08:00
hci_acl() looked up the connection with bt_conn_lookup_handle(), which returns a new reference, but never released it. This leaked one conn reference for every received ACL packet. bt_conn_receive() also consumes the buffer on every path: it forwards to l2cap (which releases) or stores the buffer in conn->rx without an addref. The hci_rx_work() worker then called bt_buf_release() on the same buffer, which caused a double free or use-after-free. Take an extra buffer reference for the worker to release, and release the connection reference from the lookup. Assisted-by: Fable Signed-off-by: AbhinavMir <atg271@gmail.com>