diff mbox series

[BlueZ] avrcp: Fix crash while handling unsupported events

Message ID 20230330234425.1064422-1-luiz.dentz@gmail.com
State New
Headers show
Series [BlueZ] avrcp: Fix crash while handling unsupported events | expand

Commit Message

Luiz Augusto von Dentz March 30, 2023, 11:44 p.m. UTC
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>

The following crash can be observed if the remote peer send and
unsupported event:

ERROR: AddressSanitizer: heap-use-after-free on address 0x60b000148f11
 at pc 0x559644552088 bp 0x7ffe28b3c7b0 sp 0x7ffe28b3c7a0
 WRITE of size 1 at 0x60b000148f11 thread T0
     #0 0x559644552087 in avrcp_handle_event profiles/audio/avrcp.c:3907
     #1 0x559644536c22 in control_response profiles/audio/avctp.c:939
     #2 0x5596445379ab in session_cb profiles/audio/avctp.c:1108
     #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43)
     #4 0x7fbcb3ea66c7  (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0xaa6c7)
     #5 0x7fbcb3e512b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2)
     #6 0x559644754ab6 in mainloop_run src/shared/mainloop-glib.c:66
     #7 0x559644755606 in mainloop_run_with_signal src/shared/mainloop-notify.c:188
     #8 0x5596445bb963 in main src/main.c:1289
     #9 0x7fbcb3bafd8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
     #10 0x7fbcb3bafe3f in __libc_start_main_impl ../csu/libc-start.c:392
     #11 0x5596444e8224 in _start (/usr/local/libexec/bluetooth/bluetoothd+0xf0224)
---
 profiles/audio/avrcp.c | 6 ++++++
 1 file changed, 6 insertions(+)

Comments

bluez.test.bot@gmail.com March 31, 2023, 2 a.m. UTC | #1
This is automated email and please do not reply to this email!

Dear submitter,

Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/project/bluetooth/list/?series=735621

---Test result---

Test Summary:
CheckPatch                    FAIL      0.74 seconds
GitLint                       FAIL      0.54 seconds
BuildEll                      PASS      26.44 seconds
BluezMake                     PASS      753.07 seconds
MakeCheck                     PASS      11.41 seconds
MakeDistcheck                 PASS      148.65 seconds
CheckValgrind                 PASS      240.95 seconds
CheckSmatch                   PASS      323.46 seconds
bluezmakeextell               PASS      96.96 seconds
IncrementalBuild              PASS      604.17 seconds
ScanBuild                     PASS      962.23 seconds

Details
##############################
Test: CheckPatch - FAIL
Desc: Run checkpatch.pl script
Output:
[BlueZ] avrcp: Fix crash while handling unsupported events
WARNING:COMMIT_LOG_LONG_LINE: Possible unwrapped commit description (prefer a maximum 75 chars per line)
#90: 
     #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43)

/github/workspace/src/src/13195053.patch total: 0 errors, 1 warnings, 12 lines checked

NOTE: For some of the reported defects, checkpatch may be able to
      mechanically convert to the typical style using --fix or --fix-inplace.

/github/workspace/src/src/13195053.patch has style problems, please review.

NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO

NOTE: If any of the errors are false positives, please report
      them to the maintainer, see CHECKPATCH in MAINTAINERS.


##############################
Test: GitLint - FAIL
Desc: Run gitlint
Output:
[BlueZ] avrcp: Fix crash while handling unsupported events

WARNING: I3 - ignore-body-lines: gitlint will be switching from using Python regex 'match' (match beginning) to 'search' (match anywhere) semantics. Please review your ignore-body-lines.regex option accordingly. To remove this warning, set general.regex-style-search=True. More details: https://jorisroovers.github.io/gitlint/configuration/#regex-style-search
14: B1 Line exceeds max length (98>80): "     #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43)"
16: B1 Line exceeds max length (90>80): "     #5 0x7fbcb3e512b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2)"
18: B1 Line exceeds max length (83>80): "     #7 0x559644755606 in mainloop_run_with_signal src/shared/mainloop-notify.c:188"
20: B1 Line exceeds max length (90>80): "     #9 0x7fbcb3bafd8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58"
22: B1 Line exceeds max length (83>80): "     #11 0x5596444e8224 in _start (/usr/local/libexec/bluetooth/bluetoothd+0xf0224)"


---
Regards,
Linux Bluetooth
patchwork-bot+bluetooth@kernel.org March 31, 2023, 10:10 p.m. UTC | #2
Hello:

This patch was applied to bluetooth/bluez.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@intel.com>:

On Thu, 30 Mar 2023 16:44:25 -0700 you wrote:
> From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
> 
> The following crash can be observed if the remote peer send and
> unsupported event:
> 
> ERROR: AddressSanitizer: heap-use-after-free on address 0x60b000148f11
>  at pc 0x559644552088 bp 0x7ffe28b3c7b0 sp 0x7ffe28b3c7a0
>  WRITE of size 1 at 0x60b000148f11 thread T0
>      #0 0x559644552087 in avrcp_handle_event profiles/audio/avrcp.c:3907
>      #1 0x559644536c22 in control_response profiles/audio/avctp.c:939
>      #2 0x5596445379ab in session_cb profiles/audio/avctp.c:1108
>      #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43)
>      #4 0x7fbcb3ea66c7  (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0xaa6c7)
>      #5 0x7fbcb3e512b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2)
>      #6 0x559644754ab6 in mainloop_run src/shared/mainloop-glib.c:66
>      #7 0x559644755606 in mainloop_run_with_signal src/shared/mainloop-notify.c:188
>      #8 0x5596445bb963 in main src/main.c:1289
>      #9 0x7fbcb3bafd8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
>      #10 0x7fbcb3bafe3f in __libc_start_main_impl ../csu/libc-start.c:392
>      #11 0x5596444e8224 in _start (/usr/local/libexec/bluetooth/bluetoothd+0xf0224)
> 
> [...]

Here is the summary with links:
  - [BlueZ] avrcp: Fix crash while handling unsupported events
    https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=f54299a85067

You are awesome, thank you!
diff mbox series

Patch

diff --git a/profiles/audio/avrcp.c b/profiles/audio/avrcp.c
index 80f34c7a77a1..dda9a303fb71 100644
--- a/profiles/audio/avrcp.c
+++ b/profiles/audio/avrcp.c
@@ -3901,6 +3901,12 @@  static gboolean avrcp_handle_event(struct avctp *conn, uint8_t code,
 	case AVRCP_EVENT_UIDS_CHANGED:
 		avrcp_uids_changed(session, pdu);
 		break;
+	default:
+		if (event > AVRCP_EVENT_LAST) {
+			warn("Unsupported event: %u", event);
+			return FALSE;
+		}
+		break;
 	}
 
 	session->registered_events |= (1 << event);