summaryrefslogtreecommitdiffstats
path: root/net/bluetooth/smp.c
diff options
context:
space:
mode:
authorDavid S. Miller <davem@davemloft.net>2015-07-27 06:53:08 +0200
committerDavid S. Miller <davem@davemloft.net>2015-07-27 06:53:08 +0200
commit03de104f7b62b4cebd8a3d33cef82d48ff28144c (patch)
tree75c076d342fa2d17058c4033d44ef9565700fd84 /net/bluetooth/smp.c
parentnet: fec: introduce fec_ptp_stop and use in probe fail path (diff)
parentBluetooth: Fix NULL pointer dereference in smp_conn_security (diff)
downloadlinux-03de104f7b62b4cebd8a3d33cef82d48ff28144c.tar.xz
linux-03de104f7b62b4cebd8a3d33cef82d48ff28144c.zip
Merge branch 'for-upstream' of git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth
Johan Hedberg says: ==================== pull request: bluetooth 2015-07-23 Here's another one-patch pull request for 4.2 which targets a potential NULL pointer dereference in the LE Security Manager code that can be triggered by using older user space tools. The issue has been there since 4.0 so there's the appropriate "Cc: stable" in place. Let me know if there are any issues pulling. Thanks. ==================== Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/bluetooth/smp.c')
-rw-r--r--net/bluetooth/smp.c4
1 files changed, 4 insertions, 0 deletions
diff --git a/net/bluetooth/smp.c b/net/bluetooth/smp.c
index 3d0f7d2a0616..ad82324f710f 100644
--- a/net/bluetooth/smp.c
+++ b/net/bluetooth/smp.c
@@ -2312,6 +2312,10 @@ int smp_conn_security(struct hci_conn *hcon, __u8 sec_level)
return 1;
chan = conn->smp;
+ if (!chan) {
+ BT_ERR("SMP security requested but not available");
+ return 1;
+ }
if (!hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED))
return 1;