syzbot


bluetooth subsystem


List(s): [email protected]
Maintainer(s): [email protected], [email protected]
Fixed bugs: 83
Parent subsystem(s): kernel (86)
open (57):
Title Repro Cause bisect Fix bisect Count Last Reported Discussions
WARNING in hci_conn_drop (2) bluetooth 1 4d11h 11h24m
INFO: task hung in hci_remote_features_evt (2) bluetooth syz 2 5d04h 2d08h
general protection fault in lookup_or_create_module_kobject bluetooth usb C 255 2h32m 4d02h
KASAN: slab-out-of-bounds Read in hci_cmd_sync_alloc bluetooth C 4 9d01h 5d03h
KASAN: slab-use-after-free Read in bt_accept_dequeue (2) bluetooth 1 15d 11d
possible deadlock in l2cap_conn_del bluetooth syz error 114 15h09m 38d
KASAN: vmalloc-out-of-bounds Read in hci_devcd_dump bluetooth C 519 17h34m 38d 💬 1 [15d]
BUG: soft lockup in hci_cmd_timeout (2) bluetooth usb syz 1 54d 50d
KASAN: wild-memory-access Read in l2cap_connect_cfm bluetooth 5 29d 52d
WARNING in hci_send_cmd (2) bluetooth 2 11d 72d
possible deadlock in l2cap_info_timeout bluetooth 12 2d18h 72d
WARNING: refcount bug in sco_conn_put bluetooth 1 81d 76d
general protection fault in h5_close bluetooth C done 5 74d 77d
general protection fault in bcsp_close bluetooth C done 3 79d 77d
general protection fault in bcsp_recv bluetooth C error 209 17h01m 82d
general protection fault in h5_recv bluetooth C done 314 8h30m 88d 💬 1 [16d]
general protection fault in __timer_delete_sync bluetooth C done 3 86d 90d 💬 1 [89d]
general protection fault in qca_close bluetooth C done 94 73d 91d PATCH [91d]
KASAN: null-ptr-deref Write in l2cap_sock_resume_cb (3) bluetooth 8 55d 101d
KASAN: slab-use-after-free Read in sock_def_readable bluetooth net 3 85d 102d
KASAN: slab-use-after-free Read in force_suspend_read bluetooth 8 83d 110d
general protection fault in hci_devcd_register bluetooth 25 2d04h 118d
WARNING in hci_devcd_register bluetooth 3 45d 124d
KASAN: slab-use-after-free Read in full_proxy_write bluetooth C 36 62d 131d
KASAN: slab-use-after-free Read in msft_opcode_get bluetooth 15 15d 133d
KASAN: slab-use-after-free Read in force_devcd_write bluetooth syz 342 20h49m 135d 💬 1 [16d]
WARNING in sco_conn_put bluetooth 2 78d 138d
WARNING: held lock freed in bt_accept_dequeue bluetooth 4 7d15h 142d
WARNING in hci_conn_timeout (2) bluetooth C error 412 11h44m 142d
KASAN: slab-use-after-free Write in sco_conn_put bluetooth 95 44d 158d
KASAN: slab-use-after-free Read in l2cap_disconn_ind bluetooth 2 96d 167d
KMSAN: uninit-value in hci_cmd_complete_evt bluetooth C 17 36d 173d
INFO: task hung in hci_cmd_sync_clear (3) bluetooth syz done 5 12d 181d
KASAN: slab-use-after-free Read in l2cap_register_user bluetooth 11 10d 182d
KASAN: slab-use-after-free Read in l2cap_unregister_user bluetooth syz done 37024 now 188d 💬 1 [16d]
BUG: corrupted list in hci_cmd_sync_dequeue_once bluetooth 30 6d01h 200d
KASAN: slab-use-after-free Read in bt_accept_unlink bluetooth 28 15d 200d
KASAN: slab-use-after-free Read in l2cap_sock_new_connection_cb bluetooth 34 22d 200d
KASAN: slab-use-after-free Read in cmd_complete_rsp bluetooth 18 56d 200d
KASAN: slab-use-after-free Read in l2cap_sock_ready_cb (2) bluetooth 45 12d 219d
BUG: corrupted list in _hci_cmd_sync_cancel_entry bluetooth 14 4h15m 223d
BUG: corrupted list in mgmt_pending_remove bluetooth C error 42 8d05h 250d 💬 1 [161d]
WARNING: ODEBUG bug in hci_release_dev (2) bluetooth C error 243 4d04h 288d
possible deadlock in sco_connect_cfm bluetooth 21 58d 304d
KASAN: slab-use-after-free Read in hci_sock_get_cookie (2) bluetooth 46 7d01h 323d
BUG: sleeping function called from invalid context in lock_sock_nested (3) bluetooth C inconclusive 141 43d 360d 💬 2 [49d]
possible deadlock in mgmt_remove_adv_monitor_complete bluetooth C unreliable 39 21d 371d
KASAN: slab-use-after-free Read in l2cap_recv_frame bluetooth C inconclusive inconclusive 137 8d23h 377d 💬 2 [80d]
WARNING in hci_recv_frame bluetooth syz error 59 7d07h 377d 💬 1 [169d]
KASAN: slab-use-after-free Read in hci_disconnect bluetooth 27 7d01h 378d
WARNING in l2cap_chan_send bluetooth 43 18d 390d
KASAN: slab-use-after-free Read in __hci_req_sync bluetooth C error error 3383 268d 396d 💬 2 [302d]
WARNING in l2cap_chan_del bluetooth 208 11h38m 417d
general protection fault in lock_sock_nested bluetooth C done done 2163 1h34m 606d
WARNING in call_timer_fn bluetooth C unreliable 6640 28m 904d 💬 8 [16d]
general protection fault in l2cap_chan_timeout (3) bluetooth C inconclusive inconclusive 33 2d21h 1183d
general protection fault in skb_release_data (2) net bluetooth C done error 703 38d 1702d
moderation (1):
Title Repro Cause bisect Fix bisect Count Last Reported Discussions
KASAN: slab-use-after-free Read in hidp_session_thread bluetooth 3 34d 84d
OSZAR »