Commit 2a5a5ec6 authored by Andrei Emeltchenko's avatar Andrei Emeltchenko Committed by Johan Hedberg
Browse files

Bluetooth: Use list _safe deleting from conn chan_list



Fixes possible bug when deleting element from the list in
function hci_chan_list_flush. list_for_each_entry_rcu is used
and after deleting element from the list we also free pointer
and then list_entry_rcu is taken from freed pointer.

Signed-off-by: default avatarAndrei Emeltchenko <andrei.emeltchenko@intel.com>
Acked-by: default avatarMarcel Holtmann <marcel@holtmann.org>
Signed-off-by: default avatarJohan Hedberg <johan.hedberg@intel.com>
parent 3c4e0df0
Loading
Loading
Loading
Loading
+2 −2
Original line number Diff line number Diff line
@@ -975,10 +975,10 @@ int hci_chan_del(struct hci_chan *chan)

void hci_chan_list_flush(struct hci_conn *conn)
{
	struct hci_chan *chan;
	struct hci_chan *chan, *n;

	BT_DBG("conn %p", conn);

	list_for_each_entry_rcu(chan, &conn->chan_list, list)
	list_for_each_entry_safe(chan, n, &conn->chan_list, list)
		hci_chan_del(chan);
}