From nobody Sun May 24 22:33:46 2026 Received: from mail-qv1-f49.google.com (mail-qv1-f49.google.com [209.85.219.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B462B41754 for ; Thu, 21 May 2026 00:13:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779322415; cv=none; b=myz76vnZYw6A+Nsy74m6OG2k186p2QoD6GR553mr9H0YI3bjXrwZ8RR6w1jLNIdOLDnLTxAcTfMQKnYr0DhqVgyUs/aLehU/O2X7HL3ujIZ/zXEUgrTcuEurr8aY7LxNsouBhad/zCI8Fv53bl03LNsJ3ySybsR7nQdT5dr11tU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779322415; c=relaxed/simple; bh=FlsmVjLwUtTt/F4MvdmnB8CMJCrNXKRgcWVC4IHb4pY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=lie/UZgdBq/A+nlopAQ9o2xCSLQfxc3Rl1CI7fn7FAKq2TpMSVbCV2IOaAn5twaSWQSqPYQB8w87aY0hkFGczdI9E8dUqmnvJ6XqTnhNHqCk8uGsExY3ssKVf3i860QqYVXpYGYBvI++hvQktbI+J1CfbFtfT5eTeOqJSpzRfeE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=rwMtHCJh; arc=none smtp.client-ip=209.85.219.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="rwMtHCJh" Received: by mail-qv1-f49.google.com with SMTP id 6a1803df08f44-8b4000e51fdso59179766d6.1 for ; Wed, 20 May 2026 17:13:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779322413; x=1779927213; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=3Ec1/vUBu03Pfy6PXr2QzxM/B7hkCHbmI2D/iRwpt3o=; b=rwMtHCJhbWKvdE2kSBfBRrgi++M1yJlOZWSPo8LWbCUeT+w7n3HTtU4Ef2ogwE2Cbd UlKX8nKutirYHy+XjM3HgLiyJ1tetB7EeTKunPuApm7pI5UjPv0J7dXfAbMYbW9Dkmsl uvOfO3s4kpjrDI2uumV7H0QWWjPGHBQG8Yw73k84Mi6lTRoMnaRwC+p70FkoCz1xxmcf bsvBkl6JL6lLT9Lo4+w+9klVt996+XbXt5mVC1ZL95uyb1sV+nlodp4ejH+eaXqp/6rW qjGFEsFE3hQjuBuuoahRr63edSLpfqQY7F8yYGWkE+WTLbPigdb9Q9xp0FXeUHzOnztB Bdzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779322413; x=1779927213; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=3Ec1/vUBu03Pfy6PXr2QzxM/B7hkCHbmI2D/iRwpt3o=; b=O2yKKgHBOK/tk4kiiEVzL6VvrS5gp0ejlQNGMOaigAf/84yDO3iqPkvrLCh5DX+1WT GBmTOMGtuZv84IFMqVSZ6x7xsjNPy7zk/JX39qobCe0wXWwIFn0d6bI/8nEcJFQldtKr N20J59vQ2orSeZeFcgS6G32Y2FKPfvcz+0bPUKVV3huRX0UNZvHFqc6S06Mx3qZpRM/I UPtWJWPoP75hU895Hd9htXgxeMhlb26qENDazHgmwScXoSRulrNkk5tHnqc+yjQayxMZ MuDThUFJ7Fc5ukQcnkeia2b5o1vBn1upuF8ugMRC5GFzXipVhG5MdeYJ8k251+J7o4uq cufw== X-Forwarded-Encrypted: i=1; AFNElJ/PlEV8mun44QiFAgBI9m+iWOIwj0zVw7IciVxCAd3N1gnhsjkfygm9BEAGWiY/ULb2GOln54Tg38wR3C8=@vger.kernel.org X-Gm-Message-State: AOJu0YzfwTPzHcHZiFWgGkfrsOzy5rYZCIuMhi2aO+E13G+n4hzEJKUn 6jbxY2FnzpBW6fBhv9wZSoBSbSy35fwsxg/AKi8bil1mbVWt50Lprn4G X-Gm-Gg: Acq92OGTTH6qLL3zSp2KEScecZr2ZYgDpw3o1kzPFLAzT8kwVSoZw9P+69g0094I9gt hkJAvf/JdAcnu4Luivl9w5BkYklYLK35p2JBjh4mmSU18tdeV+X86BaLqz5oBcG0+zNm0fQ2UM5 bCBwt1SNlc1Vd9EsbEmOHCKpsfEFdfGMBpDKWmfeNcu2YSWnzumS2fW5NpcM/F9/4mvygTED3Rq 0uk/5wQOozQaOkjOVzg4XjZwJpH3UKr7KywU+SbxIldOOWyyfwtSHCHHQ8Gc5ocJgKjDVxgtkLn Yg/MV8K3HkRi9cM1G4EoHu+tRqXAywMxNfxHi3beqPN4NMpAewNGai9jUPZGZcWzMhK0aZvxW7Z 95oW9EPXyUO8AOPol32sPPlIfg3l3cabtEzm/7apCAJk3qgWdBXwSDxXspJXoaO2QJizAdpuMos NJr3y9DWqx7QfEu1FiqlUqXmWFHnEqXbtEp0LOyFpsY3Vjdp9uoI4ubFaqaGVD/JNeofqSzpVhT NsHlY363kYrtCTqJMaG X-Received: by 2002:a05:6214:1d0d:b0:8ca:1d2d:4a51 with SMTP id 6a1803df08f44-8cc6e6b5769mr11687466d6.49.1779322412647; Wed, 20 May 2026 17:13:32 -0700 (PDT) Received: from server0 (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8ca36096575sm134875496d6.13.2026.05.20.17.13.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 20 May 2026 17:13:32 -0700 (PDT) From: Michael Bommarito To: Marcel Holtmann , Luiz Augusto von Dentz Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , linux-bluetooth@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v3] Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig Date: Wed, 20 May 2026 20:13:27 -0400 Message-ID: <20260521001327.3729880-1-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" net/bluetooth/l2cap_core.c:l2cap_sig_channel() accepts BR/EDR signaling packets up to the channel MTU and dispatches each command without enforcing the signaling MTU (MTUsig). A Bluetooth BR/EDR peer within radio range can send a fixed-channel CID 0x0001 packet that is larger than MTUsig and contains many L2CAP_ECHO_REQ commands before pairing. In a real-radio stock-kernel run, one 681-byte signaling packet containing 168 zero-length ECHO_REQ commands made the target transmit 168 ECHO_RSP frames over about 220 ms. Impact: a Bluetooth BR/EDR peer within radio range, before pairing, can force 168 ECHO_RSP frames from one 681-byte fixed-channel signaling packet containing packed ECHO_REQ commands. Define Linux's BR/EDR signaling MTU as the spec minimum of 48 bytes and reject any larger signaling packet with one L2CAP_COMMAND_REJECT_RSP carrying L2CAP_REJ_MTU_EXCEEDED before any command is dispatched. The Bluetooth Core spec wording for MTUExceeded says the reject identifier shall match the first request command in the packet, and that packets containing only responses shall be silently discarded. Linux intentionally deviates from that prescription: silently discarding desynchronizes the peer because the remote stack never learns its responses were dropped, and locating the first request command requires walking command headers past MTUsig, i.e. processing bytes from a packet we have already decided is too large to process. We therefore always emit one reject and use the identifier from the first command header (a single fixed-offset byte read), falling back to zero when the packet is too short to carry a header at all. The unrestricted BR/EDR signaling parser and ECHO_REQ response path both trace to the initial git import; no later introducing commit is available for a Fixes tag. Cc: stable@vger.kernel.org Suggested-by: Luiz Augusto von Dentz Link: https://lore.kernel.org/r/20260518002800.1361430-1-michael.bommarito@= gmail.com Link: https://lore.kernel.org/r/20260520135034.1060859-1-michael.bommarito@= gmail.com Assisted-by: Claude:claude-opus-4-7 Assisted-by: Codex:gpt-5-5-xhigh Signed-off-by: Michael Bommarito --- Resending as top level message per netdev guidance. I reproduced the stock behavior with a real-radio BR/EDR ACL link and a harness that sends a single fixed-channel signaling packet containing packed zero-length ECHO_REQ commands, and confirmed on a patched kernel that the same packet now produces one L2CAP_REJ_MTU_EXCEEDED command reject and zero ECHO_RSP frames. The patched code builds for net/bluetooth/l2cap_core.o on x86_64 defconfig with W=3D1. There are no in-tree Bluetooth selftests that reference l2cap_sig_channel(), L2CAP_SIG_MTU, or L2CAP_ECHO_REQ. Changes in v3: - Drop l2cap_sig_cmd_is_req() and l2cap_sig_first_req_ident(); the reject is now unconditional and uses only the first command header's identifier byte at a fixed offset. Per Luiz, the spec's "match the first request command identifier" rule would require parsing past MTUsig, and the spec's "silently discard if only responses" rule desynchronizes the peer. - Replace the v2 walk with a verbose comment quoting the relevant Bluetooth Core section and documenting why Linux deviates. Changes in v2: - Replace the per-PDU echo-count cap with the MTUsig direction from review. - Reject the whole over-MTUsig signaling packet with one L2CAP_REJ_MTU_EXCEEDED command reject. - Add L2CAP_SIG_MTU and drop over-MTUsig packets when no valid request command identifier is found. v1: https://lore.kernel.org/r/20260518002800.1361430-1-michael.bommarito@gm= ail.com v2: https://lore.kernel.org/r/20260520135034.1060859-1-michael.bommarito@gm= ail.com --- include/net/bluetooth/l2cap.h | 1 + net/bluetooth/l2cap_core.c | 47 +++++++++++++++++++++++++++++++++++ 2 files changed, 48 insertions(+) diff --git a/include/net/bluetooth/l2cap.h b/include/net/bluetooth/l2cap.h index 5172afee54943..e0a1f2293679a 100644 --- a/include/net/bluetooth/l2cap.h +++ b/include/net/bluetooth/l2cap.h @@ -33,6 +33,7 @@ /* L2CAP defaults */ #define L2CAP_DEFAULT_MTU 672 #define L2CAP_DEFAULT_MIN_MTU 48 +#define L2CAP_SIG_MTU 48 /* BR/EDR signaling MTU */ #define L2CAP_DEFAULT_FLUSH_TO 0xFFFF #define L2CAP_EFS_DEFAULT_FLUSH_TO 0xFFFFFFFF #define L2CAP_DEFAULT_TX_WINDOW 63 diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c index 7701528f11677..0b1e062057695 100644 --- a/net/bluetooth/l2cap_core.c +++ b/net/bluetooth/l2cap_core.c @@ -5618,6 +5618,15 @@ static inline void l2cap_sig_send_rej(struct l2cap_c= onn *conn, u16 ident) l2cap_send_cmd(conn, ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej); } =20 +static inline void l2cap_sig_send_mtu_rej(struct l2cap_conn *conn, u8 iden= t) +{ + struct l2cap_cmd_rej_mtu rej; + + rej.reason =3D cpu_to_le16(L2CAP_REJ_MTU_EXCEEDED); + rej.max_mtu =3D cpu_to_le16(L2CAP_SIG_MTU); + l2cap_send_cmd(conn, ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej); +} + static inline void l2cap_sig_channel(struct l2cap_conn *conn, struct sk_buff *skb) { @@ -5630,6 +5639,44 @@ static inline void l2cap_sig_channel(struct l2cap_co= nn *conn, if (hcon->type !=3D ACL_LINK) goto drop; =20 + /* + * Bluetooth Core v5.4, Vol 3, Part A, Section 4: the BR/EDR + * signaling channel has a fixed signaling MTU (MTUsig) whose + * minimum and default is 48 octets. Section 4.1 says that on + * an MTUExceeded command reject the identifier "shall match + * the first request command in the L2CAP packet" and that + * packets containing only response commands "shall be + * silently discarded". + * + * Linux intentionally deviates from that prescription: + * + * 1. Silently discarding desynchronizes the peer. The + * remote stack never learns its responses were dropped, + * so any state machine waiting on a paired response + * stalls until its own timer fires. + * + * 2. Locating "the first request command" requires walking + * command headers past MTUsig, i.e. processing bytes + * from a packet we have already decided is too large to + * process. + * + * Reject every over-MTUsig signaling packet with one + * L2CAP_REJ_MTU_EXCEEDED command reject. The reject's + * reason field is what tells the peer that the whole packet + * was discarded; the identifier value is informational, so + * we use the identifier from the first command header (a + * single fixed-offset byte read) or zero when the packet is + * too short to carry even one header. + */ + if (skb->len > L2CAP_SIG_MTU) { + u8 ident =3D (skb->len >=3D L2CAP_CMD_HDR_SIZE) ? + skb->data[1] : 0; + + BT_DBG("signaling packet exceeds MTU"); + l2cap_sig_send_mtu_rej(conn, ident); + goto drop; + } + while (skb->len >=3D L2CAP_CMD_HDR_SIZE) { u16 len; =20 --=20 2.53.0