From nobody Fri Sep 25 03:16:24 2026 Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E12473B8111 for ; Thu, 17 Sep 2026 04:00:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.141 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789617619; cv=none; b=iRcAuhWEZQqR7qiLQ7V6mMqYDUL1gWCnZyeHj8X/GIlO5JZQc4Il3twb60TPxxZXMbUj38XFIU+iQrhJvLLqlvRPJfkfnPoSxzltb9JkepSlXPt6roZbG+zV/S61F8Pbi/SuaF9MkW4raa/eAd03uXhFLz1U+vNvGbj/kIbM9Ig= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789617619; c=relaxed/simple; bh=t6kqad3R5WgeKWtDof9fjSN4rKNL6g8fBl1fgnljyQY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=dLlo2jZ6sW/kHjICHAhlz7oj7lhNpgvwuWgpeo3+56yjln70J6PeJRR43QKkRW963fplTKpmyWorF8PGSAEEi+IaXFg6AcwxlTkgmBHpsQP4/mT2JphjPb/JVTxvaVttfI3po9A8jGyNGLeRAjvTBuFWwVOtfFJWdsQXclLq6Ps= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KRWCu49k; arc=none smtp.client-ip=74.125.225.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KRWCu49k" Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e721b5503so3341165e9.0 for ; Wed, 16 Sep 2026 21:00:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789617615; x=1790222415; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pBijyL0HZR3/5g7v7DmejWL3K0668IdfViWW12KzHHg=; b=KRWCu49kYszdxlHpATD5vkmIMj2m8Kip6NJW/tt5iDBcrV/mep4+DF9I4W2VDvb8h9 ILHMmk21bIooIfHTXBz1Bb0xqQ700Fu20BGvp3ouDBSdHijiXkhhJzocpnM7ln3nSpr2 x1a1n68/0oqhei9FtT+kVAjxDMx8FuV1n15jsPw5iYCkCoa1d/MeagS1gTUTf/Td/zBc fR+pDGybqD19mbkla1VMryN7fsbV12WqJoPCPEFKsNg6KEoh8WbWNf4tFuKNrkP3IyBd +XvxiX/9D2QPrbMTI9bjdIp1y3k8xkC6bz7TX9AFon1zUedDHya+wDhYOAx1vB8eDJJk 4vlA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789617615; x=1790222415; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=pBijyL0HZR3/5g7v7DmejWL3K0668IdfViWW12KzHHg=; b=PMI9HWJ1mTMjVz84/dzkWjWU5HNtxg5+zEM5FuyX8Jblp4qJj1I4M8GFpqi1ojknLA BJ6EJH5CD5/+0DrDDIg4VL/IED9Ak5Ta8Fct5idaCO1Rw3hxkm94ZVzNy4ge3XUydFzz dqDnpKLJ4ZKlzmANjbMIWVRTpZQ+HM7ls/Fp8sMGy+JTMGssHmzbU3uU2/S16fpaJOwR Uu/D+9XbeLQ32tzLrDOyLVTi/wGUbzAkJRZ2N0tsmcwMYIuVBsNFPXCJJaKXDhHpoqfQ eeWY3rBwvN2Xpd7f2gED/IMHR2uO7rUYqd27Z9iyYO7MWISytfAtLlkoWz47KO+wz1cA z2YQ== X-Forwarded-Encrypted: i=1; AKwUvBzbc7f27MHqbHw1NlkYkw190eOhXuKD6BseGuyPTlvgJxhBkMozYN544mT8UA7760QZrJ4diMwM0FDVCvI=@vger.kernel.org X-Gm-Message-State: AFuF++mA9s1GWhX0eKgp6sdVtgxox6+VwCRXPFDhaLXujfKHjM4GyYQo 0iy1f6aqR6UqOGE7vGqIwloMOOfZXZYjoUV29SYlT5OkqG1wDzcoN8gQssSNtR1m X-Gm-Gg: AYBFou2qpmZZAo1TgaHQofu/+wYqkxztrj4d61XDUg5oenAqOQWH3Cof1ujG1Fg9FZh Xpswk7/V0zA4z0hQDX3QeztxWXjy4nHj9PgrkfDl2d9X5+HCG1TB5NmK1k9fpTt5pzACtlish/b +PxWr4FxQsEU23ONuDthxW3uuA4n9PhIDqyhgBaTYY2jd0goArneUaBe7cEX/tdPEA83E462vgw jCUH+/R7pAuP0T4ZxPWZSiq9zZRIRJAsk6wtpUGja1E0MBeL1AqdDIJGGNiKOX7vkAO6cQ6NWTd g/it9aZp7ZQ0/KuvqaO+ZhpIrhDckxFDsU0qeOYcV4dluFvPJ6b/GnnhSlPaT3wJVK02K0P2KM8 hOSnX/SUAg3z+iQxiC5Hwdo5Z67CtSKVgAyPnIk9aEhbqNxuKfjA6imI9SnejypnzIdnVmmNM8X T4lhq/pxRv/DBEJXU7SKU0Rv6njF0jEcPG7AN4lDUYbutsVxN5lqjh9P7roN8MIDoEDDmvy9IWM S+p3Uu1u3pi2TfYiCSdBuONyFbcRJr1ZisZrURAorr1DtO72Pfa8+4yrZ4sXHnUyVwuQzfR9rBq JEjrpZSkd7nsIhZAUHpw44Mf7fy8x84967qWNhiaC+1eLewLH/aG+pV68k4shcUdX92HzzZ+XN4 S X-Received: by 2002:a05:600c:3e0a:b0:49e:81db:4926 with SMTP id 5b1f17b1804b1-49eac4638femr61582055e9.5.1789617614946; Wed, 16 Sep 2026 21:00:14 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-9dc6-c001-54ee-4741-4927-0a28.310.pool.telefonica.de. [2a02:3100:9dc6:c001:54ee:4741:4927:a28]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fbfd935cfsm6880015e9.0.2026.09.16.21.00.12 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 16 Sep 2026 21:00:13 -0700 (PDT) From: Karl Mehltretter To: stable@vger.kernel.org Cc: Karl Mehltretter , gregkh@linuxfoundation.org, sashal@kernel.org, luiz.dentz@gmail.com, luiz.von.dentz@intel.com, marcel@holtmann.org, johan.hedberg@gmail.com, eadavis@qq.com, davem@davemloft.net, kuba@kernel.org, linux-bluetooth@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, patches@lists.linux.dev, pav@iki.fi, syzbot+b7f6f8c9303466e16c8a@syzkaller.appspotmail.com Subject: [PATCH 5.15.y 1/2] Bluetooth: L2CAP: Fix deadlock Date: Thu, 17 Sep 2026 06:00:03 +0200 Message-Id: <20260917040004.21041-2-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260917040004.21041-1-kmehltretter@gmail.com> References: <20260912065526.833703348@linuxfoundation.org> <20260912065546.976652519@linuxfoundation.org> <20260913202907.3100-1-kmehltretter@gmail.com> <20260917040004.21041-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Luiz Augusto von Dentz [ Upstream commit f1a8f402f13f94263cf349216c257b2985100927 ] This fixes the following deadlock introduced by 39a92a55be13 ("bluetooth/l2cap: sync sock recv cb and release") =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D WARNING: possible recursive locking detected 6.10.0-rc3-g4029dba6b6f1 #6823 Not tainted -------------------------------------------- kworker/u5:0/35 is trying to acquire lock: ffff888002ec2510 (&chan->lock#2/1){+.+.}-{3:3}, at: l2cap_sock_recv_cb+0x44/0x1e0 but task is already holding lock: ffff888002ec2510 (&chan->lock#2/1){+.+.}-{3:3}, at: l2cap_get_chan_by_scid+0xaf/0xd0 other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(&chan->lock#2/1); lock(&chan->lock#2/1); *** DEADLOCK *** May be due to missing lock nesting notation 3 locks held by kworker/u5:0/35: #0: ffff888002b8a940 ((wq_completion)hci0#2){+.+.}-{0:0}, at: process_one_work+0x750/0x930 #1: ffff888002c67dd0 ((work_completion)(&hdev->rx_work)){+.+.}-{0:0}, at: process_one_work+0x44e/0x930 #2: ffff888002ec2510 (&chan->lock#2/1){+.+.}-{3:3}, at: l2cap_get_chan_by_scid+0xaf/0xd0 To fix the original problem this introduces l2cap_chan_lock at l2cap_conless_channel to ensure that l2cap_sock_recv_cb is called with chan->lock held. Fixes: 89e856e124f9 ("bluetooth/l2cap: sync sock recv cb and release") Signed-off-by: Luiz Augusto von Dentz [ Karl Mehltretter: backport only the l2cap_core.c changes. The HCI changes are from an unrelated patch accidentally squashed into this commit. The l2cap_sock.c change removes locking added by 89e856e124f9, which is absent from 5.15.y, so the quoted deadlock cannot occur. The core changes are needed because c531e63871c0 was backported without the matching lock. ] Assisted-by: LLM Signed-off-by: Karl Mehltretter --- diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c index 34f89f7f993b..f1d7a6cdd8aa 100644 --- a/net/bluetooth/l2cap_core.c +++ b/net/bluetooth/l2cap_core.c @@ -7992,6 +7992,8 @@ static void l2cap_conless_channel(struct l2cap_conn *= conn, __le16 psm, =20 BT_DBG("chan %p, len %d", chan, skb->len); =20 + l2cap_chan_lock(chan); + if (chan->state !=3D BT_BOUND && chan->state !=3D BT_CONNECTED) goto drop; =20 @@ -8009,6 +8011,7 @@ static void l2cap_conless_channel(struct l2cap_conn *= conn, __le16 psm, } =20 drop: + l2cap_chan_unlock(chan); l2cap_chan_put(chan); free_skb: kfree_skb(skb); --=20 2.51.0 From nobody Fri Sep 25 03:16:24 2026 Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BAD483B9D9E for ; Thu, 17 Sep 2026 04:00:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.140 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789617623; cv=none; b=qkvMzauiN9p1eqzcgyvYOZ4HO7PFdXFQnC78sYRAVDPot86LR3u2wui6GM3Q/UvChnbTgzzOGTV6yDDlbI70xCR5B9t+KE+Prv9FGILISY3qlpxGSKusZpFeoTMZ9UkFthv8dMoAdnT8f+V8e3hdLt+LrQ0VWDhjN8uwHlnfFkY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789617623; c=relaxed/simple; bh=NndGd9GOf0I6NO8Ce3nP+s13O09BbawYzE6kgfvxPZY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=IVwmRh4GBD2ck3fJveinbecqbg87U+p8i3733DSvT3zLj/517OB/h7Jf34OPvDTj7tEpx5H27T+MBo/w3bImNjHGJgYTxUkyjIJk/NCsB5Dn7ARbFQgtHUNTEHPsXVy+m/3mV225zYNb++tXjQD3k0HjZoDXt3sjWTHQ6l0hIPA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qPELqpR0; arc=none smtp.client-ip=74.125.225.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qPELqpR0" Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d3931so2559035e9.3 for ; Wed, 16 Sep 2026 21:00:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789617617; x=1790222417; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TH7pqPWttSJGp/Lqeiet7/X4Ui7u8p69YinbdJusLhk=; b=qPELqpR04YALqjxUxYX27T5X6LbKk7qrq2qS4kGgGTQpyIJTtjUNQOrjXzVat2nJR7 cvWbz/2JETY+eWMI5n/cGRtA4oVq+IorawxoFFcbvWCN/QgnI/Li/oJW55jlXl2wrhsV twyuzaKIivXO3EQQKVwb++qJFll81qA36yH9L8JeqFXW2mWXBlpS4CfuM5scboFuWneB EILTypVnyiaTrh/ZsQTpCGdE44iHP7oDfsclJ68X+avzaBrYLMBQ9PUXJCl2SNk4US4j p82EAspswa8ms4XxoRVCeSJ+NciuPPSlw3ClQAN6/sdvk+qGCMttXAnsmbCdz0v8xi83 Z1pA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789617617; x=1790222417; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TH7pqPWttSJGp/Lqeiet7/X4Ui7u8p69YinbdJusLhk=; b=kmkoBAzFkiVUvsfc85IMcKirqOgvDWCv/Y8k5hhTEK8Ywnz8CpfVdBBpukse6YjB53 pX8+XMTHna1LhkaTqZvOwoOaIFRNHbX95yYDTJRuOjSvDzE/r2PvedFUZ0Lhg4tE/9EZ fDoqC+ns9o4B+QTKPw32wJuFNkrRvseNRloW76Ov4DkYaD/vyZJHiA/J2Yn/qxOlIP9n ImZNKsm7w0VjF2dUbLjgJBjrm+HSLGGv6Brd91T/VcFkjf+AVvRAGm0+KovfSLva3iq1 tShTTsaTR8onCJ9ehUtR4OzzWEBQRjHS2mF3lNlWw7Ok5xgfn2cRIgxpvPCiyu4IQxds 2+mA== X-Forwarded-Encrypted: i=1; AKwUvBxeb2Wcv9whOq+TuML75iE6pJlrxD7+MFtr8b53/VG2ny6GpOHGupmEIgsRV1m/yxZeBDaQ11FlJ5AEr4s=@vger.kernel.org X-Gm-Message-State: AFuF++kfl/0UQwCsAxa+Voh9PxI0yfPoST2gBumvv24qcbZ+TUsHY8Yk 8d/p8fhJfWN40mUsx6Tx9mezCITDvjAlfcz/r62wuBJ+wOxFYTwoDQtF X-Gm-Gg: AYBFou0le7TPXW2AtO1GCRTv6VMQl7QDYYz9gFU6ZBMQxxgQiRnM0mERvpc2+dEJV5d A3vk9lirr5Km6I2H7QwL+sjPStsrDDiNP/Chp5lX9WyHHNNiH2AgftNTE8YCgotHtnKpdj004XH ZG3yFpnJLBTattGGq6BKA5zEeIVbZD+Kd+GaWEnA2uecilcZuXU6fJtQDtKhSKzhmET5VSoyrw4 h5fOl09PfBydOiLzvMkuQwS3NWNpoK7bJOVEW+2Cx4AvJSAFx7pLLGByKJs9zV3M8IrDHP90dnE rY8r5rcwplUxVBHDG8yezKIet76ShN1QtZd4O8b8mn9kHYK33td3d9NcsrfdnlckTrjl1Yw5sAS DvDf1q7DZKj94ZPKNciL/JSRQ7sE4+wsjoZl7tG7Ei7XsST7VzCrYKKR4Vb+nZ9UznpakKauWod 2cHNZcesTURfQD40HKl6HoTDKlY5S+Fi2/z0HEIZw2fZDEe8vEqo2+MTiSheS5qnJ9iVfPqDxG4 HY+uatqMh5SrbUwMwX/Ow8fxb/RJ78eFIHJ6LgPJFDUNFp1FRwXWai35GJlrnIA6Dx6BKlrV+CW OSxhuWy86NYfC1yV84RjwtOUlM1G2aJQKZOT7ElZgGzC25bIj98sdbq8vq6U9qod6r5IAMCLLZN Q X-Received: by 2002:a05:600c:83c8:b0:49d:28c4:b304 with SMTP id 5b1f17b1804b1-49eb7341406mr52441125e9.29.1789617616894; Wed, 16 Sep 2026 21:00:16 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-9dc6-c001-54ee-4741-4927-0a28.310.pool.telefonica.de. [2a02:3100:9dc6:c001:54ee:4741:4927:a28]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fbfd935cfsm6880015e9.0.2026.09.16.21.00.15 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 16 Sep 2026 21:00:16 -0700 (PDT) From: Karl Mehltretter To: stable@vger.kernel.org Cc: Karl Mehltretter , gregkh@linuxfoundation.org, sashal@kernel.org, luiz.dentz@gmail.com, luiz.von.dentz@intel.com, marcel@holtmann.org, johan.hedberg@gmail.com, eadavis@qq.com, davem@davemloft.net, kuba@kernel.org, linux-bluetooth@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, patches@lists.linux.dev, pav@iki.fi, syzbot+b7f6f8c9303466e16c8a@syzkaller.appspotmail.com Subject: [PATCH 5.15.y 2/2] bluetooth/l2cap: sync sock recv cb and release Date: Thu, 17 Sep 2026 06:00:04 +0200 Message-Id: <20260917040004.21041-3-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260917040004.21041-1-kmehltretter@gmail.com> References: <20260912065526.833703348@linuxfoundation.org> <20260912065546.976652519@linuxfoundation.org> <20260913202907.3100-1-kmehltretter@gmail.com> <20260917040004.21041-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Edward Adam Davis [ Upstream commit 89e856e124f9ae548572c56b1b70c2255705f8fe ] The problem occurs between the system call to close the sock and hci_rx_wor= k, where the former releases the sock and the latter accesses it without lock = protection. CPU0 CPU1 ---- ---- sock_close hci_rx_work l2cap_sock_release hci_acldata_packet l2cap_sock_kill l2cap_recv_frame sk_free l2cap_conless_channel l2cap_sock_recv_cb If hci_rx_work processes the data that needs to be received before the sock= is closed, then everything is normal; Otherwise, the work thread may access the released sock when receiving data. Add a chan mutex in the rx callback of the sock to achieve synchronization = between the sock release and recv cb. Sock is dead, so set chan data to NULL, avoid others use invalid sock point= er. Reported-and-tested-by: syzbot+b7f6f8c9303466e16c8a@syzkaller.appspotmail.c= om Signed-off-by: Edward Adam Davis Signed-off-by: Luiz Augusto von Dentz [ Karl Mehltretter: applied in the form this commit has after f1a8f402f13f ("Bluetooth: L2CAP: Fix deadlock"), that is the chan->data clearing in l2cap_sock_kill() and the guard in l2cap_sock_recv_cb(), without the channel locking in the callback. That locking is what caused the recursive chan->lock deadlock. f1a8f402f13f removes it and moves the lock to l2cap_conless_channel(), which the previous patch does here. l2cap_data_channel() already obtains the channel locked from l2cap_get_chan_by_scid(). ] Assisted-by: LLM Signed-off-by: Karl Mehltretter --- diff --git a/net/bluetooth/l2cap_sock.c b/net/bluetooth/l2cap_sock.c index 0b51c3e0f469..bef6a948d7d5 100644 --- a/net/bluetooth/l2cap_sock.c +++ b/net/bluetooth/l2cap_sock.c @@ -1237,6 +1237,10 @@ static void l2cap_sock_kill(struct sock *sk) =20 BT_DBG("sk %p state %s", sk, state_to_string(sk->sk_state)); =20 + /* Sock is dead, so set chan data to NULL, avoid other task use invalid + * sock pointer. + */ + l2cap_pi(sk)->chan->data =3D NULL; /* Kill poor orphan */ =20 l2cap_chan_put(l2cap_pi(sk)->chan); @@ -1519,9 +1523,13 @@ static struct l2cap_chan *l2cap_sock_new_connection_= cb(struct l2cap_chan *chan) =20 static int l2cap_sock_recv_cb(struct l2cap_chan *chan, struct sk_buff *skb) { - struct sock *sk =3D chan->data; + struct sock *sk; int err; =20 + sk =3D chan->data; + if (!sk) + return -ENXIO; + lock_sock(sk); =20 if (l2cap_pi(sk)->rx_busy_skb) { --=20 2.51.0