| 概要 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hdev->req_status __hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock: hdev->req_status = HCI_REQ_PEND; However, several other functions read or write hdev->req_status without - hci_send_cmd_sync() reads req_status in hci_cmd_work (workqueue) Since __hci_cmd_sync_sk() runs on hdev->req_workqueue while Add READ_ONCE()/WRITE_ONCE() annotations on all concurrent accesses |
|---|---|
| 公表日 | 2026年5月6日19:16 |
| 登録日 | 2026年5月7日4:08 |
| 最終更新日 | 2026年5月6日22:07 |