Bluetooth: use hdev->workqueue when queuing hdev->{cmd,ncmd}_timer works
Published Dec 30, 2025
6.6
MEDIUMCVSS 3.1
EPSS 0.24%
Description
syzbot is reporting attempt to schedule hdev->cmd_work work from system_wq WQ into hdev->workqueue WQ which is under draining operation [1], for commit c8efcc2589464ac7 ("workqueue: allow chained queueing during destruction") does not allow such operation.
The check introduced by commit 877afadad2dce8aa ("Bluetooth: When HCI work queue is drained, only queue chained work") was incomplete.
Use hdev->workqueue WQ when queuing hdev->{cmd,ncmd}_timer works because hci_{cmd,ncmd}_timeout() calls queue_work(hdev->workqueue). Also, protect the queuing operation with RCU read lock in order to avoid calling queue_delayed_work() after cancel_delayed_work() completed.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.18.18StatusaffectedConstraints<5.19
- Version 5.19.2StatusaffectedConstraints<5.19.15
- Version
-
- Version 6.0StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.0
- Version 5.19.15StatusunaffectedConstraints<=5.19.*
- Version 6.0.1StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-50833 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2426258 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55865 Advisory
- https://git.kernel.org/stable/c/3c6b036fe5c8ed8b6c4cbdc03605929882907ef0
- https://git.kernel.org/stable/c/c4635cf3d845a7324c25c52d549b70c8bd7ad4c7
- https://git.kernel.org/stable/c/deee93d13d385103205879a8a0915036ecd83261
- https://lore.kernel.org/linux-cve-announce/2025123017-CVE-2022-50833-92af@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50833
- https://www.cve.org/CVERecord?id=CVE-2022-50833
Change history (0)
No recorded changes yet.