Hello bluetooth maintainers/developers, This is a 31-day syzbot report for the bluetooth subsystem. All related reports/information can be found at: https://syzkaller.appspot.com/upstream/s/bluetooth During the period, 6 new issues were detected and 2 were fixed. In total, 47 issues are still open and 72 have been fixed so far. Some of the still happening issues: Ref Crashes Repro Title <1> 13649 Yes possible deadlock in rfcomm_dlc_exists https://syzkaller.appspot.com/bug?extid=b69a625d06e8ece26415 <2> 4263 Yes WARNING in call_timer_fn https://syzkaller.appspot.com/bug?extid=6fb78d577e89e69602f9 <3> 345 Yes general protection fault in lock_sock_nested https://syzkaller.appspot.com/bug?extid=d3ccfb78a0dc16ffebe3 <4> 175 Yes BUG: sleeping function called from invalid context in hci_le_create_big_complete_evt https://syzkaller.appspot.com/bug?extid=2fb0835e0c9cefc34614 <5> 130 Yes KASAN: slab-use-after-free Read in l2cap_recv_frame https://syzkaller.appspot.com/bug?extid=5c915dc5dd417b83b348 <6> 85 Yes KASAN: slab-use-after-free Write in sco_conn_del https://syzkaller.appspot.com/bug?extid=6b9277cad941daf126a2 <7> 57 Yes BUG: sleeping function called from invalid context in lock_sock_nested (3) https://syzkaller.appspot.com/bug?extid=55cd5225f71c5cff7f6f <8> 46 Yes WARNING: ODEBUG bug in put_device https://syzkaller.appspot.com/bug?extid=a9290936c6e87b3dc3c2 <9> 45 No KASAN: slab-use-after-free Read in skb_queue_purge_reason (2) https://syzkaller.appspot.com/bug?extid=683f8cb11b94b1824c77 <10> 36 No WARNING in l2cap_chan_send https://syzkaller.appspot.com/bug?extid=b6919040d9958e2fc1ae --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@xxxxxxxxxxxxxxxx. To disable reminders for individual bugs, reply with the following command: #syz set <Ref> no-reminders To change bug's subsystems, reply with: #syz set <Ref> subsystems: new-subsystem You may send multiple commands in a single email message.