lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date:   Sun, 24 May 2020 13:14:49 +0200
From:   Arnd Bergmann <arnd@...db.de>
To:     Richard Weinberger <richard@....at>
Cc:     syzbot <syzbot+0ce97ea45b008ba3b8bd@...kaller.appspotmail.com>,
        daniel baluta <daniel.baluta@....com>,
        festevam <festevam@...il.com>,
        Greg Kroah-Hartman <gregkh@...uxfoundation.org>,
        kernel <kernel@...gutronix.de>,
        linux-arm-kernel <linux-arm-kernel@...ts.infradead.org>,
        linux-imx <linux-imx@....com>,
        linux-kernel <linux-kernel@...r.kernel.org>,
        linux-mtd <linux-mtd@...ts.infradead.org>,
        Oleksij Rempel <linux@...pel-privat.de>,
        Miquel Raynal <miquel.raynal@...tlin.com>,
        Sascha Hauer <s.hauer@...gutronix.de>,
        shawnguo <shawnguo@...nel.org>,
        syzkaller-bugs <syzkaller-bugs@...glegroups.com>,
        Vignesh Raghavendra <vigneshr@...com>
Subject: Re: KASAN: use-after-free Read in uif_close

On Sun, May 24, 2020 at 10:09 AM Richard Weinberger <richard@....at> wrote:
>
> ----- Urspr√ľngliche Mail -----
> > Von: "syzbot" <syzbot+0ce97ea45b008ba3b8bd@...kaller.appspotmail.com>
> > An: "Arnd Bergmann" <arnd@...db.de>, "daniel baluta" <daniel.baluta@....com>, "festevam" <festevam@...il.com>, "Greg
> > Kroah-Hartman" <gregkh@...uxfoundation.org>, "kernel" <kernel@...gutronix.de>, "linux-arm-kernel"
> > <linux-arm-kernel@...ts.infradead.org>, "linux-imx" <linux-imx@....com>, "linux-kernel" <linux-kernel@...r.kernel.org>,
> > "linux-mtd" <linux-mtd@...ts.infradead.org>, linux@...pel-privat.de, "Miquel Raynal" <miquel.raynal@...tlin.com>,
> > "richard" <richard@....at>, "Sascha Hauer" <s.hauer@...gutronix.de>, "shawnguo" <shawnguo@...nel.org>,
> > syzkaller-bugs@...glegroups.com, "Vignesh Raghavendra" <vigneshr@...com>
> > Gesendet: Sonntag, 24. Mai 2020 08:03:03
> > Betreff: Re: KASAN: use-after-free Read in uif_close
>
> > syzbot has bisected this bug to:
> >
> > commit 32ec783ae19d48084b893cc54747fed37b07eb0c
> > Author: Arnd Bergmann <arnd@...db.de>
> > Date:   Wed Apr 8 19:02:57 2020 +0000
> >
> >    firmware: imx: fix compile-testing
>
> Hmm, from a quick check I don't see how this is related.
> Arnd?

I suppose this was a randconfig build for a configuration that did not build
until I fixed the build stage, and then it failed at runtime, so the bug would
have been in earlier releases as well, it was just not observed.

     Arnd

Powered by blists - more mailing lists