lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Tue, 16 Aug 2022 10:57:39 -0600
From:   Jens Axboe <axboe@...nel.dk>
To:     Greg KH <gregkh@...uxfoundation.org>,
        Jiacheng Xu <578001344xu@...il.com>
Cc:     linux-kernel@...r.kernel.org, asml.silence@...il.co,
        io-uring@...r.kernel.org, security@...nel.org
Subject: Re: KASAN: null-ptr-deref Write in io_file_get_normal

On 8/16/22 10:21 AM, Greg KH wrote:
> On Wed, Aug 17, 2022 at 12:10:09AM +0800, Jiacheng Xu wrote:
>> Hello,
>>
>> When using modified Syzkaller to fuzz the Linux kernel-5.15.58, the
>> following crash was triggered.
> 
> As you sent this to public lists, there's no need to also cc:
> security@k.o as there's nothing we can do about this.

Indeed...

> Also, random syzbot submissions are best sent with a fix for them,
> otherwise it might be a while before they will be looked at.

Greg, can you cherrypick:

commit 386e4fb6962b9f248a80f8870aea0870ca603e89
Author: Jens Axboe <axboe@...nel.dk>
Date:   Thu Jun 23 11:06:43 2022 -0600

    io_uring: use original request task for inflight tracking

into 5.15-stable? It should pick cleanly and also fix this issue.

-- 
Jens Axboe


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ