lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <Y/4xPYHjl4X1D30L@kernel-devel>
Date:   Wed, 1 Mar 2023 01:52:13 +0900
From:   Shigeru Yoshida <syoshida@...hat.com>
To:     Jakub Kicinski <kuba@...nel.org>
Cc:     davem@...emloft.net, edumazet@...gle.com, pabeni@...hat.com,
        netdev@...r.kernel.org, linux-kernel@...r.kernel.org,
        syzbot+b563d33852b893653a9e@...kaller.appspotmail.com
Subject: Re: [PATCH net] net: caif: Fix use-after-free in
 cfusbl_device_notify()

On Mon, Feb 27, 2023 at 06:28:00PM -0800, Jakub Kicinski wrote:
> On Sun, 26 Feb 2023 03:28:20 +0900 Shigeru Yoshida wrote:
> > syzbot reported use-after-free in cfusbl_device_notify() [1].  This
> > causes a stack trace like below:
> 
> Please repost with the correct fixes tag, presumably:
> 
> Fixes: 7ad65bf68d70 ("caif: Add support for CAIF over CDC NCM USB interface")
> 
> Please make sure you CC the authors of that commit.

Sorry, I'll be more careful.  I'll prepare v2 patch.

Thanks,
Shigeru

> 

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ