lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20250728074014.271654-1-yang.chenzhi@vivo.com>
Date: Mon, 28 Jul 2025 15:40:14 +0800
From: Chenzhi Yang <yang.chenzhi@...o.com>
To: huk23@...udan.edu.cn
Cc: Slava.Dubeyko@....com,
	baishuoran@...eu.edu.cn,
	frank.li@...o.com,
	glaubitz@...sik.fu-berlin.de,
	jjtan24@...udan.edu.cn,
	linux-fsdevel@...r.kernel.org,
	linux-kernel@...r.kernel.org,
	slava@...eyko.com
Subject: KASAN: slab-out-of-bounds in hfsplus_bnode_read+0x268/0x290

>Hi Slava,
>Thank you for taking your time.

>We originally obtained this issue's syz and C reproducers using Syzkaller's repro tool (refer to the URL below). The issue was triggered when we ran the syz reproducer through Syzkaller.

>Url: https://github.com/google/syzkaller/blob/master/docs/reproducing_crashes.md

>Syzkaller also provides syz-execprog to verify whether the C program can trigger the issue. We are currently in the process of verifying whether the C reproducer can reliably reproduce the issue. Please allow us some time to complete this verification.

>We'll follow up with you once we have more concrete results.

>Best regards,
>Kun

Hi Kun,

Just wanted to follow up, how is the verification of the C reproducer going?
If it does reliably reproduce the issue, could you also let us know under what
scenario or environment it occurs?

Best regards,
Chenzhi

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ