[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20171218135524.GA26203@oracle.com>
Date: Mon, 18 Dec 2017 08:55:24 -0500
From: Sowmini Varadhan <sowmini.varadhan@...cle.com>
To: syzbot
<bot+aaf54a8c644d559d34dedcf3126aac68a20c9e63@...kaller.appspotmail.com>
Cc: netdev@...r.kernel.org, rds-devel@....oracle.com,
syzkaller-bugs@...glegroups.com
Subject: Re: BUG: unable to handle kernel NULL pointer dereference in
rds_send_xmit
On (12/18/17 00:43), syzbot wrote:
> BUG: unable to handle kernel NULL pointer dereference at 0000000000000028
> program syz-executor6 is using a deprecated SCSI ioctl, please convert it to
> SG_IO
> IP: rds_send_xmit+0x80/0x930 net/rds/send.c:186
conn->c_trans is at offset 0x28.
Both this and https://marc.info/?l=linux-netdev&m=151360062922798&w=2
are manifestations of the same bug: somehow the cp_send_w is still
getting queued incorrectly after the conn destroy is initiated (commit
681648e67d fixes one such window, maybe there are others).
Let me look at how this slipped through the cracks.
--Sowmini
Powered by blists - more mailing lists