[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CA+FuTSfVgPM4DZcvaRjDinoyg7cA+Pj4oCO-13+7PsFGrhuC+w@mail.gmail.com>
Date: Thu, 7 Nov 2019 09:31:24 -0500
From: Willem de Bruijn <willemdebruijn.kernel@...il.com>
To: syzbot <syzbot+e8c1d30881266e47eb33@...kaller.appspotmail.com>
Cc: Alexei Starovoitov <ast@...nel.org>, bpf <bpf@...r.kernel.org>,
Daniel Borkmann <daniel@...earbox.net>,
David Miller <davem@...emloft.net>,
David Ahern <dsahern@...il.com>,
Herbert Xu <herbert@...dor.apana.org.au>,
johannes.berg@...el.com, Martin Lau <kafai@...com>,
Alexey Kuznetsov <kuznet@....inr.ac.ru>,
linux-kernel <linux-kernel@...r.kernel.org>,
Network Development <netdev@...r.kernel.org>,
Peter Oskolkov <posk@...gle.com>, songliubraving@...com,
Steffen Klassert <steffen.klassert@...unet.com>,
syzkaller-bugs@...glegroups.com, tglx@...utronix.de,
Yonghong Song <yhs@...com>,
Hideaki YOSHIFUJI <yoshfuji@...ux-ipv6.org>
Subject: Re: KASAN: use-after-free Read in _decode_session6
On Thu, Nov 7, 2019 at 8:42 AM syzbot
<syzbot+e8c1d30881266e47eb33@...kaller.appspotmail.com> wrote:
>
> syzbot suspects this bug was fixed by commit:
>
> commit e7c87bd6cc4ec7b0ac1ed0a88a58f8206c577488
> Author: Willem de Bruijn <willemb@...gle.com>
> Date: Wed Jan 16 01:19:22 2019 +0000
>
> bpf: in __bpf_redirect_no_mac pull mac only if present
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1736f974600000
> start commit: b36fdc68 Merge tag 'gpio-v4.19-2' of git://git.kernel.org/..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=4c7e83258d6e0156
> dashboard link: https://syzkaller.appspot.com/bug?extid=e8c1d30881266e47eb33
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14d42021400000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13d09f1e400000
>
> If the result looks correct, please mark the bug fixed by replying with:
>
> #syz fix: bpf: in __bpf_redirect_no_mac pull mac only if present
#syz fix: bpf: in __bpf_redirect_no_mac pull mac only if present
indeed manually reproduced at e7c87bd6cc4e~1, failed to reproduce at
e7c87bd6cc4e. Also seems plausible given the stack trace.
Powered by blists - more mailing lists