lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20240807071655.5b230108@kernel.org>
Date: Wed, 7 Aug 2024 07:16:55 -0700
From: Jakub Kicinski <kuba@...nel.org>
To: Edward Adam Davis <eadavis@...com>
Cc: syzbot+ad601904231505ad6617@...kaller.appspotmail.com,
 davem@...emloft.net, edumazet@...gle.com, kernel@...gutronix.de,
 leitao@...ian.org, linux-can@...r.kernel.org, linux-kernel@...r.kernel.org,
 mkl@...gutronix.de, netdev@...r.kernel.org, o.rempel@...gutronix.de,
 pabeni@...hat.com, robin@...tonic.nl, socketcan@...tkopp.net,
 syzkaller-bugs@...glegroups.com
Subject: Re: [PATCH net-next] can: j1939: fix uaf in j1939_session_destroy

On Wed,  7 Aug 2024 20:35:47 +0800 Edward Adam Davis wrote:
> Fixes: c9c0ee5f20c5 ("net: skbuff: Skip early return in skb_unref when debugging")

Definitely not where the _bug_ was added, as Breno said.
It is kinda tempting to annotate somehow that this commit helped catch
the bug, tho. Not sure how.

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ