Re: net/dccp: use-after-free in dccp_feat_activate_values

From: Eric Dumazet
Date: Fri Mar 03 2017 - 10:24:23 EST


On Fri, Mar 3, 2017 at 7:12 AM, Dmitry Vyukov <dvyukov@xxxxxxxxxx> wrote:
> The first bot that picked this up started spewing:
>
> BUG: spinlock recursion on CPU#1, syz-executor2/9452

Yes. The bug is not about locking the listener, but protecting fields
of struct dccp_request_sock

I will provide a patch, once I reach the office and after the breakfast ;)