Re: KASAN: use-after-free Read in __vb2_perform_fileio

From: syzbot
Date: Tue Apr 09 2019 - 17:18:03 EST


syzbot has bisected this bug to:

commit f2fe89061d79706eca5c47e4efdc09bbc171e74a
Author: Helen Koike <helen.koike@xxxxxxxxxxxxx>
Date: Fri Apr 7 17:55:19 2017 +0000

[media] vimc: Virtual Media Controller core, capture and sensor

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=15fbb7a7200000
start commit: 38e7571c Merge tag 'io_uring-2019-03-06' of git://git.kern..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=17fbb7a7200000
console output: https://syzkaller.appspot.com/x/log.txt?x=13fbb7a7200000
kernel config: https://syzkaller.appspot.com/x/.config?x=1c9125b2c20e6dd4
dashboard link: https://syzkaller.appspot.com/bug?extid=4180ff9ca6810b06c1e9
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=101eda5f200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10c465db200000

Reported-by: syzbot+4180ff9ca6810b06c1e9@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: f2fe89061d79 ("[media] vimc: Virtual Media Controller core, capture and sensor")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection