Re: KASAN: use-after-free Read in finish_task_switch (2)

From: syzbot
Date: Fri Jul 19 2019 - 12:34:02 EST


syzbot has bisected this bug to:

commit 7f466032dc9e5a61217f22ea34b2df932786bbfc
Author: Jason Wang <jasowang@xxxxxxxxxx>
Date: Fri May 24 08:12:18 2019 +0000

vhost: access vq metadata through kernel virtual address

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=123faf70600000
start commit: 22051d9c Merge tag 'platform-drivers-x86-v5.3-2' of git://..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=113faf70600000
console output: https://syzkaller.appspot.com/x/log.txt?x=163faf70600000
kernel config: https://syzkaller.appspot.com/x/.config?x=135cb826ac59d7fc
dashboard link: https://syzkaller.appspot.com/bug?extid=7f067c796eee2acbc57a
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12c1898fa00000

Reported-by: syzbot+7f067c796eee2acbc57a@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 7f466032dc9e ("vhost: access vq metadata through kernel virtual address")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection