Re: KASAN: use-after-free Read in hidraw_ioctl
From: Andrey Konovalov
Date: Wed Aug 21 2019 - 12:40:04 EST
On Wed, Aug 21, 2019 at 6:38 PM syzbot
<syzbot+ded1794a717e3b235226@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> Hello,
>
> syzbot has tested the proposed patch and the reproducer did not trigger
> crash:
>
> Reported-and-tested-by:
> syzbot+ded1794a717e3b235226@xxxxxxxxxxxxxxxxxxxxxxxxx
>
> Tested on:
>
> commit: e96407b4 usb-fuzzer: main usb gadget fuzzer driver
> git tree: https://github.com/google/kasan.git
> kernel config: https://syzkaller.appspot.com/x/.config?x=792eb47789f57810
> compiler: gcc (GCC) 9.0.0 20181231 (experimental)
> patch: https://syzkaller.appspot.com/x/patch.diff?x=126b9da6600000
>
> Note: testing is done by a robot and is best-effort only.
Let's dup this bug into the other one:
#syz dup: KASAN: slab-out-of-bounds Read in hidraw_ioctl