Re: KASAN: use-after-free Read in nl8NUM_dump_wpan_phy

From: syzbot
Date: Tue Oct 08 2019 - 21:24:06 EST


syzbot has bisected this bug to:

commit 75cdbdd089003cd53560ff87b690ae911fa7df8e
Author: Jiri Pirko <jiri@xxxxxxxxxxxx>
Date: Sat Oct 5 18:04:37 2019 +0000

net: ieee802154: have genetlink code to parse the attrs during dumpit

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14620210e00000
start commit: 056ddc38 Merge branch 'stmmac-next'
git tree: net-next
final crash: https://syzkaller.appspot.com/x/report.txt?x=16620210e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=12620210e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=d9be300620399522
dashboard link: https://syzkaller.appspot.com/bug?extid=495688b736534bb6c6ad
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10e256c3600000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=175ecdfb600000

Reported-by: syzbot+495688b736534bb6c6ad@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 75cdbdd08900 ("net: ieee802154: have genetlink code to parse the attrs during dumpit")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection