Re: KASAN: use-after-free Write in j1939_sock_pending_del

From: syzbot
Date: Tue Nov 05 2019 - 06:45:02 EST


syzbot has bisected this bug to:

commit 9d71dd0c70099914fcd063135da3c580865e924c
Author: The j1939 authors <linux-can@xxxxxxxxxxxxxxx>
Date: Mon Oct 8 09:48:36 2018 +0000

can: add support of SAE J1939 protocol

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11150314e00000
start commit: a99d8080 Linux 5.4-rc6
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=13150314e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=15150314e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=896c87b73c6fcda6
dashboard link: https://syzkaller.appspot.com/bug?extid=07bb74aeafc88ba7d5b4
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16fd7044e00000

Reported-by: syzbot+07bb74aeafc88ba7d5b4@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 9d71dd0c7009 ("can: add support of SAE J1939 protocol")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection