Re: KASAN: use-after-free Read in tick_sched_handle (3)

From: Stefano Brivio
Date: Fri Nov 08 2019 - 07:51:23 EST


On Thu, 07 Nov 2019 05:42:07 -0800
syzbot <syzbot+999bca54de2ee169c021@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

> syzbot suspects this bug was fixed by commit:
>
> commit bc6e019b6ee65ff4ebf3ca272f774cf6c67db669
> Author: Stefano Brivio <sbrivio@xxxxxxxxxx>
> Date: Thu Jan 3 20:43:34 2019 +0000
>
> fou: Prevent unbounded recursion in GUE error handler also with UDP-Lite
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=119c0bc2600000
> start commit: 1c7fc5cb Linux 5.0-rc2
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=817708c0a0300f84
> dashboard link: https://syzkaller.appspot.com/bug?extid=999bca54de2ee169c021
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12c95a30c00000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11df0107400000
>
> If the result looks correct, please mark the bug fixed by replying with:
>
> #syz fix: fou: Prevent unbounded recursion in GUE error handler also with
> UDP-Lite
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

#syz fix: fou: Prevent unbounded recursion in GUE error handler also with UDP-Lite