Re: KASAN: use-after-free Read in snd_timer_open

From: syzbot
Date: Mon Nov 11 2019 - 18:45:04 EST


syzbot has bisected this bug to:

commit 6a34367e52caea1413eb0a0dcbb524f0c9b67e82
Author: Takashi Iwai <tiwai@xxxxxxx>
Date: Thu Nov 7 19:20:08 2019 +0000

ALSA: timer: Fix possible race at assigning a timer instance

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=16b5dde6e00000
start commit: 6980b7f6 Add linux-next specific files for 20191111
git tree: linux-next
final crash: https://syzkaller.appspot.com/x/report.txt?x=15b5dde6e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=11b5dde6e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=2af7db1972ec750e
dashboard link: https://syzkaller.appspot.com/bug?extid=4476917c053f60112c99
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=108fbfece00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1055d5aae00000

Reported-by: syzbot+4476917c053f60112c99@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 6a34367e52ca ("ALSA: timer: Fix possible race at assigning a timer instance")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection