Re: KASAN: use-after-free Read in bitmap_ip_ext_cleanup

From: syzbot
Date: Sun Jan 19 2020 - 15:21:03 EST


syzbot has bisected this bug to:

commit 3d26eb8ad1e9b906433903ce05f775cf038e747f
Author: Nikolay Aleksandrov <nikolay@xxxxxxxxxxxxxxxxxxx>
Date: Tue Jul 2 12:00:20 2019 +0000

net: bridge: don't cache ether dest pointer on input

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=17bb1cc9e00000
start commit: 9aaa2949 Merge branch '1GbE' of git://git.kernel.org/pub/s..
git tree: net-next
final crash: https://syzkaller.appspot.com/x/report.txt?x=147b1cc9e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=107b1cc9e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=66d8660c57ff3c98
dashboard link: https://syzkaller.appspot.com/bug?extid=b554d01b6c7870b17da2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15db12a5e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15316faee00000

Reported-by: syzbot+b554d01b6c7870b17da2@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 3d26eb8ad1e9 ("net: bridge: don't cache ether dest pointer on input")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection