Re: KASAN: use-after-free Read in bitmap_ip_destroy

From: syzbot
Date: Mon Jan 20 2020 - 23:41:05 EST


syzbot has bisected this bug to:

commit 354d0fab649d47045517cf7cae03d653a4dcb3b8
Author: Peng Li <lipeng321@xxxxxxxxxx>
Date: Thu Jul 4 14:04:26 2019 +0000

net: hns3: add default value for tc_size and tc_offset

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=15cc0685e00000
start commit: 8f8972a3 Merge tag 'mtd/fixes-for-5.5-rc7' of git://git.ke..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=17cc0685e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=13cc0685e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=cfbb8fa33f49f9f3
dashboard link: https://syzkaller.appspot.com/bug?extid=8b5f151de2f35100bbc5
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12e22559e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16056faee00000

Reported-by: syzbot+8b5f151de2f35100bbc5@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 354d0fab649d ("net: hns3: add default value for tc_size and tc_offset")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection