Re: KASAN: use-after-free Read in __nf_tables_abort

From: syzbot
Date: Tue Jan 21 2020 - 16:50:04 EST


syzbot has bisected this bug to:

commit ec7470b834fe7b5d7eff11b6677f5d7fdf5e9a91
Author: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Date: Mon Jan 13 17:09:58 2020 +0000

netfilter: nf_tables: store transaction list locally while requesting module

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14890721e00000
start commit: d96d875e Merge tag 'fixes_for_v5.5-rc8' of git://git.kerne..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=16890721e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=12890721e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=83c00afca9cf5153
dashboard link: https://syzkaller.appspot.com/bug?extid=29125d208b3dae9a7019
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1203f521e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10a706a5e00000

Reported-by: syzbot+29125d208b3dae9a7019@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: ec7470b834fe ("netfilter: nf_tables: store transaction list locally while requesting module")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection