Re: KASAN: slab-out-of-bounds Read in br_mrp_parse

From: Dan Carpenter
Date: Thu May 21 2020 - 10:08:28 EST


On Wed, May 20, 2020 at 11:23:18AM -0700, syzbot wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit: dda18a5c selftests/bpf: Convert bpf_iter_test_kern{3, 4}.c..
> git tree: bpf-next
^^^^^^^^

I can figure out what this is from reading Next/Trees but it would be
more useful if it were easier to script.

> console output: https://syzkaller.appspot.com/x/log.txt?x=10c4e63c100000
> kernel config: https://syzkaller.appspot.com/x/.config?x=668983fd3dd1087e
> dashboard link: https://syzkaller.appspot.com/bug?extid=9c6f0f1f8e32223df9a4
> compiler: gcc (GCC) 9.0.0 20181231 (experimental)
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17eaba3c100000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=128598f6100000
>

regards,
dan carpenter