Re: KASAN: use-after-free Write in refcount_warn_saturate

From: syzbot
Date: Fri Sep 04 2020 - 10:44:22 EST


syzbot suspects this issue was fixed by commit:

commit b83764f9220a4a14525657466f299850bbc98de9
Author: Miao-chen Chou <mcchou@xxxxxxxxxxxx>
Date: Tue Jun 30 03:15:00 2020 +0000

Bluetooth: Fix kernel oops triggered by hci_adv_monitors_clear()

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=10f92e3e900000
start commit: c0842fbc random32: move the pseudo-random 32-bit definitio..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=cf567e8c7428377e
dashboard link: https://syzkaller.appspot.com/bug?extid=7dd7f2f77a7a01d1dc14
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15b606dc900000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=123e87cc900000

If the result looks correct, please mark the issue as fixed by replying with:

#syz fix: Bluetooth: Fix kernel oops triggered by hci_adv_monitors_clear()

For information about bisection process see: https://goo.gl/tpsmEJ#bisection