Re: KASAN: use-after-free Read in j1939_session_get_by_addr_locked

From: syzbot
Date: Sun Nov 10 2019 - 22:57:06 EST


syzbot has bisected this bug to:

commit 9d71dd0c70099914fcd063135da3c580865e924c
Author: The j1939 authors <linux-can@xxxxxxxxxxxxxxx>
Date: Mon Oct 8 09:48:36 2018 +0000

can: add support of SAE J1939 protocol

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11bc06d6e00000
start commit: 00aff683 Merge tag 'for-5.4-rc6-tag' of git://git.kernel.o..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=13bc06d6e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=15bc06d6e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=8c5e2eca3f31f9bf
dashboard link: https://syzkaller.appspot.com/bug?extid=ca172a0ac477ac90f045
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=144150e2e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11aaa9fce00000

Reported-by: syzbot+ca172a0ac477ac90f045@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 9d71dd0c7009 ("can: add support of SAE J1939 protocol")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection