Re: KASAN: use-after-free Read in relay_switch_subbuf

From: syzbot
Date: Mon Nov 18 2019 - 01:59:08 EST


syzbot has bisected this bug to:

commit 21c75ad65f8e5213ec542d99c259ffe3e3671e81
Author: YueHaibing <yuehaibing@xxxxxxxxxx>
Date: Thu Mar 21 08:26:28 2019 +0000

parport_cs: Fix memory leak in parport_config

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11480c6ae00000
start commit: 26bc6721 Merge tag 'for-linus-2019-11-05' of git://git.ker..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=13480c6ae00000
console output: https://syzkaller.appspot.com/x/log.txt?x=15480c6ae00000
kernel config: https://syzkaller.appspot.com/x/.config?x=8c5e2eca3f31f9bf
dashboard link: https://syzkaller.appspot.com/bug?extid=29093015c21333d1c46d
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=132afbcce00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=179a1f8ae00000

Reported-by: syzbot+29093015c21333d1c46d@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 21c75ad65f8e ("parport_cs: Fix memory leak in parport_config")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection