Re: KASAN: use-after-free Read in __queue_work (2)

From: syzbot
Date: Sat Nov 23 2019 - 18:37:06 EST


syzbot has bisected this bug to:

commit 7594bf37ae9ffc434da425120c576909eb33b0bc
Author: Al Viro <viro@xxxxxxxxxxxxxxxxxx>
Date: Mon Jul 17 02:53:08 2017 +0000

9p: untangle ->poll() mess

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=12ad235ee00000
start commit: ca04b3cc Merge tag 'armsoc-fixes' of git://git.kernel.org/..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=11ad235ee00000
console output: https://syzkaller.appspot.com/x/log.txt?x=16ad235ee00000
kernel config: https://syzkaller.appspot.com/x/.config?x=2ca6c7a31d407f86
dashboard link: https://syzkaller.appspot.com/bug?extid=1c9db6a163a4000d0765
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1473a452400000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14087748400000

Reported-by: syzbot+1c9db6a163a4000d0765@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 7594bf37ae9f ("9p: untangle ->poll() mess")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection