Re: KASAN: use-after-free Read in fb_mode_is_equal

From: syzbot
Date: Wed Dec 25 2019 - 10:26:09 EST


syzbot has bisected this bug to:

commit 13ff178ccd6d3b8074c542a911300b79c4eec255
Author: Daniel Vetter <daniel.vetter@xxxxxxxx>
Date: Tue May 28 09:02:53 2019 +0000

fbcon: Call fbcon_mode_deleted/new_modelist directly

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1737c63ee00000
start commit: 46cf053e Linux 5.5-rc3
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=14b7c63ee00000
console output: https://syzkaller.appspot.com/x/log.txt?x=10b7c63ee00000
kernel config: https://syzkaller.appspot.com/x/.config?x=ed9d672709340e35
dashboard link: https://syzkaller.appspot.com/bug?extid=f11cda116c57db68c227
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12bf72c6e00000

Reported-by: syzbot+f11cda116c57db68c227@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 13ff178ccd6d ("fbcon: Call fbcon_mode_deleted/new_modelist directly")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection