Re: BUG: corrupted list in nft_obj_del

From: Florian Westphal
Date: Thu Jan 16 2020 - 09:53:12 EST


syzbot <syzbot+6ca99af7e70e298bd09d@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit: 8b792f84 Merge branch 'mlxsw-Various-fixes'
> git tree: net
> console output: https://syzkaller.appspot.com/x/log.txt?x=1766b349e00000
> kernel config: https://syzkaller.appspot.com/x/.config?x=7e89bd00623fe71e
> dashboard link: https://syzkaller.appspot.com/bug?extid=6ca99af7e70e298bd09d
> compiler: gcc (GCC) 9.0.0 20181231 (experimental)
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=168b95e1e00000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10f29b3ee00000
>
> IMPORTANT: if you fix the bug, please add the following tag to the commit:
> Reported-by: syzbot+6ca99af7e70e298bd09d@xxxxxxxxxxxxxxxxxxxxxxxxx
>
> list_del corruption, ffff8880a46b1500->prev is LIST_POISON2

#syz fix: netfilter: nf_tables: fix flowtable list del corruption