Re: BUG: corrupted list in cma_listen_on_dev

From: Jason Gunthorpe
Date: Mon Mar 09 2020 - 13:18:04 EST


On Fri, Mar 06, 2020 at 02:55:02PM -0800, syzbot wrote:
> Hello,
>
> syzbot has tested the proposed patch and the reproducer did not trigger crash:
>
> Reported-and-tested-by: syzbot+2b10b240fbbed30f10fb@xxxxxxxxxxxxxxxxxxxxxxxxx
>
> Tested on:
>
> commit: 5e29d144 RDMA/mlx5: Prevent UMR usage with RO only when we..
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/rdma/rdma.git for-next
> kernel config: https://syzkaller.appspot.com/x/.config?x=6d613b606deeaad7
> dashboard link: https://syzkaller.appspot.com/bug?extid=2b10b240fbbed30f10fb
> compiler: clang version 10.0.0 (https://github.com/llvm/llvm-project/ c2443155a0fb245c8f17f2c1c72b6ea391e86e81)
>
> Note: testing is done by a robot and is best-effort only.

#syz dup KASAN: use-after-free Read in rdma_listen (2)