Re: KASAN: use-after-free Read in ath9k_hif_usb_rx_cb (2)

From: syzbot
Date: Wed Nov 18 2020 - 21:07:10 EST


syzbot has bisected this issue to:

commit dcd479e10a0510522a5d88b29b8f79ea3467d501
Author: Johannes Berg <johannes.berg@xxxxxxxxx>
Date: Fri Oct 9 12:17:11 2020 +0000

mac80211: always wind down STA state

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=100c9c16500000
start commit: 0fa8ee0d Merge branch 'for-linus' of git://git.kernel.org/..
git tree: upstream
final oops: https://syzkaller.appspot.com/x/report.txt?x=120c9c16500000
console output: https://syzkaller.appspot.com/x/log.txt?x=140c9c16500000
kernel config: https://syzkaller.appspot.com/x/.config?x=75292221eb79ace2
dashboard link: https://syzkaller.appspot.com/bug?extid=03110230a11411024147
userspace arch: i386
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1587f841500000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11ec0fe6500000

Reported-by: syzbot+03110230a11411024147@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: dcd479e10a05 ("mac80211: always wind down STA state")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection