Re: KASAN: use-after-free Write in __sco_sock_close

From: Dmitry Vyukov
Date: Thu Dec 17 2020 - 06:08:52 EST


On Wed, Dec 16, 2020 at 8:15 AM syzbot
<syzbot+077eca30d3cb7c02b273@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit 6dfccd13db2ff2b709ef60a50163925d477549aa
> Author: Anmol Karn <anmol.karan123@xxxxxxxxx>
> Date: Wed Sep 30 14:18:13 2020 +0000
>
> Bluetooth: Fix null pointer dereference in hci_event_packet()
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14cb845b500000
> start commit: 47ec5303 Merge git://git.kernel.org/pub/scm/linux/kernel/g..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=e0c783f658542f35
> dashboard link: https://syzkaller.appspot.com/bug?extid=077eca30d3cb7c02b273
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=165a89dc900000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=130a8c62900000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: Bluetooth: Fix null pointer dereference in hci_event_packet()
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

#syz fix: Bluetooth: Fix null pointer dereference in hci_event_packet()