Re: general protection fault in jffs2_parse_param

From: Dmitry Vyukov
Date: Tue Jan 26 2021 - 00:12:30 EST


On Sun, Jan 17, 2021 at 5:14 PM syzbot
<syzbot+9765367bb86a19d38732@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit a61df3c413e49b0042f9caf774c58512d1cc71b7
> Author: Jamie Iles <jamie@xxxxxxxxxxxx>
> Date: Mon Oct 12 13:12:04 2020 +0000
>
> jffs2: Fix NULL pointer dereference in rp_size fs option parsing
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=15cb91e7500000
> start commit: bf3e7628 Merge branch 'mtd/fixes' of git://git.kernel.org/..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=61033507391c77ff
> dashboard link: https://syzkaller.appspot.com/bug?extid=9765367bb86a19d38732
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13d81f32500000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13516852500000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: jffs2: Fix NULL pointer dereference in rp_size fs option parsing
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

#syz fix: jffs2: Fix NULL pointer dereference in rp_size fs option parsing