Re: BUG: KASAN: use-after-free in enqueue_timer+0x4f/0x1e0

From: David Airlie
Date: Mon Oct 11 2021 - 21:48:42 EST


On Tue, Oct 12, 2021 at 2:07 AM Kim Phillips <kim.phillips@xxxxxxx> wrote:
>
> Hi,
>
> On 10/5/21 1:10 PM, Kim Phillips wrote:
> > Hi, I occasionally see the below trace with Linus' master on an
> > AMD Milan system:
> >
> > [ 25.657322] BUG: kernel NULL pointer dereference, address: 0000000000000000
> > [ 25.665097] #PF: supervisor instruction fetch in kernel mode
> > [ 25.671448] #PF: error_code(0x0010) - not-present page
> <snip>
> > That bisection led to this commit:
> >
> > commit aae74ff9caa8de9a45ae2e46068c417817392a26
> > Author: Ainux <ainux.wang@xxxxxxxxx>
> > Date: Wed May 26 19:15:15 2021 +0800
> > drm/ast: Add detect function support
> <snip>
> > I confirmed that if I revert it from v5.15-rc4 (after reverting
> > its dependent 572994bf18ff "drm/ast: Zero is missing in detect
> > function"), the problem goes away.
> >
> > Full .config, dmesg attached.
> >
> > I can test any possible fixes...
>
>
> Ping - if no fixes are in the works, can the offending commit(s)
> be reverted?

tzimmermann?

Dave.