Re: net/ipv6: null-ptr-deref in ip6_route_del/lock_acquire

From: Andrey Konovalov
Date: Mon Feb 27 2017 - 16:35:43 EST


On Mon, Feb 27, 2017 at 9:34 PM, Cong Wang <xiyou.wangcong@xxxxxxxxx> wrote:
> On Mon, Feb 27, 2017 at 12:05 PM, Andrey Konovalov
> <andreyknvl@xxxxxxxxxx> wrote:
>> On Mon, Feb 27, 2017 at 8:59 PM, David Ahern <dsa@xxxxxxxxxxxxxxxxxxx> wrote:
>>> On 2/27/17 10:11 AM, Cong Wang wrote:
>>>> The attached patch fixes this crash, but I am not sure if it is the
>>>> best way to fix this bug yet...
>>>
>>> I'll take a look. I can not reproduce this using route or ip, so the
>>> fuzzer is doing something interesting.
>>
>> Hi David,
>>
>> I've attached a simple reproducer to the report, it doesn't work for you?
>
> It works for me and I have verified the formal patch I sent.

Hi Cong,

That's what I thought when I read your message, thanks!

I was just confused by David saying that the fuzzer is doing something
interesting, when the reproducer is just an ioctl call on a socket.

>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller+unsubscribe@xxxxxxxxxxxxxxxxx
> For more options, visit https://groups.google.com/d/optout.