Re: KASAN, xt_TCPMSS finally found nasty use-after-free bug? 4.10.8

From: Eric Dumazet
Date: Mon Apr 03 2017 - 08:09:18 EST


On Mon, 2017-04-03 at 11:10 +0300, Denys Fedoryshchenko wrote:

> I modified patch a little as:
> if (th->doff * 4 < sizeof(_tcph)) {
> par->hotdrop = true;
> WARN_ON_ONCE(!tcpinfo->option);
> return false;
> }
>
> And it did triggered WARN once at morning, and didn't hit KASAN. I will
> run for a while more, to see if it is ok, and then if stable, will try
> to enable SFQ again.

Excellent news !
We will post an official fix today, thanks a lot for this detective work
Denys.