Re: KASAN: use-after-free Read in rds_find_bound
From: Dmitry Vyukov
Date: Wed Feb 14 2018 - 12:14:50 EST
On Wed, Feb 14, 2018 at 5:53 PM, Santosh Shilimkar
<santosh.shilimkar@xxxxxxxxxx> wrote:
>>> On 12/30/17 1:17 AM, syzbot wrote:
>>>>
>>>>
>>>> Hello,
>>>>
>>>> syzkaller hit the following crash on
>>>> fba961ab29e5ffb055592442808bb0f7962e05da
>>>> git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/master
>>>> compiler: gcc (GCC) 7.1.1 20170620
>>>> .config is attached
>>>> Raw console output is attached.
>>>> Unfortunately, I don't have any reproducer for this bug yet.
>>>>
>>>>
>>>> IMPORTANT: if you fix the bug, please add the following tag to the
>>>> commit:
>>>> Reported-by: syzbot+93a5839deb355537440f@xxxxxxxxxxxxxxxxxxxxxxxxx
>>>
>>>
>>>
>>> Posted a fix[1] for above issue. Didn't test it but looks straight
>>> forward.
>>
>>
>>
>> Hi Santosh,
>>
>> What is that fix? You forgot to provide any link/reference. I also
>> don't see any patches from you at around that date...
>>
> Fix [1] was later not added since there was a still a race. Wanted to
> see if the issue re-appears after recent netns fix [2].
We will not see if the bug re-appears or not until this bug is closed.
Please see this recent discussion about another rds bug:
https://groups.google.com/d/msg/syzkaller-bugs/3XjmOzr5jRU/g7pXIsY1BgAJ
In the current state syzbot will never report bugs in these functions again.