Reminder: 7 open syzbot bugs in "net/netrom" subsystem

From: Eric Biggers
Date: Wed Jun 26 2019 - 23:50:37 EST


[This email was generated by a script. Let me know if you have any suggestions
to make it better.]

Of the currently open syzbot reports against the upstream kernel, I've manually
marked 7 of them as possibly being bugs in the "net/netrom" subsystem. I've
listed these reports below, sorted by an algorithm that tries to list first the
reports most likely to be still valid, important, and actionable.

Of these 7 bugs, 1 was seen in mainline in the last week.

If you believe a bug is no longer valid, please close the syzbot report by
sending a '#syz fix', '#syz dup', or '#syz invalid' command in reply to the
original thread, as explained at https://goo.gl/tpsmEJ#status

If you believe I misattributed a bug to the "net/netrom" subsystem, please let
me know, and if possible forward the report to the correct people or mailing
list.

Here are the bugs:

--------------------------------------------------------------------------------
Title: general protection fault in prepare_to_wait
Last occurred: 1 day ago
Reported: 174 days ago
Branches: Mainline and others
Dashboard link: https://syzkaller.appspot.com/bug?id=c670fb9da2ce08f7b5101baa9426083b39ee9f90
Original thread: https://lkml.kernel.org/lkml/000000000000fa6a2c057e8b7064@xxxxxxxxxx/T/#u

This bug has a C reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+55f9d3e51d49e20b2ce5@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/000000000000fa6a2c057e8b7064@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: memory leak in nr_create
Last occurred: 7 days ago
Reported: 30 days ago
Branches: Mainline
Dashboard link: https://syzkaller.appspot.com/bug?id=24be997a573ef9d497d6d7302518779b75d8119a
Original thread: https://lkml.kernel.org/lkml/0000000000009412c60589e804d8@xxxxxxxxxx/T/#u

This bug has a C reproducer.

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+10f1194569953b72f1ae@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/0000000000009412c60589e804d8@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: memory leak in nr_rx_frame
Last occurred: 30 days ago
Reported: 30 days ago
Branches: Mainline
Dashboard link: https://syzkaller.appspot.com/bug?id=0c00cc3e04fe00ad69ac62fbe8464b2f0fae932a
Original thread: https://lkml.kernel.org/lkml/000000000000da88840589e8fe2c@xxxxxxxxxx/T/#u

This bug has a C reproducer.

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+d6636a36d3c34bd88938@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/000000000000da88840589e8fe2c@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: KASAN: use-after-free Read in lock_sock_nested
Last occurred: 24 days ago
Reported: 175 days ago
Branches: Mainline and others
Dashboard link: https://syzkaller.appspot.com/bug?id=6c137905024f86513297b035845acecb55fa9dab
Original thread: https://lkml.kernel.org/lkml/0000000000007a5aad057e7748c9@xxxxxxxxxx/T/#u

This bug has a syzkaller reproducer only.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+500c69d1e21d970e461b@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/0000000000007a5aad057e7748c9@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: KASAN: use-after-free Read in nr_release
Last occurred: 0 days ago
Reported: 18 days ago
Branches: net
Dashboard link: https://syzkaller.appspot.com/bug?id=5332f4a9ce674d6378f0bd91af752d2be80f3aba
Original thread: https://lkml.kernel.org/lkml/0000000000007e8b70058acbd60f@xxxxxxxxxx/T/#u

Unfortunately, this bug does not have a reproducer.

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+6eaef7158b19e3fec3a0@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/0000000000007e8b70058acbd60f@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: memory leak in nr_loopback_queue
Last occurred: 28 days ago
Reported: 28 days ago
Branches: Mainline
Dashboard link: https://syzkaller.appspot.com/bug?id=20e5b6ff68ec36b9ba8ac5225e560a3a563f343a
Original thread: https://lkml.kernel.org/lkml/000000000000a7f012058a0c7a65@xxxxxxxxxx/T/#u

This bug has a syzkaller reproducer only.

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+470d1a4a7b7a7c225881@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/000000000000a7f012058a0c7a65@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: KASAN: use-after-free Read in refcount_inc_not_zero_checked (2)
Last occurred: 70 days ago
Reported: 102 days ago
Branches: Mainline
Dashboard link: https://syzkaller.appspot.com/bug?id=b0192a79bb2d222d3e723d7db60dfb5e0ec0e570
Original thread: https://lkml.kernel.org/lkml/000000000000eea12405843bc43c@xxxxxxxxxx/T/#u

This bug has a syzkaller reproducer only.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+eff6b596cc8194e2f029@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/000000000000eea12405843bc43c@xxxxxxxxxx