Re: KASAN: use-after-free Read in hci_cmd_timeout

From: syzbot
Date: Wed Jul 03 2019 - 14:26:03 EST


syzbot has bisected this bug to:

commit ff92b9dd9268507e23fc10cc4341626cef50367c
Author: Suganath Prabu <suganath-prabu.subramani@xxxxxxxxxxxx>
Date: Thu Oct 25 14:03:40 2018 +0000

scsi: mpt3sas: Update MPI headers to support Aero controllers

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=130ac8dda00000
start commit: eca94432 Bluetooth: Fix faulty expression for minimum encr..
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=108ac8dda00000
console output: https://syzkaller.appspot.com/x/log.txt?x=170ac8dda00000
kernel config: https://syzkaller.appspot.com/x/.config?x=f6451f0da3d42d53
dashboard link: https://syzkaller.appspot.com/bug?extid=19a9f729f05272857487
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=125b7999a00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=176deefba00000

Reported-by: syzbot+19a9f729f05272857487@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: ff92b9dd9268 ("scsi: mpt3sas: Update MPI headers to support Aero controllers")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection