Re: KASAN: use-after-free Read in tipc_udp_nl_dump_remoteip

From: syzbot
Date: Tue Oct 08 2019 - 17:06:03 EST


syzbot has bisected this bug to:

commit 057af70713445fad2459aa348c9c2c4ecf7db938
Author: Jiri Pirko <jiri@xxxxxxxxxxxx>
Date: Sat Oct 5 18:04:39 2019 +0000

net: tipc: have genetlink code to parse the attrs during dumpit

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11675620e00000
start commit: 056ddc38 Merge branch 'stmmac-next'
git tree: net-next
final crash: https://syzkaller.appspot.com/x/report.txt?x=13675620e00000
console output: https://syzkaller.appspot.com/x/log.txt?x=15675620e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=d9be300620399522
dashboard link: https://syzkaller.appspot.com/bug?extid=dbe02e13bcce52bcf182
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=137ecdfb600000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15dd0d0b600000

Reported-by: syzbot+dbe02e13bcce52bcf182@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 057af7071344 ("net: tipc: have genetlink code to parse the attrs during dumpit")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection