Re: general protection fault in tss_update_io_bitmap

From: Kees Cook
Date: Thu Nov 21 2019 - 12:36:20 EST


On Thu, Nov 21, 2019 at 12:01:15PM +0100, Borislav Petkov wrote:
> On Wed, Nov 20, 2019 at 05:55:09PM -0800, syzbot wrote:
> > Hello,
> >
> > syzbot found the following crash on:
> >
> > HEAD commit: 5d1131b4 Add linux-next specific files for 20191119
> > git tree: linux-next
> > console output: https://syzkaller.appspot.com/x/log.txt?x=177979d2e00000
> > kernel config: https://syzkaller.appspot.com/x/.config?x=b60c562d89e5a8df
> > dashboard link: https://syzkaller.appspot.com/bug?extid=81e6ff9d4cdb05fd4f5e
> > compiler: gcc (GCC) 9.0.0 20181231 (experimental)
> > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1549ed8ce00000
> > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17f91012e00000
> >
> > The bug was bisected to:
> >
> > commit 111e7b15cf10f6e973ccf537c70c66a5de539060
> > Author: Thomas Gleixner <tglx@xxxxxxxxxxxxx>
> > Date: Tue Nov 12 20:40:33 2019 +0000
> >
> > x86/ioperm: Extend IOPL config to control ioperm() as well
> >
> > bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=10490e86e00000
> > final crash: https://syzkaller.appspot.com/x/report.txt?x=12490e86e00000
> > console output: https://syzkaller.appspot.com/x/log.txt?x=14490e86e00000
>
> Try this:
>
> https://git.kernel.org/tip/e3cb0c7102f04c83bf1a7cb1d052e92749310b46

Rewording so syzbot can see it (https://goo.gl/tpsmEJ#testing-patches) ...

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git e3cb0c7102f04c83bf1a7cb1d052e92749310b46

--
Kees Cook