Re: KASAN: slab-out-of-bounds Write in pipe_write

From: syzbot
Date: Mon Dec 02 2019 - 14:54:04 EST


syzbot has bisected this bug to:

commit a194dfe6e6f6f7205eea850a420f2bc6a1541209
Author: David Howells <dhowells@xxxxxxxxxx>
Date: Fri Sep 20 15:32:19 2019 +0000

pipe: Rearrange sequence in pipe_write() to preallocate slot

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=16085abce00000
start commit: b94ae8ad Merge tag 'seccomp-v5.5-rc1' of git://git.kernel...
git tree: upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=15085abce00000
console output: https://syzkaller.appspot.com/x/log.txt?x=11085abce00000
kernel config: https://syzkaller.appspot.com/x/.config?x=ff560c3de405258c
dashboard link: https://syzkaller.appspot.com/bug?extid=838eb0878ffd51f27c41
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=146a9f86e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1791d82ae00000

Reported-by: syzbot+838eb0878ffd51f27c41@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: a194dfe6e6f6 ("pipe: Rearrange sequence in pipe_write() to preallocate slot")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection