Re: KASAN: null-ptr-deref Read in refcount_sub_and_test_checked (2)

From: syzbot
Date: Fri Dec 06 2019 - 20:30:19 EST


syzbot suspects this bug was fixed by commit:

commit 62dcb4f41836bd3c44b5b651bb6df07ea4cb1551
Author: Hans Verkuil <hverkuil-cisco@xxxxxxxxx>
Date: Thu Nov 8 12:23:37 2018 +0000

media: vb2: check memory model for VIDIOC_CREATE_BUFS

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14972e41e00000
start commit: ccda4af0 Linux 4.20-rc2
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=4a0a89f12ca9b0f5
dashboard link: https://syzkaller.appspot.com/bug?extid=0468b73bdbb243217224
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16d20893400000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=118f5a2b400000

If the result looks correct, please mark the bug fixed by replying with:

#syz fix: media: vb2: check memory model for VIDIOC_CREATE_BUFS

For information about bisection process see: https://goo.gl/tpsmEJ#bisection