Re: KASAN: use-after-free Read in hci_chan_del

From: syzbot
Date: Mon Aug 03 2020 - 13:08:09 EST


syzbot has bisected this issue to:

commit 166beccd47e11e4d27477e8ca1d7eda47cf3b2da
Author: Eric Anholt <eric@xxxxxxxxxx>
Date: Mon Oct 3 18:52:06 2016 +0000

staging/vchi: Convert to current get_user_pages() arguments.

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=178321a4900000
start commit: 5a30a789 Merge tag 'x86-urgent-2020-08-02' of git://git.ke..
git tree: upstream
final oops: https://syzkaller.appspot.com/x/report.txt?x=144321a4900000
console output: https://syzkaller.appspot.com/x/log.txt?x=104321a4900000
kernel config: https://syzkaller.appspot.com/x/.config?x=e59ee776d5aa8d55
dashboard link: https://syzkaller.appspot.com/bug?extid=305a91e025a73e4fd6ce
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=127dd914900000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=122a94ec900000

Reported-by: syzbot+305a91e025a73e4fd6ce@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 166beccd47e1 ("staging/vchi: Convert to current get_user_pages() arguments.")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection