Re: [syzbot] KASAN: use-after-free Read in __queue_work (3)

From: Dmitry Vyukov
Date: Fri May 14 2021 - 03:50:56 EST


On Thu, May 13, 2021 at 6:27 PM syzbot
<syzbot+77e5e02c6c81136cdaff@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit e2cb6b891ad2b8caa9131e3be70f45243df82a80
> Author: Lin Ma <linma@xxxxxxxxxx>
> Date: Mon Apr 12 11:17:57 2021 +0000
>
> bluetooth: eliminate the potential race condition when removing the HCI controller
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=127b3593d00000
> start commit: c0842fbc random32: move the pseudo-random 32-bit definitio..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=cf567e8c7428377e
> dashboard link: https://syzkaller.appspot.com/bug?extid=77e5e02c6c81136cdaff
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=140e36a4900000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: bluetooth: eliminate the potential race condition when removing the HCI controller
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection


Looks reasonable based on the commit and bisection log.
Unfortunately I cannot easily send this as my email client will wrap
the commit title line (longer than 80 chars)...