Re: [syzbot] KASAN: use-after-free Write in get_ucounts

From: Dmitry Vyukov
Date: Fri Sep 17 2021 - 03:54:12 EST


On Tue, 7 Sept 2021 at 08:51, syzbot
<syzbot+8c3af233123df0578a5c@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit 345daff2e994ee844d6a609c37f085695fbb4c4d
> Author: Alexey Gladkov <legion@xxxxxxxxxx>
> Date: Tue Jul 27 15:24:18 2021 +0000
>
> ucounts: Fix race condition between alloc_ucounts and put_ucounts
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1378d0ed300000
> start commit: d5ad8ec3cfb5 Merge tag 'media/v5.14-2' of git://git.kernel..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=702bfdfbf389c324
> dashboard link: https://syzkaller.appspot.com/bug?extid=8c3af233123df0578a5c
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16fedec6300000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: ucounts: Fix race condition between alloc_ucounts and put_ucounts

Looks legit:

#syz fix: ucounts: Fix race condition between alloc_ucounts and put_ucounts