Re: [syzbot] KASAN: use-after-free Read in io_poll_check_events

From: syzbot
Date: Fri Apr 01 2022 - 08:26:33 EST


syzbot has bisected this issue to:

commit d570aa1c4f191100f502edfc240e8d49687f62ac
Author: Jens Axboe <axboe@xxxxxxxxx>
Date: Thu Mar 31 18:38:46 2022 +0000

io_uring: drop the old style inflight file tracking

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11507c5b700000
start commit: e5071887cd22 Add linux-next specific files for 20220401
git tree: linux-next
final oops: https://syzkaller.appspot.com/x/report.txt?x=13507c5b700000
console output: https://syzkaller.appspot.com/x/log.txt?x=15507c5b700000
kernel config: https://syzkaller.appspot.com/x/.config?x=17fed8f59a304eee
dashboard link: https://syzkaller.appspot.com/bug?extid=edb9c7738ba8cbdbf197
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1016f8f3700000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14907c5b700000

Reported-by: syzbot+edb9c7738ba8cbdbf197@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: d570aa1c4f19 ("io_uring: drop the old style inflight file tracking")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection