Re: [syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_connect (2)

From: syzbot
Date: Tue Sep 10 2024 - 14:43:13 EST


syzbot has bisected this issue to:

commit 5af1f84ed13a416297ab9ced7537f4d5ae7f329a
Author: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>
Date: Thu Aug 3 18:04:51 2023 +0000

Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=12477bc7980000
start commit: 788220eee30d Merge tag 'pm-6.11-rc7' of git://git.kernel.o..
git tree: upstream
final oops: https://syzkaller.appspot.com/x/report.txt?x=11477bc7980000
console output: https://syzkaller.appspot.com/x/log.txt?x=16477bc7980000
kernel config: https://syzkaller.appspot.com/x/.config?x=57042fe37c7ee7c2
dashboard link: https://syzkaller.appspot.com/bug?extid=c12e2f941af1feb5632c
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11da6f29980000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1304189f980000

Reported-by: syzbot+c12e2f941af1feb5632c@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 5af1f84ed13a ("Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection