Re: [syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_unregister_user

From: syzbot
Date: Mon Dec 23 2024 - 17:29:13 EST


syzbot has bisected this issue to:

commit c8992cffbe7411c6da4c4416d5eecfc6b78e0fec
Author: Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>
Date: Wed Dec 1 18:55:05 2021 +0000

Bluetooth: hci_event: Use of a function table to handle Command Complete

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14d538c4580000
start commit: 30b981796b94 selftests: drv-net: test empty queue and NAPI..
git tree: net
final oops: https://syzkaller.appspot.com/x/report.txt?x=16d538c4580000
console output: https://syzkaller.appspot.com/x/log.txt?x=12d538c4580000
kernel config: https://syzkaller.appspot.com/x/.config?x=6a2b862bf4a5409f
dashboard link: https://syzkaller.appspot.com/bug?extid=14b6d57fb728e27ce23c
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12050adf980000

Reported-by: syzbot+14b6d57fb728e27ce23c@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: c8992cffbe74 ("Bluetooth: hci_event: Use of a function table to handle Command Complete")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection