Re: [syzbot] [kernel?] KASAN: slab-use-after-free Read in binder_release_work

From: Carlos Llamas
Date: Mon Jan 13 2025 - 10:00:12 EST


On Sat, Jan 11, 2025 at 02:45:04PM -0800, syzbot wrote:
> syzbot suspects this issue was fixed by commit:
>
> commit 7e20434cbca814cb91a0a261ca0106815ef48e5f
> Author: Carlos Llamas <cmllamas@xxxxxxxxxx>
> Date: Thu Sep 26 23:36:14 2024 +0000
>
> binder: fix freeze UAF in binder_release_work()
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1380f218580000
> start commit: 3e5e6c9900c3 Merge tag 'nfsd-6.12-3' of git://git.kernel.o..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=cf5329baa0b5a257
> dashboard link: https://syzkaller.appspot.com/bug?extid=9ba7a8cdae0440edd57b
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1245faa7980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=105db630580000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: binder: fix freeze UAF in binder_release_work()
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

#syz fix: binder: fix freeze UAF in binder_release_work()