Re: KASAN: use-after-free Read in bpf_csum_update

From: Daniel Borkmann
Date: Fri Jun 08 2018 - 05:53:03 EST


On 06/04/2018 01:36 AM, syzbot wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit:ÂÂÂ bcece5dc40b9 bpf: Change bpf_fib_lookup to return -EAFNOSU..
> git tree:ÂÂÂÂÂÂ bpf-next
> console output: https://syzkaller.appspot.com/x/log.txt?x=161e2c6f800000
> kernel config:Â https://syzkaller.appspot.com/x/.config?x=e4078980b886800c
> dashboard link: https://syzkaller.appspot.com/bug?extid=3d0b2441dbb71751615e
> compiler:ÂÂÂÂÂÂ gcc (GCC) 8.0.1 20180413 (experimental)
> syzkaller repro:https://syzkaller.appspot.com/x/repro.syz?x=17cb5adf800000
> C reproducer:ÂÂ https://syzkaller.appspot.com/x/repro.c?x=17ebf19f800000

#syz fix: bpf: reject passing modified ctx to helper functions