Re: KASAN: slab-out-of-bounds Read in bpf_skb_change_proto

From: Daniel Borkmann
Date: Mon Jun 11 2018 - 05:43:08 EST


On 06/10/2018 05:27 PM, syzbot wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit:ÂÂÂ a16afaf7928b Merge tag 'for-v4.18' of git://git.kernel.org..
> git tree:ÂÂÂÂÂÂ upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=1338f6bf800000
> kernel config:Â https://syzkaller.appspot.com/x/.config?x=314f2150f36c16ca
> dashboard link: https://syzkaller.appspot.com/bug?extid=d2d729bdde65dee3eae6
> compiler:ÂÂÂÂÂÂ gcc (GCC) 8.0.1 20180413 (experimental)
> syzkaller repro:https://syzkaller.appspot.com/x/repro.syz?x=1173381f800000
> C reproducer:ÂÂ https://syzkaller.appspot.com/x/repro.c?x=171f90cf800000
>
> IMPORTANT: if you fix the bug, please add the following tag to the commit:
> Reported-by: syzbot+d2d729bdde65dee3eae6@xxxxxxxxxxxxxxxxxxxxxxxxx

#syz fix: bpf: reject passing modified ctx to helper functions