Re: KASAN: use-after-free Read in bpf_cgroup_storage_release

From: Daniel Borkmann
Date: Fri Aug 03 2018 - 04:48:57 EST


On 08/02/2018 07:59 PM, syzbot wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit:ÂÂÂ fc2a3b5dd618 Merge branch 'bpf-cgroup-local-storage'
> git tree:ÂÂÂÂÂÂ bpf-next
> console output: https://syzkaller.appspot.com/x/log.txt?x=17a6a1c8400000
> kernel config:Â https://syzkaller.appspot.com/x/.config?x=3bfcc1651962483
> dashboard link: https://syzkaller.appspot.com/bug?extid=25554ab865a12b51c66f
> compiler:ÂÂÂÂÂÂ gcc (GCC) 8.0.1 20180413 (experimental)
> syzkaller repro:https://syzkaller.appspot.com/x/repro.syz?x=12c4b9b4400000
> C reproducer:ÂÂ https://syzkaller.appspot.com/x/repro.c?x=13e9d6f0400000
>
> IMPORTANT: if you fix the bug, please add the following tag to the commit:
> Reported-by: syzbot+25554ab865a12b51c66f@xxxxxxxxxxxxxxxxxxxxxxxxx

#syz fix: 82c018d734a7 Merge branch 'bpf-cgroup-local-storage'