Re: KASAN: use-after-free Write in tlb_finish_mmu

From: Jason Wang
Date: Wed Jul 24 2019 - 03:07:46 EST



On 2019/7/20 äå4:04, syzbot wrote:
syzbot has bisected this bug to:

commit 7f466032dc9e5a61217f22ea34b2df932786bbfc
Author: Jason Wang <jasowang@xxxxxxxxxx>
Date:ÂÂ Fri May 24 08:12:18 2019 +0000

ÂÂÂ vhost: access vq metadata through kernel virtual address

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11642a58600000
start commit:ÂÂ 22051d9c Merge tag 'platform-drivers-x86-v5.3-2' of git://..
git tree:ÂÂÂÂÂÂ upstream
final crash: https://syzkaller.appspot.com/x/report.txt?x=13642a58600000
console output: https://syzkaller.appspot.com/x/log.txt?x=15642a58600000
kernel config: https://syzkaller.appspot.com/x/.config?x=d831b9cbe82e79e4
dashboard link: https://syzkaller.appspot.com/bug?extid=8267e9af795434ffadad
userspace arch: i386
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10d58784600000

Reported-by: syzbot+8267e9af795434ffadad@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 7f466032dc9e ("vhost: access vq metadata through kernel virtual address")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection


#syz dup: WARNING in __mmdrop