Re: KASAN: use-after-free Read in tls_push_sg

From: Jakub Kicinski
Date: Mon Aug 19 2019 - 18:42:41 EST


On Fri, 17 May 2019 11:40:05 -0700, syzbot wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit: 35c99ffa Merge tag 'for_linus' of git://git.kernel.org/pub..
> git tree: net-next
> console output: https://syzkaller.appspot.com/x/log.txt?x=10ff3322a00000
> kernel config: https://syzkaller.appspot.com/x/.config?x=82f0809e8f0a8c87
> dashboard link: https://syzkaller.appspot.com/bug?extid=66fbe4719f6ef22754ee
> compiler: gcc (GCC) 9.0.0 20181231 (experimental)
>
> Unfortunately, I don't have any reproducer for this crash yet.
>
> IMPORTANT: if you fix the bug, please add the following tag to the commit:
> Reported-by: syzbot+66fbe4719f6ef22754ee@xxxxxxxxxxxxxxxxxxxxxxxxx

Most likely:

#syz fix: net/tls: fix page double free on TX cleanup