Re: KASAN: use-after-free Read in nf_ct_deliver_cached_events

From: syzbot
Date: Fri Oct 25 2019 - 00:20:37 EST


syzbot has bisected this bug to:

commit 2341e0775747864b684abe8627f3d45b167f2940
Author: David Howells <dhowells@xxxxxxxxxx>
Date: Thu Jun 9 22:02:51 2016 +0000

rxrpc: Simplify connect() implementation and simplify sendmsg() op

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=12f869df600000
start commit: 12d61c69 Add linux-next specific files for 20191024
git tree: linux-next
final crash: https://syzkaller.appspot.com/x/report.txt?x=11f869df600000
console output: https://syzkaller.appspot.com/x/log.txt?x=16f869df600000
kernel config: https://syzkaller.appspot.com/x/.config?x=afb75fd8c9fd5ed8
dashboard link: https://syzkaller.appspot.com/bug?extid=c7aabc9fe93e7f3637ba
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10938e18e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=147caa97600000

Reported-by: syzbot+c7aabc9fe93e7f3637ba@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: 2341e0775747 ("rxrpc: Simplify connect() implementation and simplify sendmsg() op")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection