Re: BUG: corrupted list in _cma_attach_to_dev

From: Jason Gunthorpe
Date: Mon Mar 09 2020 - 19:03:52 EST


On Mon, Mar 09, 2020 at 01:20:04PM -0700, syzbot wrote:
> Hello,
>
> syzbot has tested the proposed patch and the reproducer did not trigger crash:
>
> Reported-and-tested-by: syzbot+06b50ee4a9bd73e8b89f@xxxxxxxxxxxxxxxxxxxxxxxxx
>
> Tested on:
>
> commit: 0aeb3622 RDMA/hns: fix spelling mistake "attatch" -> "atta..
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/rdma/rdma.git for-next
> kernel config: https://syzkaller.appspot.com/x/.config?x=b58f96e9824c82cb
> dashboard link: https://syzkaller.appspot.com/bug?extid=06b50ee4a9bd73e8b89f
> compiler: gcc (GCC) 9.0.0 20181231 (experimental)
>
> Note: testing is done by a robot and is best-effort only.

#syz dup: KASAN: use-after-free Read in rdma_listen (2)