Re: KASAN: use-after-free Read in tty_open

From: Eric Biggers
Date: Fri Apr 24 2020 - 22:19:04 EST


On Fri, Apr 24, 2020 at 05:23:03PM -0700, syzbot wrote:
> syzbot suspects this bug was fixed by commit:
>
> commit ca4463bf8438b403596edd0ec961ca0d4fbe0220
> Author: Eric Biggers <ebiggers@xxxxxxxxxx>
> Date: Sun Mar 22 03:43:04 2020 +0000
>
> vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11594fc8100000
> start commit: 07c4b9e9 Merge tag 'scsi-fixes' of git://git.kernel.org/pu..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=79f79de2a27d3e3d
> dashboard link: https://syzkaller.appspot.com/bug?extid=9af6d43c1beabec8fd05
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=113886fae00000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1263520ae00000
>
> If the result looks correct, please mark the bug fixed by replying with:
>
> #syz fix: vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

#syz fix: vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console