Re: KASAN: use-after-free Read in __cfg8NUM_wpan_dev_from_attrs (2)

From: Dmitry Vyukov
Date: Wed Nov 11 2020 - 06:24:27 EST


On Thu, Aug 6, 2020 at 9:00 AM syzbot
<syzbot+14e0e4960091ffae7cf7@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit bf64ff4c2aac65d680dc639a511c781cf6b6ec08
> Author: Cong Wang <xiyou.wangcong@xxxxxxxxx>
> Date: Sat Jun 27 07:12:24 2020 +0000
>
> genetlink: get rid of family->attrbuf
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=12069494900000
> start commit: e44f65fd xen-netfront: remove redundant assignment to vari..
> git tree: net-next
> kernel config: https://syzkaller.appspot.com/x/.config?x=829871134ca5e230
> dashboard link: https://syzkaller.appspot.com/bug?extid=14e0e4960091ffae7cf7
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11818aa7100000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10f997d3100000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: genetlink: get rid of family->attrbuf
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

#syz fix: genetlink: get rid of family->attrbuf