Re: KASAN: use-after-free Write in refcount_warn_saturate

From: Dmitry Vyukov
Date: Wed Nov 11 2020 - 08:25:36 EST


On Fri, Sep 4, 2020 at 4:44 PM syzbot
<syzbot+7dd7f2f77a7a01d1dc14@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit b83764f9220a4a14525657466f299850bbc98de9
> Author: Miao-chen Chou <mcchou@xxxxxxxxxxxx>
> Date: Tue Jun 30 03:15:00 2020 +0000
>
> Bluetooth: Fix kernel oops triggered by hci_adv_monitors_clear()
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=10f92e3e900000
> start commit: c0842fbc random32: move the pseudo-random 32-bit definitio..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=cf567e8c7428377e
> dashboard link: https://syzkaller.appspot.com/bug?extid=7dd7f2f77a7a01d1dc14
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15b606dc900000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=123e87cc900000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: Bluetooth: Fix kernel oops triggered by hci_adv_monitors_clear()
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

#syz fix: Bluetooth: Fix kernel oops triggered by hci_adv_monitors_clear()