KASAN: use-after-free Read in ath9k_hif_usb_rx_cb (2) should share the same root cause with "KASAN: slab-out-of-bounds Read in ath9k_hif_usb_rx_cb (2)"

From: 慕冬亮
Date: Wed Jan 13 2021 - 06:48:51 EST


Dear kernel developers,

I found that KASAN: use-after-free Read in ath9k_hif_usb_rx_cb (2) and
"KASAN: slab-out-of-bounds Read in ath9k_hif_usb_rx_cb (2)" should
share the same root cause.

The reasons for my above statement, 1) the stack trace is the same;
2) we observed two crash behaviors appear alternatively when you run
one PoC in its building environment multiple times. 3) their PoCs have
a really high similarity

If you can have any issues with this statement or our information is
useful for you, please let us know. Thanks very much.

--
My best regards to you.

No System Is Safe!
Dongliang Mu