Re: [syzbot] KASAN: null-ptr-deref Write in l2cap_chan_put

From: Dmitry Vyukov
Date: Sat Dec 04 2021 - 04:48:24 EST


On Fri, 26 Nov 2021 at 17:47, syzbot
<syzbot+452e9465a3b2817fa4c2@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit 1bff51ea59a9afb67d2dd78518ab0582a54a472c
> Author: Wang ShaoBo <bobo.shaobowang@xxxxxxxxxx>
> Date: Wed Sep 1 00:35:37 2021 +0000
>
> Bluetooth: fix use-after-free error in lock_sock_nested()
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=141cfa45b00000
> start commit: c70672d8d316 Merge tag 's390-5.9-5' of git://git.kernel.or..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=bd46548257448703
> dashboard link: https://syzkaller.appspot.com/bug?extid=452e9465a3b2817fa4c2
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=152f31f9900000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: Bluetooth: fix use-after-free error in lock_sock_nested()
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

Looks reasonable:

#syz fix: Bluetooth: fix use-after-free error in lock_sock_nested()