Re: [syzbot] [serial?] KASAN: use-after-free Read in gsm_cleanup_mux

From: Aleksandr Nogikh
Date: Mon Oct 02 2023 - 07:40:18 EST


On Sun, Oct 1, 2023 at 6:29 AM syzbot
<syzbot+893c55305230e719a203@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit 3c4f8333b582487a2d1e02171f1465531cde53e3
> Author: Yi Yang <yiyang13@xxxxxxxxxx>
> Date: Fri Aug 11 03:11:21 2023 +0000
>
> tty: n_gsm: fix the UAF caused by race condition in gsm_cleanup_mux
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=121e6a92680000
> start commit: a4412fdd49dc error-injection: Add prompt for function erro..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=cc4b2e0a8e8a8366
> dashboard link: https://syzkaller.appspot.com/bug?extid=893c55305230e719a203
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12b1ca83880000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1023c5e3880000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: tty: n_gsm: fix the UAF caused by race condition in gsm_cleanup_mux

#syz fix: tty: n_gsm: fix the UAF caused by race condition in gsm_cleanup_mux

>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection
>
> --