From mboxrd@z Thu Jan 1 00:00:00 1970 From: syzbot Date: Wed, 04 Dec 2019 21:41:01 +0000 Subject: Re: KASAN: slab-out-of-bounds Read in fbcon_get_font Message-Id: <0000000000003e640e0598e7abc3@google.com> List-Id: In-Reply-To: <0000000000002cfc3a0598d42b70@google.com> References: <0000000000002cfc3a0598d42b70@google.com> In-Reply-To: <0000000000002cfc3a0598d42b70@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable To: aryabinin@virtuozzo.com, b.zolnierkie@samsung.com, daniel.thompson@linaro.org, daniel.vetter@ffwll.ch, dri-devel@lists.freedesktop.org, dvyukov@google.com, ghalat@redhat.com, gleb@kernel.org, gwshan@linux.vnet.ibm.com, hpa@zytor.com, jmorris@namei.org, kasan-dev@googlegroups.com, kvm@vger.kernel.org, linux-fbdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, maarten.lankhorst@linux.intel.com, mingo@redhat.com, mpe@ellerman.id.au, pbonzini@redhat.com, penguin-kernel@i-love.sakura.ne.jp, ruscur@russell.cc, sam@ravnborg.org, serge@hallyn.com, stewart@linux.vnet.ibm.com, syzkaller-bugs@googlegroups.com, takedakn@nttdata.co.jp, tglx@linutronix.de, x86@kernel.org syzbot has bisected this bug to: commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31 Author: Russell Currey Date: Mon Feb 8 04:08:20 2016 +0000 powerpc/powernv: Remove support for p5ioc2 bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=127a042ae00000 start commit: 76bb8b05 Merge tag 'kbuild-v5.5' of git://git.kernel.org/p.. git tree: upstream final crash: https://syzkaller.appspot.com/x/report.txt?x=117a042ae00000 console output: https://syzkaller.appspot.com/x/log.txt?x=167a042ae00000 kernel config: https://syzkaller.appspot.com/x/.config?x=DD226651cb0f364b dashboard link: https://syzkaller.appspot.com/bug?extidD55ca3b3291de891abc syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11181edae00000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=105cbb7ae00000 Reported-by: syzbot+4455ca3b3291de891abc@syzkaller.appspotmail.com Fixes: 2de50e9674fc ("powerpc/powernv: Remove support for p5ioc2") For information about bisection process see: https://goo.gl/tpsmEJ#bisection From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.4 required=3.0 tests=FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3FF0C2D0B1 for ; Wed, 4 Dec 2019 21:41:05 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id BD5DF2073C for ; Wed, 4 Dec 2019 21:41:05 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728228AbfLDVlC (ORCPT ); Wed, 4 Dec 2019 16:41:02 -0500 Received: from mail-il1-f199.google.com ([209.85.166.199]:37230 "EHLO mail-il1-f199.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728060AbfLDVlC (ORCPT ); Wed, 4 Dec 2019 16:41:02 -0500 Received: by mail-il1-f199.google.com with SMTP id t19so838821ila.4 for ; Wed, 04 Dec 2019 13:41:01 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:in-reply-to:message-id:subject :from:to; bh=JrNPfPX8ooL5t/Vw7RYAMqCMbF8rwCtCqkj0exct6ns=; b=rp16tY23QqQ6jXVVkKzBPUHC6ryM1Dsg9ld2EuZyz9AEkzKVI9EzzWcBExuv6LzWJt 4+miI28+EEe8YxsQEx3ZjAwoRTjHpC0xBMCFSh2e1g5qMrtSs5Ez2oLLbU5GVyrs4LNu AKN8eI7/34vBzWSVaQGuRRFvRF2cxPsFduUuyQHM/3I+m24FXQwjCMCgCrv40qoGl139 b/8VslGi34rIJj9ePSRqxzG6MAxV3tdqYszYu6ik5j1JHReLS+UHm9+FTKjSJHakCd9D s+6DI9U5pqwZeejeae80j70/4fT+fbLrun6EfluPtzaPwWK3l+Lw+g9x9IuxmAy7z0aJ uvPg== X-Gm-Message-State: APjAAAVkWQBq8MCXsJejIz2rWMQt1gvxtWgWzKrQZBx3rp16IZVdtUai jBiyQHl/KyhTrwM0J7zy8mXQQ5h4DXc0FzSzRpPaNktRjoIf X-Google-Smtp-Source: APXvYqweHEd887dmgHwZ98tD32QtHsIIU9QUEjKbdT4mjyi6aPIBc1Zjh5EyBzHGg/jDulIxR32o86hj/XmAPTryABiezG7aI+6v MIME-Version: 1.0 X-Received: by 2002:a05:6638:d3:: with SMTP id w19mr5157404jao.127.1575495661402; Wed, 04 Dec 2019 13:41:01 -0800 (PST) Date: Wed, 04 Dec 2019 13:41:01 -0800 In-Reply-To: <0000000000002cfc3a0598d42b70@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <0000000000003e640e0598e7abc3@google.com> Subject: Re: KASAN: slab-out-of-bounds Read in fbcon_get_font From: syzbot To: aryabinin@virtuozzo.com, b.zolnierkie@samsung.com, daniel.thompson@linaro.org, daniel.vetter@ffwll.ch, dri-devel@lists.freedesktop.org, dvyukov@google.com, ghalat@redhat.com, gleb@kernel.org, gwshan@linux.vnet.ibm.com, hpa@zytor.com, jmorris@namei.org, kasan-dev@googlegroups.com, kvm@vger.kernel.org, linux-fbdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, maarten.lankhorst@linux.intel.com, mingo@redhat.com, mpe@ellerman.id.au, pbonzini@redhat.com, penguin-kernel@i-love.sakura.ne.jp, ruscur@russell.cc, sam@ravnborg.org, serge@hallyn.com, stewart@linux.vnet.ibm.com, syzkaller-bugs@googlegroups.com, takedakn@nttdata.co.jp, tglx@linutronix.de, x86@kernel.org Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes Sender: owner-linux-security-module@vger.kernel.org Precedence: bulk List-ID: syzbot has bisected this bug to: commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31 Author: Russell Currey Date: Mon Feb 8 04:08:20 2016 +0000 powerpc/powernv: Remove support for p5ioc2 bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=127a042ae00000 start commit: 76bb8b05 Merge tag 'kbuild-v5.5' of git://git.kernel.org/p.. git tree: upstream final crash: https://syzkaller.appspot.com/x/report.txt?x=117a042ae00000 console output: https://syzkaller.appspot.com/x/log.txt?x=167a042ae00000 kernel config: https://syzkaller.appspot.com/x/.config?x=dd226651cb0f364b dashboard link: https://syzkaller.appspot.com/bug?extid=4455ca3b3291de891abc syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11181edae00000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=105cbb7ae00000 Reported-by: syzbot+4455ca3b3291de891abc@syzkaller.appspotmail.com Fixes: 2de50e9674fc ("powerpc/powernv: Remove support for p5ioc2") For information about bisection process see: https://goo.gl/tpsmEJ#bisection From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.4 required=3.0 tests=FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5B3B3C43603 for ; Thu, 5 Dec 2019 07:45:10 +0000 (UTC) Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 3B53C205F4 for ; Thu, 5 Dec 2019 07:45:10 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 3B53C205F4 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=dri-devel-bounces@lists.freedesktop.org Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id E4C386F5A2; Thu, 5 Dec 2019 07:44:57 +0000 (UTC) Received: from mail-il1-f197.google.com (mail-il1-f197.google.com [209.85.166.197]) by gabe.freedesktop.org (Postfix) with ESMTPS id 0EBD36E94E for ; Wed, 4 Dec 2019 21:41:02 +0000 (UTC) Received: by mail-il1-f197.google.com with SMTP id k9so829415ili.8 for ; Wed, 04 Dec 2019 13:41:02 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:in-reply-to:message-id:subject :from:to; bh=JrNPfPX8ooL5t/Vw7RYAMqCMbF8rwCtCqkj0exct6ns=; b=iCaFFRkdbEe87bv08nyeJuwLufN8Ovit/H+nmQKXeXLXCVSsD8i66QmWHdQVhmrkOO HLcf889q6N9jzfUQi2dfVyHK0fyxgu6VkD/oqcWmlMEwSlKQkaqQljEKz4im3sjJpYWm fHyZDmnfg9quO8DW9N9NTjCZZbo8aoN//qN9dEA4jJ79xNc01rJQRTNrxpPr69cy2H2x CsyZ2SFMDflUXL4UzTIYV0Ead4PIiMHplk62UMbKdnsEjxOenvnRcutBj4Jco+x3/ypu InM83XyTKU8hrdks7kBZeGWhnh8aL0JSSlbYO59Hw0gobI3NIKZ4PdnTMq0R3NqnUvvl h3QA== X-Gm-Message-State: APjAAAX4UpRnMx9C2ECQyMe1p004SOYFWZu+Lh7g+YvXaWufc/uQPj3q F7hhgeWRQ+JwB/2nt6MrMJjHVliP9zgiBvc8cje6Imhbx5be X-Google-Smtp-Source: APXvYqweHEd887dmgHwZ98tD32QtHsIIU9QUEjKbdT4mjyi6aPIBc1Zjh5EyBzHGg/jDulIxR32o86hj/XmAPTryABiezG7aI+6v MIME-Version: 1.0 X-Received: by 2002:a05:6638:d3:: with SMTP id w19mr5157404jao.127.1575495661402; Wed, 04 Dec 2019 13:41:01 -0800 (PST) Date: Wed, 04 Dec 2019 13:41:01 -0800 In-Reply-To: <0000000000002cfc3a0598d42b70@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <0000000000003e640e0598e7abc3@google.com> Subject: Re: KASAN: slab-out-of-bounds Read in fbcon_get_font From: syzbot To: aryabinin@virtuozzo.com, b.zolnierkie@samsung.com, daniel.thompson@linaro.org, daniel.vetter@ffwll.ch, dri-devel@lists.freedesktop.org, dvyukov@google.com, ghalat@redhat.com, gleb@kernel.org, gwshan@linux.vnet.ibm.com, hpa@zytor.com, jmorris@namei.org, kasan-dev@googlegroups.com, kvm@vger.kernel.org, linux-fbdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, maarten.lankhorst@linux.intel.com, mingo@redhat.com, mpe@ellerman.id.au, pbonzini@redhat.com, penguin-kernel@i-love.sakura.ne.jp, ruscur@russell.cc, sam@ravnborg.org, serge@hallyn.com, stewart@linux.vnet.ibm.com, syzkaller-bugs@googlegroups.com, takedakn@nttdata.co.jp, tglx@linutronix.de, x86@kernel.org X-Mailman-Approved-At: Thu, 05 Dec 2019 07:44:39 +0000 X-BeenThere: dri-devel@lists.freedesktop.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Direct Rendering Infrastructure - Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Transfer-Encoding: base64 Content-Type: text/plain; charset="utf-8"; Format="flowed"; DelSp="yes" Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" c3l6Ym90IGhhcyBiaXNlY3RlZCB0aGlzIGJ1ZyB0bzoKCmNvbW1pdCAyZGU1MGU5Njc0ZmM0Y2Ez YzYxNzRiMDQ0NzdmNjllYjI2YjRlZTMxCkF1dGhvcjogUnVzc2VsbCBDdXJyZXkgPHJ1c2N1ckBy dXNzZWxsLmNjPgpEYXRlOiAgIE1vbiBGZWIgOCAwNDowODoyMCAyMDE2ICswMDAwCgogICAgIHBv d2VycGMvcG93ZXJudjogUmVtb3ZlIHN1cHBvcnQgZm9yIHA1aW9jMgoKYmlzZWN0aW9uIGxvZzog IGh0dHBzOi8vc3l6a2FsbGVyLmFwcHNwb3QuY29tL3gvYmlzZWN0LnR4dD94PTEyN2EwNDJhZTAw MDAwCnN0YXJ0IGNvbW1pdDogICA3NmJiOGIwNSBNZXJnZSB0YWcgJ2tidWlsZC12NS41JyBvZiBn aXQ6Ly9naXQua2VybmVsLm9yZy9wLi4KZ2l0IHRyZWU6ICAgICAgIHVwc3RyZWFtCmZpbmFsIGNy YXNoOiAgICBodHRwczovL3N5emthbGxlci5hcHBzcG90LmNvbS94L3JlcG9ydC50eHQ/eD0xMTdh MDQyYWUwMDAwMApjb25zb2xlIG91dHB1dDogaHR0cHM6Ly9zeXprYWxsZXIuYXBwc3BvdC5jb20v eC9sb2cudHh0P3g9MTY3YTA0MmFlMDAwMDAKa2VybmVsIGNvbmZpZzogIGh0dHBzOi8vc3l6a2Fs bGVyLmFwcHNwb3QuY29tL3gvLmNvbmZpZz94PWRkMjI2NjUxY2IwZjM2NGIKZGFzaGJvYXJkIGxp bms6IGh0dHBzOi8vc3l6a2FsbGVyLmFwcHNwb3QuY29tL2J1Zz9leHRpZD00NDU1Y2EzYjMyOTFk ZTg5MWFiYwpzeXogcmVwcm86ICAgICAgaHR0cHM6Ly9zeXprYWxsZXIuYXBwc3BvdC5jb20veC9y ZXByby5zeXo/eD0xMTE4MWVkYWUwMDAwMApDIHJlcHJvZHVjZXI6ICAgaHR0cHM6Ly9zeXprYWxs ZXIuYXBwc3BvdC5jb20veC9yZXByby5jP3g9MTA1Y2JiN2FlMDAwMDAKClJlcG9ydGVkLWJ5OiBz eXpib3QrNDQ1NWNhM2IzMjkxZGU4OTFhYmNAc3l6a2FsbGVyLmFwcHNwb3RtYWlsLmNvbQpGaXhl czogMmRlNTBlOTY3NGZjICgicG93ZXJwYy9wb3dlcm52OiBSZW1vdmUgc3VwcG9ydCBmb3IgcDVp b2MyIikKCkZvciBpbmZvcm1hdGlvbiBhYm91dCBiaXNlY3Rpb24gcHJvY2VzcyBzZWU6IGh0dHBz Oi8vZ29vLmdsL3Rwc21FSiNiaXNlY3Rpb24KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX18KZHJpLWRldmVsIG1haWxpbmcgbGlzdApkcmktZGV2ZWxAbGlzdHMu ZnJlZWRlc2t0b3Aub3JnCmh0dHBzOi8vbGlzdHMuZnJlZWRlc2t0b3Aub3JnL21haWxtYW4vbGlz dGluZm8vZHJpLWRldmVs