All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+4c0d0c4cde787116d465@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org
Subject: Re: [syzbot] [PATCH] test uaf in sco_sock_timeout
Date: Thu, 16 Nov 2023 17:01:55 -0800	[thread overview]
Message-ID: <000000000000c3e53a060a4eae0a@google.com> (raw)
In-Reply-To: <000000000000797bd1060a457c08@google.com>

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.

***

Subject: [PATCH] test uaf in sco_sock_timeout
Author: lizhi.xu@windriver.com

#syz test https://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git 8de1e7afcc1c

diff --git a/net/bluetooth/sco.c b/net/bluetooth/sco.c
index c736186aba26..515b52e14b5f 100644
--- a/net/bluetooth/sco.c
+++ b/net/bluetooth/sco.c
@@ -415,6 +415,8 @@ static void sco_sock_cleanup_listen(struct sock *parent)
  */
 static void sco_sock_kill(struct sock *sk)
 {
+	struct sco_conn *conn = container_of(sk, struct sco_conn, sk);
+
 	if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
 		return;
 
@@ -423,6 +425,9 @@ static void sco_sock_kill(struct sock *sk)
 	/* Kill poor orphan */
 	bt_sock_unlink(&sco_sk_list, sk);
 	sock_set_flag(sk, SOCK_DEAD);
+	sco_conn_lock(conn);
+	conn->sk = NULL;
+	sco_conn_unlock(conn);
 	sock_put(sk);
 }
 

  reply	other threads:[~2023-11-17  1:04 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-11-16 14:03 [syzbot] Test on mainline syzbot
2023-11-17  1:01 ` syzbot [this message]
2023-11-18  3:25 ` [syzbot] [PATCH] Test uaf in sco_sock_timeout syzbot
2023-12-06  3:58 ` [syzbot] [bluetooth?] KASAN: slab-use-after-free Write " syzbot
2024-10-01 19:50 ` [syzbot] Re: [PATCH v1] Bluetooth: SCO: Use disable_delayed_work_sync syzbot
2024-10-02 18:27 ` [syzbot] Re: [PATCH v2] " syzbot
2024-10-02 19:20 ` [syzbot] Re: [PATCH v3] " syzbot
2024-10-02 19:47 ` syzbot
2024-10-02 20:46 ` syzbot
2024-10-03 15:38 ` syzbot
2024-10-03 16:33 ` syzbot
2024-10-03 19:21 ` syzbot
2024-10-04 16:06 ` syzbot
2024-10-04 17:24 ` syzbot
2024-10-07 17:16 ` syzbot
2024-10-07 20:54 ` syzbot
2024-10-22 16:44 ` syzbot
2024-10-22 19:19 ` syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=000000000000c3e53a060a4eae0a@google.com \
    --to=syzbot+4c0d0c4cde787116d465@syzkaller.appspotmail.com \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.