diff for duplicates of <20200927092701.GA1037755@PWN> diff --git a/a/1.txt b/N1/1.txt index e56a7c9..a6a6c88 100644 --- a/a/1.txt +++ b/N1/1.txt @@ -18,22 +18,22 @@ On Sun, Sep 27, 2020 at 05:28:12PM +0900, Tetsuo Handa wrote: > > static char fontdata[8192] = { 2 }; > -> [ 227.065369] bit_putcs: width=1 cellsize=1 count maxcnt92 scan_align=0 buf_align=0 image.height=1 -> [ 227.066254] bit_putcs: width=1 cellsize=1 count maxcnt92 scan_align=0 buf_align=0 image.height=1 -> [ 227.067642] vcÿff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0 -> [ 227.067699] vcpÿff8880d69b4000 before: ->vc_rowsH0 ->vc_cols ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1 -> [ 227.067774] vcpÿff8880d69b4000 after: ->vc_rowsH0 ->vc_cols ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1 ret=0 -> [ 227.067831] vcpÿff8880cac4b000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.067891] vcpÿff8880cac4b000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.067947] vcpÿff8880c6180000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068007] vcpÿff8880c6180000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.068063] vcpÿff8880d6b84000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068123] vcpÿff8880d6b84000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.068179] vcpÿff8880ca8c0000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068255] vcpÿff8880ca8c0000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.068455] vcpÿff8880cbd5d000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068515] vcpÿff8880cbd5d000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.084709] ================================= +> [ 227.065369] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1 +> [ 227.066254] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1 +> [ 227.067642] vc=ffff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0 +> [ 227.067699] vcp=ffff8880d69b4000 before: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1 +> [ 227.067774] vcp=ffff8880d69b4000 after: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1 ret=0 +> [ 227.067831] vcp=ffff8880cac4b000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.067891] vcp=ffff8880cac4b000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.067947] vcp=ffff8880c6180000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068007] vcp=ffff8880c6180000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.068063] vcp=ffff8880d6b84000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068123] vcp=ffff8880d6b84000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.068179] vcp=ffff8880ca8c0000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068255] vcp=ffff8880ca8c0000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.068455] vcp=ffff8880cbd5d000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068515] vcp=ffff8880cbd5d000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.084709] ================================================================== > [ 227.084729] BUG: KASAN: slab-out-of-bounds in soft_cursor+0x34e/0x4a0 > [ 227.084748] Read of size 9 at addr ffff8880c98d5930 by task a.out/1662 @@ -41,9 +41,14 @@ Very interesting, I remember seeing this on the syzbot dashboard... Yes, I guess it is this one: KASAN: slab-out-of-bounds Read in soft_cursor - https://syzkaller.appspot.com/bug?idk8355d27b2b94fb5cedf4655e3a59162d9e48e3 + https://syzkaller.appspot.com/bug?id=6b8355d27b2b94fb5cedf4655e3a59162d9e48e3 There is a `0x560aul` ioctl() in the reproducer, which is `VT_RESIZEX`. Thank you, Peilin Ye + +_______________________________________________ +dri-devel mailing list +dri-devel@lists.freedesktop.org +https://lists.freedesktop.org/mailman/listinfo/dri-devel diff --git a/a/content_digest b/N1/content_digest index eda22f9..b698c9d 100644 --- a/a/content_digest +++ b/N1/content_digest @@ -4,7 +4,7 @@ "ref\0494395bc-a7dd-fdb1-8196-a236a266ef54@i-love.sakura.ne.jp\0" "From\0Peilin Ye <yepeilin.cs@gmail.com>\0" "Subject\0Re: KASAN: use-after-free Read in bit_putcs\0" - "Date\0Sun, 27 Sep 2020 09:27:01 +0000\0" + "Date\0Sun, 27 Sep 2020 05:27:01 -0400\0" "To\0Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>\0" "Cc\0syzbot <syzbot+b308f5fd049fbbc6e74f@syzkaller.appspotmail.com>" linux-fbdev@vger.kernel.org @@ -40,22 +40,22 @@ "> \n" "> static char fontdata[8192] = { 2 };\n" "> \n" - "> [ 227.065369] bit_putcs: width=1 cellsize=1 count\302\200 maxcnt\302\20192 scan_align=0 buf_align=0 image.height=1\n" - "> [ 227.066254] bit_putcs: width=1 cellsize=1 count\302\200 maxcnt\302\20192 scan_align=0 buf_align=0 image.height=1\n" - "> [ 227.067642] vc\303\277ff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0\n" - "> [ 227.067699] vcp\303\277ff8880d69b4000 before: ->vc_rowsH0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1\n" - "> [ 227.067774] vcp\303\277ff8880d69b4000 after: ->vc_rowsH0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1 ret=0\n" - "> [ 227.067831] vcp\303\277ff8880cac4b000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.067891] vcp\303\277ff8880cac4b000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.067947] vcp\303\277ff8880c6180000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068007] vcp\303\277ff8880c6180000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.068063] vcp\303\277ff8880d6b84000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068123] vcp\303\277ff8880d6b84000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.068179] vcp\303\277ff8880ca8c0000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068255] vcp\303\277ff8880ca8c0000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.068455] vcp\303\277ff8880cbd5d000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068515] vcp\303\277ff8880cbd5d000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.084709] =================================\n" + "> [ 227.065369] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1\n" + "> [ 227.066254] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1\n" + "> [ 227.067642] vc=ffff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0\n" + "> [ 227.067699] vcp=ffff8880d69b4000 before: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1\n" + "> [ 227.067774] vcp=ffff8880d69b4000 after: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1 ret=0\n" + "> [ 227.067831] vcp=ffff8880cac4b000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.067891] vcp=ffff8880cac4b000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.067947] vcp=ffff8880c6180000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068007] vcp=ffff8880c6180000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.068063] vcp=ffff8880d6b84000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068123] vcp=ffff8880d6b84000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.068179] vcp=ffff8880ca8c0000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068255] vcp=ffff8880ca8c0000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.068455] vcp=ffff8880cbd5d000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068515] vcp=ffff8880cbd5d000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.084709] ==================================================================\n" "> [ 227.084729] BUG: KASAN: slab-out-of-bounds in soft_cursor+0x34e/0x4a0\n" "> [ 227.084748] Read of size 9 at addr ffff8880c98d5930 by task a.out/1662\n" "\n" @@ -63,11 +63,16 @@ "\n" "Yes, I guess it is this one:\n" "\tKASAN: slab-out-of-bounds Read in soft_cursor\n" - "\thttps://syzkaller.appspot.com/bug?idk8355d27b2b94fb5cedf4655e3a59162d9e48e3\n" + "\thttps://syzkaller.appspot.com/bug?id=6b8355d27b2b94fb5cedf4655e3a59162d9e48e3\n" "\n" "There is a `0x560aul` ioctl() in the reproducer, which is `VT_RESIZEX`.\n" "\n" "Thank you,\n" - Peilin Ye + "Peilin Ye\n" + "\n" + "_______________________________________________\n" + "dri-devel mailing list\n" + "dri-devel@lists.freedesktop.org\n" + https://lists.freedesktop.org/mailman/listinfo/dri-devel -9ffe9930dd12117106aa9e8e2140069d9ea62441b9fe4d999df85da4635c330c +1f4e18905d1aaf2093810c96b52f21fee6a59cef5ca00c957efbdfdb9f3b75b3
diff --git a/a/1.txt b/N2/1.txt index e56a7c9..665b4c9 100644 --- a/a/1.txt +++ b/N2/1.txt @@ -18,22 +18,22 @@ On Sun, Sep 27, 2020 at 05:28:12PM +0900, Tetsuo Handa wrote: > > static char fontdata[8192] = { 2 }; > -> [ 227.065369] bit_putcs: width=1 cellsize=1 count maxcnt92 scan_align=0 buf_align=0 image.height=1 -> [ 227.066254] bit_putcs: width=1 cellsize=1 count maxcnt92 scan_align=0 buf_align=0 image.height=1 -> [ 227.067642] vcÿff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0 -> [ 227.067699] vcpÿff8880d69b4000 before: ->vc_rowsH0 ->vc_cols ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1 -> [ 227.067774] vcpÿff8880d69b4000 after: ->vc_rowsH0 ->vc_cols ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1 ret=0 -> [ 227.067831] vcpÿff8880cac4b000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.067891] vcpÿff8880cac4b000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.067947] vcpÿff8880c6180000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068007] vcpÿff8880c6180000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.068063] vcpÿff8880d6b84000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068123] vcpÿff8880d6b84000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.068179] vcpÿff8880ca8c0000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068255] vcpÿff8880ca8c0000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.068455] vcpÿff8880cbd5d000 before: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 -> [ 227.068515] vcpÿff8880cbd5d000 after: ->vc_rows0 ->vc_cols ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\x16 ret=0 -> [ 227.084709] ================================= +> [ 227.065369] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1 +> [ 227.066254] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1 +> [ 227.067642] vc=ffff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0 +> [ 227.067699] vcp=ffff8880d69b4000 before: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1 +> [ 227.067774] vcp=ffff8880d69b4000 after: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1 ret=0 +> [ 227.067831] vcp=ffff8880cac4b000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.067891] vcp=ffff8880cac4b000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.067947] vcp=ffff8880c6180000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068007] vcp=ffff8880c6180000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.068063] vcp=ffff8880d6b84000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068123] vcp=ffff8880d6b84000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.068179] vcp=ffff8880ca8c0000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068255] vcp=ffff8880ca8c0000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.068455] vcp=ffff8880cbd5d000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 +> [ 227.068515] vcp=ffff8880cbd5d000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0 +> [ 227.084709] ================================================================== > [ 227.084729] BUG: KASAN: slab-out-of-bounds in soft_cursor+0x34e/0x4a0 > [ 227.084748] Read of size 9 at addr ffff8880c98d5930 by task a.out/1662 @@ -41,7 +41,7 @@ Very interesting, I remember seeing this on the syzbot dashboard... Yes, I guess it is this one: KASAN: slab-out-of-bounds Read in soft_cursor - https://syzkaller.appspot.com/bug?idk8355d27b2b94fb5cedf4655e3a59162d9e48e3 + https://syzkaller.appspot.com/bug?id=6b8355d27b2b94fb5cedf4655e3a59162d9e48e3 There is a `0x560aul` ioctl() in the reproducer, which is `VT_RESIZEX`. diff --git a/a/content_digest b/N2/content_digest index eda22f9..18dd165 100644 --- a/a/content_digest +++ b/N2/content_digest @@ -4,20 +4,20 @@ "ref\0494395bc-a7dd-fdb1-8196-a236a266ef54@i-love.sakura.ne.jp\0" "From\0Peilin Ye <yepeilin.cs@gmail.com>\0" "Subject\0Re: KASAN: use-after-free Read in bit_putcs\0" - "Date\0Sun, 27 Sep 2020 09:27:01 +0000\0" + "Date\0Sun, 27 Sep 2020 05:27:01 -0400\0" "To\0Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>\0" "Cc\0syzbot <syzbot+b308f5fd049fbbc6e74f@syzkaller.appspotmail.com>" - linux-fbdev@vger.kernel.org b.zolnierkie@samsung.com daniel.vetter@ffwll.ch deller@gmx.de - syzkaller-bugs@googlegroups.com - linux-kernel@vger.kernel.org - dri-devel@lists.freedesktop.org - Linus Torvalds <torvalds@linux-foundation.org> gregkh@linuxfoundation.org jirislaby@kernel.org - " Peilin Ye <yepeilin.cs@gmail.com>\0" + syzkaller-bugs@googlegroups.com + Linus Torvalds <torvalds@linux-foundation.org> + Peilin Ye <yepeilin.cs@gmail.com> + dri-devel@lists.freedesktop.org + linux-fbdev@vger.kernel.org + " linux-kernel@vger.kernel.org\0" "\00:1\0" "b\0" "On Sun, Sep 27, 2020 at 05:28:12PM +0900, Tetsuo Handa wrote:\n" @@ -40,22 +40,22 @@ "> \n" "> static char fontdata[8192] = { 2 };\n" "> \n" - "> [ 227.065369] bit_putcs: width=1 cellsize=1 count\302\200 maxcnt\302\20192 scan_align=0 buf_align=0 image.height=1\n" - "> [ 227.066254] bit_putcs: width=1 cellsize=1 count\302\200 maxcnt\302\20192 scan_align=0 buf_align=0 image.height=1\n" - "> [ 227.067642] vc\303\277ff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0\n" - "> [ 227.067699] vcp\303\277ff8880d69b4000 before: ->vc_rowsH0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1\n" - "> [ 227.067774] vcp\303\277ff8880d69b4000 after: ->vc_rowsH0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines@0 ->vc_font.height=9 save_font_height=1 ret=0\n" - "> [ 227.067831] vcp\303\277ff8880cac4b000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.067891] vcp\303\277ff8880cac4b000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.067947] vcp\303\277ff8880c6180000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068007] vcp\303\277ff8880c6180000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.068063] vcp\303\277ff8880d6b84000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068123] vcp\303\277ff8880d6b84000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.068179] vcp\303\277ff8880ca8c0000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068255] vcp\303\277ff8880ca8c0000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.068455] vcp\303\277ff8880cbd5d000 before: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026\n" - "> [ 227.068515] vcp\303\277ff8880cbd5d000 after: ->vc_rows0 ->vc_cols\302\200 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height\026 ret=0\n" - "> [ 227.084709] =================================\n" + "> [ 227.065369] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1\n" + "> [ 227.066254] bit_putcs: width=1 cellsize=1 count=80 maxcnt=8192 scan_align=0 buf_align=0 image.height=1\n" + "> [ 227.067642] vc=ffff8880d69b4000 v.v_rows=0 v.v_cols=0 v.v_vlin=1 v.v_clin=9 v.v_vcol=0 v.v_ccol=0 ret=0\n" + "> [ 227.067699] vcp=ffff8880d69b4000 before: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1\n" + "> [ 227.067774] vcp=ffff8880d69b4000 after: ->vc_rows=480 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=400 ->vc_font.height=9 save_font_height=1 ret=0\n" + "> [ 227.067831] vcp=ffff8880cac4b000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.067891] vcp=ffff8880cac4b000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.067947] vcp=ffff8880c6180000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068007] vcp=ffff8880c6180000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.068063] vcp=ffff8880d6b84000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068123] vcp=ffff8880d6b84000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.068179] vcp=ffff8880ca8c0000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068255] vcp=ffff8880ca8c0000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.068455] vcp=ffff8880cbd5d000 before: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16\n" + "> [ 227.068515] vcp=ffff8880cbd5d000 after: ->vc_rows=30 ->vc_cols=80 ->vc_scan_lines=1 save_scan_lines=0 ->vc_font.height=9 save_font_height=16 ret=0\n" + "> [ 227.084709] ==================================================================\n" "> [ 227.084729] BUG: KASAN: slab-out-of-bounds in soft_cursor+0x34e/0x4a0\n" "> [ 227.084748] Read of size 9 at addr ffff8880c98d5930 by task a.out/1662\n" "\n" @@ -63,11 +63,11 @@ "\n" "Yes, I guess it is this one:\n" "\tKASAN: slab-out-of-bounds Read in soft_cursor\n" - "\thttps://syzkaller.appspot.com/bug?idk8355d27b2b94fb5cedf4655e3a59162d9e48e3\n" + "\thttps://syzkaller.appspot.com/bug?id=6b8355d27b2b94fb5cedf4655e3a59162d9e48e3\n" "\n" "There is a `0x560aul` ioctl() in the reproducer, which is `VT_RESIZEX`.\n" "\n" "Thank you,\n" Peilin Ye -9ffe9930dd12117106aa9e8e2140069d9ea62441b9fe4d999df85da4635c330c +89af508e8cf4ce419b1dc38652fc3d88cecc978ac568949dcab4b8466f323cd5
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.