diff for duplicates of <56e97869.6afe420a.80cd8.ffffde3d@mx.google.com> diff --git a/a/1.txt b/N1/1.txt index 74cf6ff..2639e5a 100644 --- a/a/1.txt +++ b/N1/1.txt @@ -3,15 +3,16 @@ I've got the following use-after-free report while running syzkaller fuzzer. Unfortunately no reproducer. It was found in the Linux kernel version(4.4, on commit 9638685e32af961943b679fcb72d4ddd458eb18f). -================================= +================================================================== BUG: KASAN: use-after-free in ppp_unregister_channel+0x372/0x3a0 at addr ffff880064e217e0 Read of size 8 by task syz-executor/11581 -======================================BUG net_namespace (Not tainted): kasan: bad access detected +============================================================================= +BUG net_namespace (Not tainted): kasan: bad access detected ----------------------------------------------------------------------------- Disabling lock debugging due to kernel taint -INFO: Allocated in copy_net_ns+0x6b/0x1a0 age’569 cpu=3 pidi06 +INFO: Allocated in copy_net_ns+0x6b/0x1a0 age=92569 cpu=3 pid=6906 [< none >] ___slab_alloc+0x4c7/0x500 kernel/mm/slub.c:2440 [< none >] __slab_alloc+0x4c/0x90 kernel/mm/slub.c:2469 [< inline >] slab_alloc_node kernel/mm/slub.c:2532 @@ -29,7 +30,7 @@ INFO: Allocated in copy_net_ns+0x6b/0x1a0 age’569 cpu=3 pidi06 [< none >] SyS_clone+0x37/0x50 kernel/kernel/fork.c:1826 [< none >] entry_SYSCALL_64_fastpath+0x16/0x7a kernel/arch/x86/entry/entry_64.S:185 -INFO: Freed in net_drop_ns+0x67/0x80 ageW5 cpu=2 pid&31 +INFO: Freed in net_drop_ns+0x67/0x80 age=575 cpu=2 pid=2631 [< none >] __slab_free+0x1fc/0x320 kernel/mm/slub.c:2650 [< inline >] slab_free kernel/mm/slub.c:2805 [< none >] kmem_cache_free+0x2a0/0x330 kernel/mm/slub.c:2814 @@ -105,7 +106,7 @@ Memory state around the buggy address: ^ ffff880064e21800: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff880064e21880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb -================================= +================================================================== Best Regards, diff --git a/a/content_digest b/N1/content_digest index dc5add6..2f06a5b 100644 --- a/a/content_digest +++ b/N1/content_digest @@ -1,6 +1,6 @@ "From\0Baozeng Ding <sploving1@gmail.com>\0" "Subject\0net/ppp: use-after-free in ppp_unregister_channel\0" - "Date\0Wed, 16 Mar 2016 15:14:42 +0000\0" + "Date\0Wed, 16 Mar 2016 23:14:42 +0800\0" "To\0linux-kernel@vger.kernel.org\0" "Cc\0paulus@samba.org" linux-ppp@vger.kernel.org @@ -12,15 +12,16 @@ "fuzzer. Unfortunately no reproducer. It was found in the Linux kernel\n" "version(4.4, on commit 9638685e32af961943b679fcb72d4ddd458eb18f).\n" "\n" - "=================================\n" + "==================================================================\n" "BUG: KASAN: use-after-free in ppp_unregister_channel+0x372/0x3a0 at\n" "addr ffff880064e217e0\n" "Read of size 8 by task syz-executor/11581\n" - "======================================BUG net_namespace (Not tainted): kasan: bad access detected\n" + "=============================================================================\n" + "BUG net_namespace (Not tainted): kasan: bad access detected\n" "-----------------------------------------------------------------------------\n" "\n" "Disabling lock debugging due to kernel taint\n" - "INFO: Allocated in copy_net_ns+0x6b/0x1a0 age\342\200\231569 cpu=3 pidi06\n" + "INFO: Allocated in copy_net_ns+0x6b/0x1a0 age=92569 cpu=3 pid=6906\n" "[< none >] ___slab_alloc+0x4c7/0x500 kernel/mm/slub.c:2440\n" "[< none >] __slab_alloc+0x4c/0x90 kernel/mm/slub.c:2469\n" "[< inline >] slab_alloc_node kernel/mm/slub.c:2532\n" @@ -38,7 +39,7 @@ "[< none >] SyS_clone+0x37/0x50 kernel/kernel/fork.c:1826\n" "[< none >] entry_SYSCALL_64_fastpath+0x16/0x7a kernel/arch/x86/entry/entry_64.S:185\n" "\n" - "INFO: Freed in net_drop_ns+0x67/0x80 ageW5 cpu=2 pid&31\n" + "INFO: Freed in net_drop_ns+0x67/0x80 age=575 cpu=2 pid=2631\n" "[< none >] __slab_free+0x1fc/0x320 kernel/mm/slub.c:2650\n" "[< inline >] slab_free kernel/mm/slub.c:2805\n" "[< none >] kmem_cache_free+0x2a0/0x330 kernel/mm/slub.c:2814\n" @@ -114,10 +115,10 @@ " ^\n" " ffff880064e21800: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n" " ffff880064e21880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n" - "=================================\n" + "==================================================================\n" "\n" "Best Regards,\n" "\n" Baozeng Ding -3cf6b2fa8900c9a76b5dcb45f69e7ec9c6e0afef4e90cacbc568ab1f9f4994ac +7e0b4c881c8f095625255e0ab2c0af948a5f145180b87d2cf553ee0c49f6a155
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.