From: syzbot <syzbot+df9e891bf8ea586f846b@syzkaller.appspotmail.com>
To: asml.silence@gmail.com, axboe@kernel.dk, brauner@kernel.org,
gregkh@linuxfoundation.org, io-uring@vger.kernel.org,
jack@suse.cz, kartikey406@gmail.com, kees@kernel.org,
linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org,
mjguzik@gmail.com, nogikh@google.com, stern@rowland.harvard.edu,
syzbot@kernel.org, syzbot@lists.linux.dev,
syzkaller-bugs@googlegroups.com,
syzkaller-upstream-moderation@googlegroups.com,
torvalds@ppc970.osdl.org, viro@zeniv.linux.org.uk
Subject: Re: [syzbot] [usb?] KASAN: slab-use-after-free Read in ep_open
Date: Mon, 17 Aug 2026 06:42:03 -0700 [thread overview]
Message-ID: <6a830fab.dbb3a75c.20434b.005d.GAE@google.com> (raw)
In-Reply-To: <6a6bfa43.1b55b669.19788.0016.GAE@google.com>
syzbot has bisected this issue to:
commit aa00f67adc2c0d6439f81b5a81ff181377c47a7e
Author: Jens Axboe <axboe@kernel.dk>
Date: Tue Oct 22 19:47:00 2024 +0000
io_uring: add support for fixed wait regions
bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=10e60679580000
start commit: 9a143525f62b Merge tag 'ata-7.2-rc7' of git://git.kernel.o..
git tree: upstream
final oops: https://syzkaller.appspot.com/x/report.txt?x=12e60679580000
console output: https://syzkaller.appspot.com/x/log.txt?x=14e60679580000
kernel config: https://syzkaller.appspot.com/x/.config?x=c44651ea7dd2f307
dashboard link: https://syzkaller.appspot.com/bug?extid=df9e891bf8ea586f846b
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=120defb9580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16323fb9580000
Reported-by: syzbot+df9e891bf8ea586f846b@syzkaller.appspotmail.com
Fixes: aa00f67adc2c ("io_uring: add support for fixed wait regions")
For information about bisection process see: https://goo.gl/tpsmEJ#bisection
next prev parent reply other threads:[~2026-08-17 13:42 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 1:28 [syzbot] [usb?] KASAN: slab-use-after-free Read in ep_open syzbot
2026-07-31 4:26 ` Forwarded: [PATCH] usb: gadgetfs: fix use-after-free in ep_open() syzbot
2026-07-31 4:44 ` syzbot
2026-07-31 8:09 ` syzbot
2026-07-31 11:40 ` Forwarded: [PATCH v2] " syzbot
2026-08-17 13:42 ` syzbot [this message]
2026-08-17 15:04 ` [syzbot] [usb?] KASAN: slab-use-after-free Read in ep_open Jens Axboe
2026-08-17 15:45 ` Alan Stern
2026-08-17 16:38 ` syzbot
2026-08-17 18:14 ` Alan Stern
2026-08-18 7:42 ` Greg KH
2026-08-18 15:37 ` Alan Stern
[not found] <20260731042637.9137-1-kartikey406@gmail.com>
2026-07-31 5:42 ` syzbot
[not found] <20260731044451.10817-1-kartikey406@gmail.com>
2026-07-31 6:59 ` syzbot
[not found] <20260731080941.13394-1-kartikey406@gmail.com>
2026-07-31 9:08 ` syzbot
[not found] <20260731114022.18295-1-kartikey406@gmail.com>
2026-07-31 16:21 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a830fab.dbb3a75c.20434b.005d.GAE@google.com \
--to=syzbot+df9e891bf8ea586f846b@syzkaller.appspotmail.com \
--cc=asml.silence@gmail.com \
--cc=axboe@kernel.dk \
--cc=brauner@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=io-uring@vger.kernel.org \
--cc=jack@suse.cz \
--cc=kartikey406@gmail.com \
--cc=kees@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=mjguzik@gmail.com \
--cc=nogikh@google.com \
--cc=stern@rowland.harvard.edu \
--cc=syzbot@kernel.org \
--cc=syzbot@lists.linux.dev \
--cc=syzkaller-bugs@googlegroups.com \
--cc=syzkaller-upstream-moderation@googlegroups.com \
--cc=torvalds@ppc970.osdl.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.