From: Jens Axboe <axboe@kernel.dk>
To: Homin Rhee <hominlab@gmail.com>, io-uring@vger.kernel.org
Subject: Re: [Report] Use-After-Free in io_wq_worker_running
Date: Sun, 15 Jan 2023 08:36:55 -0700 [thread overview]
Message-ID: <ecfa3acb-44d7-e0a5-903e-0607ca134c3d@kernel.dk> (raw)
In-Reply-To: <CAA2QpBfokQQ=eX=Ek4f4-cft25cRkqALZZB6B=VYYmfUKk5Mzg@mail.gmail.com>
On 1/15/23 6:19 AM, Homin Rhee wrote:
> Hello,
> I'm iCAROS7 and my syzkaller hit follow KASAN bug via UAF.
>
> Target kernel commit: 0bf913e07b37
> Target arch: amd64
> Host syzkaller version: 96166539c4c242fccd41c7316b7080377dca428b
> Host CPU: Intel i7 12700K
> Host OS: Kubuntu 22.04.1 LTS (5.18.19-051819-generic)
This is a duplicate, see the mailing list. But in any case, it's
fixed as of:
commit e6db6f9398dadcbc06318a133d4c44a2d3844e61
Author: Jens Axboe <axboe@kernel.dk>
Date: Sun Jan 8 10:39:17 2023 -0700
io_uring/io-wq: only free worker if it was allocated for creation
caused by a buggy commit that went into 6.2-rc3.
--
Jens Axboe
parent reply other threads:[~2023-01-15 15:37 UTC|newest]
Thread overview: expand[flat|nested] mbox.gz Atom feed
[parent not found: <CAA2QpBfokQQ=eX=Ek4f4-cft25cRkqALZZB6B=VYYmfUKk5Mzg@mail.gmail.com>]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ecfa3acb-44d7-e0a5-903e-0607ca134c3d@kernel.dk \
--to=axboe@kernel.dk \
--cc=hominlab@gmail.com \
--cc=io-uring@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.