public inbox for cip-dev@lists.cip-project.org
 help / color / mirror / Atom feed
* [PATCH 4.19.y-cip 0/6] Backport netfilter: nf_tables: autoload modules from the abort path
@ 2022-01-10 14:09 Amy Fong
  0 siblings, 0 replies; only message in thread
From: Amy Fong @ 2022-01-10 14:09 UTC (permalink / raw)
  To: cip-dev, nobuhiro1.iwamatsu, pavel

The following series backports netfilter: nf_tables: autoload modules from abort path
which fixes the bug mentioned in the following:

   https://syzkaller.appspot.com/bug?extid=437bf61d165c87bd40fb


----

BUG: corrupted list in __nf_tables_abort
Status: fixed on 2020/03/17 22:09
Reported-by: syzbot+437bf61d165c87bd40fb@syzkaller.appspotmail.com
Fix commit: eb014de4fd41 netfilter: nf_tables: autoload modules from the abort path
First crash: 717d, last: 710d

Cause bisection: introduced by (bisect log) :
commit ec7470b834fe7b5d7eff11b6677f5d7fdf5e9a91
Author: Pablo Neira Ayuso <pablo@netfilter.org>
Date: Mon Jan 13 17:09:58 2020 +0000

  netfilter: nf_tables: store transaction list locally while requesting module

Crash: KASAN: use-after-free Read in __nf_tables_abort (log)
Repro: C syz .config

Fix bisection: fixed by (bisect log) :
commit 34682110abc50ffea7e002b0c2fd7ea9e0000ccc
Author: Max Chou <max.chou@realtek.com>
Date: Wed Nov 27 03:01:07 2019 +0000

  Bluetooth: btusb: Edit the logical value for Realtek Bluetooth reset




^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2022-01-10 14:09 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-01-10 14:09 [PATCH 4.19.y-cip 0/6] Backport netfilter: nf_tables: autoload modules from the abort path Amy Fong

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox