From mboxrd@z Thu Jan 1 00:00:00 1970 From: Rainer Weikusat Subject: Re: Use-after-free in ppoll Date: Sun, 22 Nov 2015 18:51:44 +0000 Message-ID: <87vb8tq33z.fsf@doppelsaurus.mobileactivedefense.com> References: <8737vym7f3.fsf@doppelsaurus.mobileactivedefense.com> <87ziy5q3cy.fsf@doppelsaurus.mobileactivedefense.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: Dmitry Vyukov , Jason Baron , Al Viro , David Miller , LKML , David Howells , netdev , syzkaller , Kostya Serebryany , Alexander Potapenko , Sasha Levin , Eric Dumazet To: Rainer Weikusat Return-path: In-Reply-To: <87ziy5q3cy.fsf@doppelsaurus.mobileactivedefense.com> (Rainer Weikusat's message of "Sun, 22 Nov 2015 18:46:21 +0000") Sender: linux-kernel-owner@vger.kernel.org List-Id: netdev.vger.kernel.org Rainer Weikusat writes: [...] > because of the close, this routine will be called with the peer_wait > wait_queue_head of the non-closed socket of the socket pair as > wait_address argument. This should have been "peer_wait wait_queue_head of the peer of the non-closed socket, ie, that of the closed socket"...