KASAN: use-after-free Write in end_requests

5 views
Skip to first unread message

syzbot

unread,
Aug 1, 2018, 3:29:03 PM8/1/18
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: d1e0b8e0cb7a Add linux-next specific files for 20180725
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=119ecb2c400000
kernel config: https://syzkaller.appspot.com/x/.config?x=eef3552c897e4d33
dashboard link: https://syzkaller.appspot.com/bug?extid=b6b1597223fa59453438
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
CC: [linux-...@vger.kernel.org linux-...@vger.kernel.org
mik...@szeredi.hu]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b6b159...@syzkaller.appspotmail.com

Unknown ioctl 185
IPVS: set_ctl: invalid protocol: 2 172.20.20.27:20001
IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready
Unknown ioctl 185
==================================================================
BUG: KASAN: use-after-free in end_requests+0x37b/0x460 fs/fuse/dev.c:2042
Write of size 4 at addr ffff8801d34416e4 by task syz-executor0/29613

CPU: 1 PID: 29613 Comm: syz-executor0 Not tainted 4.18.0-rc6-next-20180725+
#18
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1c9/0x2b4 lib/dump_stack.c:113
? dump_stack_print_


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Feb 22, 2019, 5:29:34 AM2/22/19
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages