Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752493AbdCCPYP (ORCPT ); Fri, 3 Mar 2017 10:24:15 -0500 Received: from mail-io0-f169.google.com ([209.85.223.169]:35584 "EHLO mail-io0-f169.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752337AbdCCPXM (ORCPT ); Fri, 3 Mar 2017 10:23:12 -0500 MIME-Version: 1.0 In-Reply-To: References: <1488551576.9415.328.camel@edumazet-glaptop3.roam.corp.google.com> <1488552503.9415.330.camel@edumazet-glaptop3.roam.corp.google.com> From: Eric Dumazet Date: Fri, 3 Mar 2017 07:22:33 -0800 Message-ID: Subject: Re: net/dccp: use-after-free in dccp_feat_activate_values To: Dmitry Vyukov Cc: Eric Dumazet , Cong Wang , Andrey Konovalov , Gerrit Renker , "David S. Miller" , dccp@vger.kernel.org, netdev , LKML Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 359 Lines: 9 On Fri, Mar 3, 2017 at 7:12 AM, Dmitry Vyukov wrote: > The first bot that picked this up started spewing: > > BUG: spinlock recursion on CPU#1, syz-executor2/9452 Yes. The bug is not about locking the listener, but protecting fields of struct dccp_request_sock I will provide a patch, once I reach the office and after the breakfast ;)