Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751997AbdIUQuf (ORCPT ); Thu, 21 Sep 2017 12:50:35 -0400 Received: from iolanthe.rowland.org ([192.131.102.54]:40618 "HELO iolanthe.rowland.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with SMTP id S1751737AbdIUQuc (ORCPT ); Thu, 21 Sep 2017 12:50:32 -0400 Date: Thu, 21 Sep 2017 12:50:31 -0400 (EDT) From: Alan Stern X-X-Sender: stern@iolanthe.rowland.org To: Andrey Konovalov cc: Oliver Neukum , Greg Kroah-Hartman , USB list , , , LKML , Dmitry Vyukov , Kostya Serebryany , syzkaller Subject: Re: usb/storage/uas: slab-out-of-bounds in uas_probe In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 524 Lines: 16 On Thu, 21 Sep 2017, Andrey Konovalov wrote: > Hi! > > I've got the following report while fuzzing the kernel with syzkaller. > > On commit ebb2c2437d8008d46796902ff390653822af6cc4 (Sep 18). > > The issue occurs when we iterate over interface altsettings, but I > don't see the driver doing anything wrong. I might be missing > something, or this might be an issue in USB core altsettings parsing. My guess is the latter, although I can't see what is going wrong. Can you provide the code that does this? Alan Stern