Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753282AbdIURQ0 (ORCPT ); Thu, 21 Sep 2017 13:16:26 -0400 Received: from mail-io0-f170.google.com ([209.85.223.170]:51288 "EHLO mail-io0-f170.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751922AbdIURQY (ORCPT ); Thu, 21 Sep 2017 13:16:24 -0400 X-Google-Smtp-Source: AOwi7QCvFZbHvKcUyFGH8WoVkROtpOjkWphrxi9MdyaZAxENHlRy3u8MFqI01KBg0CTFuxz5NOfoV3ugOuVUCK9viIs= MIME-Version: 1.0 In-Reply-To: References: From: Andrey Konovalov Date: Thu, 21 Sep 2017 19:16:22 +0200 Message-ID: Subject: Re: usb/storage/uas: slab-out-of-bounds in uas_probe To: Alan Stern Cc: Oliver Neukum , Greg Kroah-Hartman , USB list , linux-scsi@vger.kernel.org, usb-storage@lists.one-eyed-alien.net, LKML , Dmitry Vyukov , Kostya Serebryany , syzkaller Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 687 Lines: 21 On Thu, Sep 21, 2017 at 6:50 PM, Alan Stern wrote: > On Thu, 21 Sep 2017, Andrey Konovalov wrote: > >> Hi! >> >> I've got the following report while fuzzing the kernel with syzkaller. >> >> On commit ebb2c2437d8008d46796902ff390653822af6cc4 (Sep 18). >> >> The issue occurs when we iterate over interface altsettings, but I >> don't see the driver doing anything wrong. I might be missing >> something, or this might be an issue in USB core altsettings parsing. > > My guess is the latter, although I can't see what is going wrong. Can > you provide the code that does this? I did, see the previous email (replying in case you missed it). > > Alan Stern >