Received: by 2002:a25:1506:0:0:0:0:0 with SMTP id 6csp77212ybv; Tue, 18 Feb 2020 18:08:56 -0800 (PST) X-Google-Smtp-Source: APXvYqyMg52iutPeKJly0dPwL/jldmn3DXUZdFdxjXjIAy0kF20g4BgA8p3viCv1aD9a+3Zn4rkk X-Received: by 2002:aca:3805:: with SMTP id f5mr3258686oia.6.1582078136478; Tue, 18 Feb 2020 18:08:56 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1582078136; cv=none; d=google.com; s=arc-20160816; b=HwH86V0JnOD0iLrkvWkOVvaobqc0CFD/f6Ogwqsyp2kPmyOsfINmJV2hW9BxL8Z1Q+ 2XtfldKpKN4z/DUBwZGSQrhPwryAap6cgglDl7xtTyL+QiOrtbr13O0+OpZoiw1BAGC5 plI0AYjaRVDxVsDskjfxPzAVYPAnYoe3zpZuuJz6y+UKy6e8avTLt8O5hfTJtcJq42H5 ozDAeIttakBm+zWtWrzV3FVgxqLcJMUYk/zs1EtCZKhD8n9B3eGT8ZSwRMLyxWvvtjJ7 P6MpOKDI0m13TCN6AZyB2ASl6kAwe8QGypA8FH4xMLQm4+lWbG7Eg6tJhPw786Rpf8VF Vgxw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:to:from:subject :message-id:in-reply-to:date:mime-version; bh=RK3D/RxvxzBgLYScJUCHQi9tw7MWUa47bUiKjfiLToc=; b=OgesWIz1QpZxHQtvxlxuX6mfDHp5X8+2P6e99AaXXxiQ/44+p3AHqm4BNhveKS98KI 67PKLVjEoZwBi1AGXfhm5M913iZ+Bez0tTnz9kbuBpOeSs/Zt2alEKjHEnBvJr48/Lrh qwG9wDsVFkturN6c40HhLh+C34DZqowQM84T1mwyCfl5bw3TAI9TzCKHgpR6oyBXUmr8 3QU6gLi8WGY+Jghp4B/RhICpbUYZRKRURnyN6BJsNrpdU9/BGOfwm4hGCi+XE/eNX2eD 7OGRVv9g8XY1MZeLrRhYrx6Nsjep2yUdoD9lS/+VdXkDqmedpA50cZm123OirSPrHXeT Mn5A== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id w5si382409otm.45.2020.02.18.18.08.44; Tue, 18 Feb 2020 18:08:56 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727960AbgBSCID convert rfc822-to-8bit (ORCPT + 99 others); Tue, 18 Feb 2020 21:08:03 -0500 Received: from mail-il1-f199.google.com ([209.85.166.199]:43365 "EHLO mail-il1-f199.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726761AbgBSCIC (ORCPT ); Tue, 18 Feb 2020 21:08:02 -0500 Received: by mail-il1-f199.google.com with SMTP id o13so18709857ilf.10 for ; Tue, 18 Feb 2020 18:08:01 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:in-reply-to:message-id:subject :from:to:content-transfer-encoding; bh=4diWwWLXm7lY/GHl3gvscC/1M0a1R7YH2cSj9Fw5eHQ=; b=DnyEUbq71/Z/rVqY9k3Gu+5UKcLzewac1o1wU8GmrDtXSvc5Q/HpJtqLx7BTZ7APci 1riQ/BbZ0SSR+JcANpXWdeBKIEQOHqfm3lMUQYzYz6Wt5Pu9iV9X8KMmC/LOsvCVa65Q 8A3RXr3PdvNLX6tnCNRDMIV2HUCxn1oeM0zXks1jh3InVPvgI1//Q3WWa4HH6l53tvVM ROOrq0poPZl5+5fdY6nDmRAbLOcdNYrR6cCgGw94uxUcpNCeMJuaRSHfplsC/e+riX+/ 2uBE12ZFth8MKOw3j22TOw4ZHZ29Ywr/P7xfSyTb3V9SjVu7fKv99XF+d4+Fbxn8lzEu 9XGA== X-Gm-Message-State: APjAAAWd8+0FqKd0lKOh22iqho5yZy6Ky+PsApnETIYZ4dVJub8peNz/ iu3hJ49X4sEZJKoH36fD4fOY5wbYr9POKZV7gMM/dfPAAUk6 MIME-Version: 1.0 X-Received: by 2002:a92:15c2:: with SMTP id 63mr22276770ilv.111.1582078081462; Tue, 18 Feb 2020 18:08:01 -0800 (PST) Date: Tue, 18 Feb 2020 18:08:01 -0800 In-Reply-To: <000000000000bb0378059c865fdf@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <0000000000000d774c059ee442e6@google.com> Subject: Re: KASAN: use-after-free Read in bitmap_ip_destroy From: syzbot To: a@unstable.cc, b.a.t.m.a.n@lists.open-mesh.org, coreteam@netfilter.org, davem@davemloft.net, florent.fourcot@wifirst.fr, fw@strlen.de, jeremy@azazel.net, johannes.berg@intel.com, kadlec@blackhole.kfki.hu, kadlec@netfilter.org, linux-kernel@vger.kernel.org, lipeng321@huawei.com, mareklindner@neomailbox.ch, netdev@vger.kernel.org, netfilter-devel@vger.kernel.org, pablo@netfilter.org, sw@simonwunderlich.de, syzkaller-bugs@googlegroups.com, tanhuazhong@huawei.com Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8BIT Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org syzbot suspects this bug was fixed by commit: commit 32c72165dbd0e246e69d16a3ad348a4851afd415 Author: Kadlecsik József Date: Sun Jan 19 21:06:49 2020 +0000 netfilter: ipset: use bitmap infrastructure completely bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=17fc79b5e00000 start commit: 8f8972a3 Merge tag 'mtd/fixes-for-5.5-rc7' of git://git.ke.. git tree: upstream kernel config: https://syzkaller.appspot.com/x/.config?x=cfbb8fa33f49f9f3 dashboard link: https://syzkaller.appspot.com/bug?extid=8b5f151de2f35100bbc5 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12e22559e00000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16056faee00000 If the result looks correct, please mark the bug fixed by replying with: #syz fix: netfilter: ipset: use bitmap infrastructure completely For information about bisection process see: https://goo.gl/tpsmEJ#bisection