Received: by 2002:a05:6a10:17d3:0:0:0:0 with SMTP id hz19csp2838896pxb; Tue, 13 Apr 2021 11:22:09 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyaBmDmvVZfHfbLWGQgz/N6oIfEdEfiyZiEG0hPiF104VECZJZZf5Por1JKA/rRyMNq3Xck X-Received: by 2002:a05:6402:438f:: with SMTP id o15mr36316498edc.123.1618338129078; Tue, 13 Apr 2021 11:22:09 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1618338129; cv=none; d=google.com; s=arc-20160816; b=FPOBFqnK5tGvMXRIATcZJZXDEAtUFbers2bcuV7jWsVL7cHbMQrBYxpHno+zn+44Pb jYpyufNknAmGm7D2meTT+gINSNgvglv5jM/tfmU/K0fB/ao3a8zf7bRx7qHXZ9kbSY34 xCh+upJdEO+OSyZfq/UgIRNre5xbTtAiUHlVJ+Z3b4W6q7r9/4jvyARG6PLDR3equRR+ R1fZkhN+KjzPmQ2Bi5f6Q/w7B80fdJQB6QnUdNNEHMn+6k1xPo2O+xiOUz7uB7QZUegh fWaFgWUZ43T42rLLRnX8x+xaU7DjAUtZOB2z5uaAUfMNq3Hou0hTGpkj2yreg23Krsdp fR9w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-transfer-encoding :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=1Jhigyf9UU6G6IXvufmrKhvm5rl8XcUyp6UG+kGmgLA=; b=TL2HwJCIXVZyhZdoRxv6zXtLbKUp1Y58fmgwAYDcemS+bCvDy3B54BNq6RGHWWf2nb qXWwXJ0TicwViV5CacYGsVqMQelZ+E6ITh3LQh5OPw4QBXLJ4R4H9g27voNnzG88f/mo fjpMRO4SgrIwi1A4hWf/168+PDpJu9SvZXpcttqUkd2oEXaRLu6ouEnNNlNIWTiXNg42 Ye2QlsL4NkOE4BiJ5CTUTIkmRnGVgihPKQNOfrWdCkxtVuLurkdqLzR65GHxRSUXcRHS jzeDSoX7vg6Qn5XjcPMHiJijXbcU/c5gStInaO0vnGLienKVg+0ES/wuvAnrDYgmEMfx brtg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@ziepe.ca header.s=google header.b="P8TZ3q/K"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id p12si10389125eji.19.2021.04.13.11.21.43; Tue, 13 Apr 2021 11:22:09 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@ziepe.ca header.s=google header.b="P8TZ3q/K"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1346069AbhDMNpV (ORCPT + 99 others); Tue, 13 Apr 2021 09:45:21 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49532 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1346062AbhDMNpU (ORCPT ); Tue, 13 Apr 2021 09:45:20 -0400 Received: from mail-qv1-xf2c.google.com (mail-qv1-xf2c.google.com [IPv6:2607:f8b0:4864:20::f2c]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id BEBF7C061756 for ; Tue, 13 Apr 2021 06:45:00 -0700 (PDT) Received: by mail-qv1-xf2c.google.com with SMTP id iu14so8052644qvb.4 for ; Tue, 13 Apr 2021 06:45:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:content-transfer-encoding:in-reply-to; bh=1Jhigyf9UU6G6IXvufmrKhvm5rl8XcUyp6UG+kGmgLA=; b=P8TZ3q/K2FYMwgX8ih6dAOpznLZqzG37b1Il+KiMHbiWEjdcrBMIXlzDa57UplaUu8 1cAAmqJDwP+fMGvD6pfollJBQ39I4eEqGf7lGvVy2tw198zw6adWvWR1L3rvb6WgYOFV uQGjCtawvPEMW58igm5A0CBka0uwolxOU4LEpFWKSs1lhPa77NKyBLPUg4WWHQTJy3LB 156DznYIBE8+OodCuxpBC0EFExw/tzwn0R97kcNdKbOkaiQkydvJ+gJ0LLFY0JZWEeRv camQQdnfN4b3Ipkdf/GOljO8I/WtnNMwVi71Eh0N1IqdmIxk8/zkFM1RV0Whu15RMwut uVGQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:content-transfer-encoding :in-reply-to; bh=1Jhigyf9UU6G6IXvufmrKhvm5rl8XcUyp6UG+kGmgLA=; b=DkEWcoEs6FThcmdAyrxJTw0Pif36LA4GhJsajHLBpogpnPosIX4JyVHQahpDMnZoNW OkcM/fe1npsBYwSSFOGSGDO/NrRtrYnbemW6DYY7bkoAEOQuQjcBwyRQE7OpJsUL9Uf2 Sfcg7j1NVNdO9EQcDDdbjIIDEoBjisJCgxP0JTicctQq4Nf0rLirlu7BYIhVeX7tDvSW bQ6HBbNfQ252o0Q0WyC2rmdPDwFgLhnD5G7XuYkxJu5qElK+tLLePjvIeUQv6DyopVbT t0OK2pAKz/eu3Mu08TwDQodQX6z1AaBXsiemuCQm9m1QY+JANaILDEFWTBh+DeC/sLvK RLOw== X-Gm-Message-State: AOAM532aZZD+XkLoSvS88vAmrUe/YApWxxnJalHZJdLs4ivlM/+1ZIzO Op9NFuCyrDUThxByfZw+BU2cNg== X-Received: by 2002:ad4:458b:: with SMTP id x11mr163890qvu.36.1618321500031; Tue, 13 Apr 2021 06:45:00 -0700 (PDT) Received: from ziepe.ca (hlfxns017vw-142-162-115-133.dhcp-dynamic.fibreop.ns.bellaliant.net. [142.162.115.133]) by smtp.gmail.com with ESMTPSA id i21sm1369148qtr.94.2021.04.13.06.44.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 13 Apr 2021 06:44:59 -0700 (PDT) Received: from jgg by mlx with local (Exim 4.94) (envelope-from ) id 1lWJLe-005HU5-T4; Tue, 13 Apr 2021 10:44:58 -0300 Date: Tue, 13 Apr 2021 10:44:58 -0300 From: Jason Gunthorpe To: Hao Sun Cc: dledford@redhat.com, linux-rdma@vger.kernel.org, leon@kernel.org, linux-kernel@vger.kernel.org Subject: Re: KASAN: use-after-free Read in cma_cancel_operation, rdma_listen Message-ID: <20210413134458.GI227011@ziepe.ca> References: <20210413133359.GG227011@ziepe.ca> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Apr 13, 2021 at 09:42:43PM +0800, Hao Sun wrote: > Jason Gunthorpe 于2021年4月13日周二 下午9:34写道: > > > > On Tue, Apr 13, 2021 at 11:36:41AM +0800, Hao Sun wrote: > > > Hi > > > > > > When using Healer(https://github.com/SunHao-0/healer/tree/dev) to fuzz > > > the Linux kernel, I found two use-after-free bugs which have been > > > reported a long time ago by Syzbot. > > > Although the corresponding patches have been merged into upstream, > > > these two bugs can still be triggered easily. > > > The original information about Syzbot report can be found here: > > > https://syzkaller.appspot.com/bug?id=8dc0bcd9dd6ec915ba10b3354740eb420884acaa > > > https://syzkaller.appspot.com/bug?id=95f89b8fb9fdc42e28ad586e657fea074e4e719b > > > > Then why hasn't syzbot seen this in a year's time? Seems strange > > > > Seems strange to me too, but the fact is that the reproduction program > in attachment can trigger these two bugs quickly. Do you have this in the C format? Jason