Received: by 2002:a05:7412:bb8d:b0:d7:7d3a:4fe2 with SMTP id js13csp246663rdb; Mon, 14 Aug 2023 15:57:05 -0700 (PDT) X-Google-Smtp-Source: AGHT+IGRazvFT6mNpn7uQj5fHyICXkEUFdT5pqKRPHYz9zCBeu9j7lyiQXwTMzupeCA5X+yXBP4b X-Received: by 2002:a05:6a00:1a90:b0:682:5a68:9846 with SMTP id e16-20020a056a001a9000b006825a689846mr13993509pfv.16.1692053824297; Mon, 14 Aug 2023 15:57:04 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1692053824; cv=none; d=google.com; s=arc-20160816; b=e51c5okljkVTm1p2jCE/l2BsIRWTnbM1b7wSDVqvUmyPjiuUFIJnH3NUKfzIJMhtvv Rz+pwAt5IksS6908M+GhClLT21EB5VOglVaDJ+uUe/1IcgV+N3sQ5Sh4sEh2c+dIKARW fTMupRMWWjDlISPLEHDTZYtNcyYTAgWZDGfhDsuBVqmzLCHq8BOeKG5CpZBSOfBdFlIT k6uhzkLIWgGoM1NFBOUkVvmY8Gdmr8sf2yVu2oWtIOL28ff2UXCvxbmhJ3FPZmw/61zy JVgLhGQ434X84IBsiA7fyYUPs5PSstgs6GB6Jqb3ohCGlMzHlWP7m1ESxnaJA+NJOrEH DrGA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:to:from:subject:message-id:in-reply-to:date :mime-version; bh=ESKM9ZhqAvF1tyO2W2reMjI8w6E0LleNDUBpM/RmnhE=; fh=hiliH/R8UiLx3Pg4rY7EIY3FfuwgooRGWU+fu2l5nvc=; b=iZI3lZUGnZHoekg2p6u91ysFYskaJgJgiJHAWEn/eegIW6thpwlh/kv8uAbuHDbRqR 2e4Ir2xqnrwmJVA195XSxMG+Wd1OLfVMFM8hJxjf8p60ZnFHwqJ05Onv+lKIQVbERq7e ZkX9GO5p9V233sWM+XDjxAC7MGlKQnlG2psyhBaseFf51iw1EZonAH2FT5ceJeCkwn9b tpO0MA/FDwLC87+M+BTUgm6QOn0d31ZHwOA1bHuHRCXcYj7V+UY+nRY+hNJzcz6jeq/f yJfzHVs69I/koFu2V6PmVLOkoxhxPI1Un6xK9xL7P9lojG3FmVFxyuR9KIfhvUo5Tw6y dOSA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id m68-20020a633f47000000b00564b349a772si228872pga.557.2023.08.14.15.56.50; Mon, 14 Aug 2023 15:57:04 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231436AbjHNUHk (ORCPT + 99 others); Mon, 14 Aug 2023 16:07:40 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43218 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232020AbjHNUHf (ORCPT ); Mon, 14 Aug 2023 16:07:35 -0400 Received: from mail-pg1-f198.google.com (mail-pg1-f198.google.com [209.85.215.198]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id E351C10C8 for ; Mon, 14 Aug 2023 13:07:34 -0700 (PDT) Received: by mail-pg1-f198.google.com with SMTP id 41be03b00d2f7-564b8c529bfso5050110a12.0 for ; Mon, 14 Aug 2023 13:07:34 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1692043654; x=1692648454; h=to:from:subject:message-id:in-reply-to:date:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ESKM9ZhqAvF1tyO2W2reMjI8w6E0LleNDUBpM/RmnhE=; b=KC6wSGkMER4IYbk7V71TQhtnx0teclrF0WmdESS0fi/1G3e3VHarVMdemwZ8HXcZHB 4m3dVqCULhTwGalc3kZFF6tkRVO6CEyWszy0+Tk+boZszr0fvIgh8zzVac3MRy1oRUA7 HSfGGB2ZWCDWxBCF5EgT6aG/mXdZ+nBixrBi7xu5fxFnNgBV5/90p5EJ2QZyVnXA11QW vRDY3MV4xPxBTxFUwWm/nqm3PtD8B/4rQ0GlzHRipfdi1LrQwVnQ/Z41inWQGX52918d UkBYPcNdOgex4JGeErdAVbf/x94Zur/DtDYaRvQf0qk/wUvsf1a8/Mg5NEnu8eOsKjQ+ JSnQ== X-Gm-Message-State: AOJu0YwWwc9bYcFh3KbjDtz41WN8bDa7Yy23RGeCVOqdh+IL6tcYC6LT t3K7mUN+vPQo32wr1VAoqFiR0Bip6U9q2/XzeftJIHTRVp/F MIME-Version: 1.0 X-Received: by 2002:a17:903:2301:b0:1b8:95fc:d0f with SMTP id d1-20020a170903230100b001b895fc0d0fmr4379586plh.7.1692043654450; Mon, 14 Aug 2023 13:07:34 -0700 (PDT) Date: Mon, 14 Aug 2023 13:07:34 -0700 In-Reply-To: <00000000000024d7f70602b705e9@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <000000000000f7d5180602e79cec@google.com> Subject: Re: [syzbot] [udf?] KASAN: use-after-free Read in udf_sync_fs From: syzbot To: hdanton@sina.com, jack@suse.com, jack@suse.cz, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, steve.magnani@digidescorp.com, steve@digidescorp.com, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=0.9 required=5.0 tests=BAYES_00,FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,SORTED_RECIPS,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org syzbot has bisected this issue to: commit e8b4274735e416621cfb28c2802b4ad52da35d0f Author: Steve Magnani Date: Fri Feb 8 17:34:55 2019 +0000 udf: finalize integrity descriptor before writeback bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14e3d76fa80000 start commit: f8de32cc060b Merge tag 'tpmdd-v6.5-rc7' of git://git.kerne.. git tree: upstream final oops: https://syzkaller.appspot.com/x/report.txt?x=16e3d76fa80000 console output: https://syzkaller.appspot.com/x/log.txt?x=12e3d76fa80000 kernel config: https://syzkaller.appspot.com/x/.config?x=171b698bc2e613cf dashboard link: https://syzkaller.appspot.com/bug?extid=82df44ede2faca24c729 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10df55d7a80000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17e4d78ba80000 Reported-by: syzbot+82df44ede2faca24c729@syzkaller.appspotmail.com Fixes: e8b4274735e4 ("udf: finalize integrity descriptor before writeback") For information about bisection process see: https://goo.gl/tpsmEJ#bisection