Received: by 2002:ab2:1149:0:b0:1f3:1f8c:d0c6 with SMTP id z9csp1752806lqz; Mon, 1 Apr 2024 16:52:43 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCV65WO2AKSxg6w52ifYywyFgQVfruNcUE5DcbLF3DzzN+wmsXZSd4d0eqi4VXM/tnhH66+jTjcD1EvdUSpO/S1AnYRwACisa+iRuVm5kg== X-Google-Smtp-Source: AGHT+IHs92qBpxzLH6dfSlf0GZ+kqp6iyeGGvU3rF1oOqAQaK2wJbmOUgwFAVEofCHJEPA2KA6ob X-Received: by 2002:a05:620a:5e52:b0:788:4e44:a9b7 with SMTP id ya18-20020a05620a5e5200b007884e44a9b7mr11818761qkn.78.1712015563630; Mon, 01 Apr 2024 16:52:43 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1712015563; cv=pass; d=google.com; s=arc-20160816; b=M5X2MJA4eGMa5fPK2LLgnqcHGVXHl8D0m8n5M8sVUvit+3RG+JJ87huTAQ460b0G4f 3MBzGZEMBBkYZU2ilxtF0rXF/Jsg6ILjpfC1EnRWNIzROoqvHhMOp6pw96Dnp8fAHPzu Jlf16wSw1+gUx7rqWqZ68svPmVeWqD8t/PJzxuednjJZSaTvARr1XiWl3fQwXf7qCNDS JKzNij1AGWcxWaPjmCo4GnwmV0Fff3HHYCfSZlnEh3S84PSpE2/ZAGu3PLfNeETTmps6 myyAhRRZhomcCrwyfJVXl5um2CryHjn0HBVRPgWeTlYMQ3Rs1OeS/E5YIB9FX0BtqTyB tmDw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=in-reply-to:content-disposition:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:message-id:subject:cc :to:from:dkim-signature:date; bh=I1QBPl5Ey4ifEIkMCxl3N8eliVz2YzHxUOV12z15xsk=; fh=QbxhSyLuw5Ozq1xZc/+SBL7siGqq5aWQKrQ6pL11t1c=; b=AWGI6c4JrElXlWsg5x4S1Z9/UIGqFD/UPdwcM6kTG4lWGcRLcIEp8zOdOVI4kjqrY7 BeDigAWsn3emeCQPk7QgLj8QfImTojYsAOUKh3z0pBSr3M7yrpxnX9YkBSq8lKE+c/w6 iFhfeI1FvXacbWfy7b6SJtfre/4RXLRVG8Z6ILihQr29SgXbV5eY/Ss0NJRBn3duKFNp gQ7PKa8xGU4+HKykiDQEZaIb/V6NqCb4dT8d708ZrpZ/zMEMG3SIxKbkiPHE7OD6XRyC 8xDuksMiV9CQMrdAlgUowVy3OHgkFvSHDZs5PORaTINJSegJ9f9avzCaef1yYGBITPwe M4ug==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@linux.dev header.s=key1 header.b=aaWCmJZb; arc=pass (i=1 spf=pass spfdomain=linux.dev dkim=pass dkdomain=linux.dev dmarc=pass fromdomain=linux.dev); spf=pass (google.com: domain of linux-kernel+bounces-127210-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.199.223 as permitted sender) smtp.mailfrom="linux-kernel+bounces-127210-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.dev Return-Path: Received: from ny.mirrors.kernel.org (ny.mirrors.kernel.org. [147.75.199.223]) by mx.google.com with ESMTPS id pa16-20020a05620a831000b00789e304ba10si10623622qkn.66.2024.04.01.16.52.43 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 01 Apr 2024 16:52:43 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-127210-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.199.223 as permitted sender) client-ip=147.75.199.223; Authentication-Results: mx.google.com; dkim=pass header.i=@linux.dev header.s=key1 header.b=aaWCmJZb; arc=pass (i=1 spf=pass spfdomain=linux.dev dkim=pass dkdomain=linux.dev dmarc=pass fromdomain=linux.dev); spf=pass (google.com: domain of linux-kernel+bounces-127210-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.199.223 as permitted sender) smtp.mailfrom="linux-kernel+bounces-127210-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.dev Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ny.mirrors.kernel.org (Postfix) with ESMTPS id 5DFE61C2203F for ; Mon, 1 Apr 2024 23:52:43 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id D151A57864; Mon, 1 Apr 2024 23:52:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="aaWCmJZb" Received: from out-188.mta1.migadu.com (out-188.mta1.migadu.com [95.215.58.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA84657306 for ; Mon, 1 Apr 2024 23:52:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.188 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712015553; cv=none; b=AfrQVjaXQL2RwIQMJt12Tc+X7JW6TPIpQrDPu/YBmu/Vbm5YRHljldmGdgthPxQys4CQqrHq7+jAdKk/Ded6TWpq2KhP5RNHxrvW7jse4jfANaWpVR9KQsBH7v/4M9TdxW56khmFtLdpSfyAVHq/O6D3T0NcSi402OwaHBVeBFY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712015553; c=relaxed/simple; bh=I1QBPl5Ey4ifEIkMCxl3N8eliVz2YzHxUOV12z15xsk=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=LDD2CvyNl3ym9gD+6dlw0iVH6Yn5WAyEVwJpyGC0mdhpc2RbTinFlljzoBHxm9AjvWf3fLYVdCAUuDkI6IxOdMmHzk7eu+2SfDYXmhqHIYA5RnokdiMz2ekjIvM5x/1+P8yVOyN1U0ZGG8IC6m8N2qklf1ydtdYPAv+NOYQUqPQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=aaWCmJZb; arc=none smtp.client-ip=95.215.58.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Date: Mon, 1 Apr 2024 16:52:24 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1712015548; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=I1QBPl5Ey4ifEIkMCxl3N8eliVz2YzHxUOV12z15xsk=; b=aaWCmJZbN6WUia8WK2ZqGCYGcNR5t9Erobt0UtI7/peiidTZrpG2Qjqzx9d5jj/b68+T3L SeC/Yfw5Lz3vQJICvtLPw2lPUGwruRUcbWCwu2AJzZEeuiX36xZQlQ4Ktz6BGXj6Ht2q2n Gmot9nNsLQaABuOt8Du1c2yz9TvCtn0= X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. From: Roman Gushchin To: Ubisectech Sirius Cc: linux-trace-kernel , linux-kernel , hannes , mhocko , "shakeel.butt" Subject: Re: general protection fault in refill_obj_stock Message-ID: References: <91e1389e-0723-42e7-9ea4-396ec6b54e49.bugreport@ubisectech.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <91e1389e-0723-42e7-9ea4-396ec6b54e49.bugreport@ubisectech.com> X-Migadu-Flow: FLOW_OUT On Mon, Apr 01, 2024 at 03:04:46PM +0800, Ubisectech Sirius wrote: > Hello. > We are Ubisectech Sirius Team, the vulnerability lab of China ValiantSec. Recently, our team has discovered a issue in Linux kernel 6.7. Attached to the email were a PoC file of the issue. Thank you for the report! I tried to compile and run your test program for about half an hour on a virtual machine running 6.7 with enabled KASAN, but wasn't able to reproduce the problem. Can you, please, share a bit more information? How long does it take to reproduce? Do you mind sharing your kernel config? Is there anything special about your setup? What are exact steps to reproduce the problem? Is this problem reproducible on 6.6? It's interesting that the problem looks like use-after-free for the objcg pointer but happens in the context of udev-systemd, which I believe should be fairly stable and it's cgroup is not going anywhere. Thanks!