2023-06-16 15:11:52

by syzbot

[permalink] [raw]
Subject: Re: [syzbot] [bluetooth?] possible deadlock in sco_conn_del

syzbot suspects this issue was fixed by commit:

commit a2ac591cb4d83e1f2d4b4adb3c14b2c79764650a
Author: Ruihan Li <[email protected]>
Date: Wed May 3 13:39:36 2023 +0000

Bluetooth: Fix UAF in hci_conn_hash_flush again

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=13755717280000
start commit: e4cf7c25bae5 Merge tag 'kbuild-fixes-v6.2' of git://git.ke..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=555d27e379d75ff1
dashboard link: https://syzkaller.appspot.com/bug?extid=b825d87fe2d043e3e652
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10052058480000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1190687c480000

If the result looks correct, please mark the issue as fixed by replying with:

#syz fix: Bluetooth: Fix UAF in hci_conn_hash_flush again

For information about bisection process see: https://goo.gl/tpsmEJ#bisection


2023-06-19 06:12:31

by Dmitry Vyukov

[permalink] [raw]
Subject: Re: [syzbot] [bluetooth?] possible deadlock in sco_conn_del

On Fri, 16 Jun 2023 at 17:09, syzbot
<[email protected]> wrote:
>
> syzbot suspects this issue was fixed by commit:
>
> commit a2ac591cb4d83e1f2d4b4adb3c14b2c79764650a
> Author: Ruihan Li <[email protected]>
> Date: Wed May 3 13:39:36 2023 +0000
>
> Bluetooth: Fix UAF in hci_conn_hash_flush again
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=13755717280000
> start commit: e4cf7c25bae5 Merge tag 'kbuild-fixes-v6.2' of git://git.ke..
> git tree: upstream
> kernel config: https://syzkaller.appspot.com/x/.config?x=555d27e379d75ff1
> dashboard link: https://syzkaller.appspot.com/bug?extid=b825d87fe2d043e3e652
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10052058480000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1190687c480000
>
> If the result looks correct, please mark the issue as fixed by replying with:
>
> #syz fix: Bluetooth: Fix UAF in hci_conn_hash_flush again
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

Looks reasonable:

#syz fix: Bluetooth: Fix UAF in hci_conn_hash_flush again