Received: by 2002:a05:6a10:206:0:0:0:0 with SMTP id 6csp3918915pxj; Tue, 8 Jun 2021 01:48:21 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyLorTUZpeeEhB5Vw2sJ6ZKUKFCP0tA8Xy8dtvfnHgOP467YvsJuw13YJVKXgi0aUHd9gal X-Received: by 2002:aa7:c547:: with SMTP id s7mr23961140edr.239.1623142101046; Tue, 08 Jun 2021 01:48:21 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1623142101; cv=none; d=google.com; s=arc-20160816; b=YoyMZSxMQaKTl1J3nx7xtPMPGSAVPeskjZg8zHUy1DDdwJLE04IyVt1xtexYxnOwqy 69v9S4vi44wVUcxMEILEkUq506PhLCQJLJeBTS04SZtVga33wrfdIQbFRFV6igrIhDyA orh1bsFEo1hhCToy6RRov+Juz3cu9xLy1EjXX/1W932DYlbWyhu+4/p6ywtCZJ4ZxQMU WGxMdeqrY7mr5UTZ/Hg4PMqKd6QNQb8mvvaCoDdXevRo/E7mnO1ign1KxLiyudldMBPu frQtEuw9zQSBFRAvWxbHZxiyNQ/yeHUvVMjNAhRBuY4PwUsV7JKUqMM3NtH9/AkU3RwA yiew== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-transfer-encoding :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature:dkim-signature; bh=OcJGuks2BsIJ9Z1Uvy/YBynhz/rsZ2UduAezquC86NI=; b=hYNPwazSQuMtW3G/C/yQOpMH5hJ59ebqhs4AUl5IVR2DRr3RHPpFQMo+QUNeB8RfLP zK7X+OGPyIs8gBmGniAHxW4XxA7fON5CD44MpS2JAEavOd9H2YRkrjawlWofe6720H9x dTzleN8wcMv/1EWZsCoTjOonUwveIkhiBDDiaeV7aRtqK7bv08oqt2hbYp0kuYOhlrhx XlolZGlgyJtgNVKESm7+rzRZ27pW44fIQVqlck/lybU6Mtx8MPV6hIUv9NMdJj3CUNP7 4LnF3Y3LXOchGBKL/ceZD8UK2PcKE4oQdJXXXMopHphMCDRNl38lgXWJ+HehmneMb8Vt LSfg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kroah.com header.s=fm1 header.b=Av6caqxi; dkim=pass header.i=@messagingengine.com header.s=fm3 header.b=LQ3VVl0v; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id u21si14469953ejz.696.2021.06.08.01.47.57; Tue, 08 Jun 2021 01:48:21 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kroah.com header.s=fm1 header.b=Av6caqxi; dkim=pass header.i=@messagingengine.com header.s=fm3 header.b=LQ3VVl0v; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231330AbhFHIsB (ORCPT + 99 others); Tue, 8 Jun 2021 04:48:01 -0400 Received: from new3-smtp.messagingengine.com ([66.111.4.229]:43025 "EHLO new3-smtp.messagingengine.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231337AbhFHIsA (ORCPT ); Tue, 8 Jun 2021 04:48:00 -0400 Received: from compute1.internal (compute1.nyi.internal [10.202.2.41]) by mailnew.nyi.internal (Postfix) with ESMTP id 79FBF5804C1; Tue, 8 Jun 2021 04:46:07 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute1.internal (MEProxy); Tue, 08 Jun 2021 04:46:07 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kroah.com; h= date:from:to:cc:subject:message-id:references:mime-version :content-type:content-transfer-encoding:in-reply-to; s=fm1; bh=O cJGuks2BsIJ9Z1Uvy/YBynhz/rsZ2UduAezquC86NI=; b=Av6caqxi5rTeJuJHw NWZllbrLTXvWa6MpjlijpjX11gb55Q9azwW9YidOA7pOaoaBZSbY9Er5dQF3lAwH XRCYFjQQkWNjX09zfqB2bbyTZ2mYtyx2iNJu1VVlM/KfyAN6Tnjugvlkl6cKwKrF v5Q4Stz39wCAJcxFC3HftStWE/BMDI9JOUeza2CR4jQFVcJlT+N3QezxzhJe2yIB S3QXGkKjZ7jcy1uCy+7X53oQC0v2UeKU+K61lSBBZrBzNm4bUcg9wC8QCa5ErgDI 2c+8ZfMRSyHtP9PSb0qUczFUy5Fqcr7m9/I999kyu60xVMk94hj+0wYvV7Y1Yvfl dSSWA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm3; bh=OcJGuks2BsIJ9Z1Uvy/YBynhz/rsZ2UduAezquC86 NI=; b=LQ3VVl0vrlrnC1fH8a6CIwcGKSaKfX0uKUPPrFAxMAoczlzylddAm1zFD rYqKAwYGUWA/3OAg2hMIW9NFlRfDq7MZTwuuEqBL226S/F/OSkbV31O/L3ZudGdN xIv+0nG+5SjqmHYHjrZXqM6E72EZ8DcfQig6lt4AVp+Yan/a2FE3fusNCm0/TnYE rEUdURyDrdJdZzWXpPKA7bHeyZoilks79sJa8CquafC8YfJHuVXf0ibgmvQLTr1i XC3auMTnQ6ebbQDZd0RxdXliO92ysTZJ3e/teU8uNtYzNWOtwuCxWbJvchXXkuG/ bESeHmPi1hLl9C76I1WnQkySvf12Q== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrfedtledgtdehucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepfffhvffukfhfgggtugfgjgesthekredttddtudenucfhrhhomhepifhrvghg ucfmjfcuoehgrhgvgheskhhrohgrhhdrtghomheqnecuggftrfgrthhtvghrnhepvedtie elueetgeeggfeufefhvefgtdetgfetgfdtvdegjeehieduvddtkeffheffnecuvehluhhs thgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepghhrvghgsehkrhhorg hhrdgtohhm X-ME-Proxy: Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 8 Jun 2021 04:46:05 -0400 (EDT) Date: Tue, 8 Jun 2021 10:46:04 +0200 From: Greg KH To: SyzScope Cc: "Jason A. Donenfeld" , syzbot , davem@davemloft.net, johan.hedberg@gmail.com, kuba@kernel.org, linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, marcel@holtmann.org, netdev@vger.kernel.org, syzkaller-bugs@googlegroups.com, kernel-hardening@lists.openwall.com Subject: Re: KASAN: use-after-free Read in hci_chan_del Message-ID: References: <000000000000adea7f05abeb19cf@google.com> <2fb47714-551c-f44b-efe2-c6708749d03f@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org On Mon, Jun 07, 2021 at 11:26:26AM -0700, SyzScope wrote: > Hi all, > We are really thankful for all the suggestions and concerns. We are > definitely interested in continuing this line of research. > > Just to clarify:? SyzScope is an ongoing research project that is currently > under submission, which has an anonymity requirement. As documented, we can not accept anonymous contributions to the kernel, so perhaps just wait until your paper is accepted? However, we take patches from researchers all the time under their real names while their papers are being reviewed, so this "requirement" seems odd to me, who is requiring this? > Therefore we chose to > use a gmail address initially in the public channel. Since Greg asked, we > did reveal our university affiliation and email address, as well as > cross-referenced a private email (again using university address) to > security@kernel.org. security@kernel.org is for fixing bugs reported to them that are not public, it is not for any sort of "notification of affiliation". See the documentation for the details about what this alias is to be used for please. > We are sorry for the chaos of using several different > email addresses. In the future, we will try to use our university address > directly (we checked with other researchers and it seems to be okay). That would be best, as obviously, and again, as documented, we can not accept anonymous contributions to the kernel. greg k-h