Re: Re: [BUG] net/ppp: A use after free in ppp_unregister_channe

2021-03-15 Thread Tom Parkin
58 (星期五) > > > 收件人: lyl2...@mail.ustc.edu.cn > > > 抄送: pau...@samba.org, da...@davemloft.net, linux-...@vger.kernel.org, > > > net...@vger.kernel.org, linux-kernel@vger.kernel.org > > > 主题: Re: [BUG] net/ppp: A use after free in ppp_unregister_channe > > > >

Re: Re: [BUG] net/ppp: A use after free in ppp_unregister_channe

2021-03-15 Thread Guillaume Nault
-...@vger.kernel.org, > > net...@vger.kernel.org, linux-kernel@vger.kernel.org > > 主题: Re: [BUG] net/ppp: A use after free in ppp_unregister_channe > > > > Thanks for the report! > > > > On Thu, Mar 11, 2021 at 20:34:44 +0800, lyl2...@mail.ustc.edu.cn wrote:

Re: [BUG] net/ppp: A use after free in ppp_unregister_channe

2021-03-15 Thread Guillaume Nault
On Fri, Mar 12, 2021 at 10:12:58AM +, Tom Parkin wrote: > Thanks for the report! > > On Thu, Mar 11, 2021 at 20:34:44 +0800, lyl2...@mail.ustc.edu.cn wrote: > > File: drivers/net/ppp/ppp_generic.c > > > > In ppp_unregister_channel, pch could be freed in ppp_unbridge_channels() > > but after

Re: [BUG] net/ppp: A use after free in ppp_unregister_channe

2021-03-15 Thread Guillaume Nault
On Thu, Mar 11, 2021 at 08:34:44PM +0800, lyl2...@mail.ustc.edu.cn wrote: > File: drivers/net/ppp/ppp_generic.c > > In ppp_unregister_channel, pch could be freed in ppp_unbridge_channels() > but after that pch is still in use. Inside the function ppp_unbridge_channels, > if "pchbb == pch" is true

Re: Re: [BUG] net/ppp: A use after free in ppp_unregister_channe

2021-03-15 Thread Tom Parkin
-...@vger.kernel.org, > > net...@vger.kernel.org, linux-kernel@vger.kernel.org > > 主题: Re: [BUG] net/ppp: A use after free in ppp_unregister_channe > > > > Thanks for the report! > > > > On Thu, Mar 11, 2021 at 20:34:44 +0800, lyl2...@mail.ustc.edu.cn wrote:

Re: Re: [BUG] net/ppp: A use after free in ppp_unregister_channe

2021-03-12 Thread lyl2019
> -原始邮件- > 发件人: "Tom Parkin" > 发送时间: 2021-03-12 18:12:58 (星期五) > 收件人: lyl2...@mail.ustc.edu.cn > 抄送: pau...@samba.org, da...@davemloft.net, linux-...@vger.kernel.org, > net...@vger.kernel.org, linux-kernel@vger.kernel.org > 主题: Re: [BU

Re: [BUG] net/ppp: A use after free in ppp_unregister_channe

2021-03-12 Thread Tom Parkin
Thanks for the report! On Thu, Mar 11, 2021 at 20:34:44 +0800, lyl2...@mail.ustc.edu.cn wrote: > File: drivers/net/ppp/ppp_generic.c > > In ppp_unregister_channel, pch could be freed in ppp_unbridge_channels() > but after that pch is still in use. Inside the function ppp_unbridge_channels, > if