Re: scsi: use-after-free in sg_start_req

2017-01-30 Thread Dmitry Vyukov
On Mon, Jan 30, 2017 at 5:36 PM, Bart Van Assche wrote: > On Mon, 2017-01-30 at 08:25 +0100, Dmitry Vyukov wrote: >> On commit ca63ff9b11f958efafd8c8fa60fda14baec6149c > > What kernel have you been testing? That commit is not in any upstream kernel. This is mmotm git://git.kernel.org/pub/scm/linu

Re: scsi: use-after-free in sg_start_req

2017-01-30 Thread Bart Van Assche
On Mon, 2017-01-30 at 08:25 +0100, Dmitry Vyukov wrote: > On commit ca63ff9b11f958efafd8c8fa60fda14baec6149c What kernel have you been testing? That commit is not in any upstream kernel. Bart.-- To unsubscribe from this list: send the line "unsubscribe linux-scsi" in the body of a message to majo

scsi: use-after-free in sg_start_req

2017-01-29 Thread Dmitry Vyukov
Hello, The following program triggers use-after-free in sg_start_req: https://gist.githubusercontent.com/dvyukov/be6561d2819fe30a78711234e53866b8/raw/1d75d4508f7a8ebb0b1ec0d18c0054fbffbc0708/gistfile1.txt BUG: KASAN: use-after-free in bio_copy_user_iov+0xee1/0xf00 block/bio.c:1248 at addr 880