Re: net: use-after-free in recvmmsg

2016-03-11 Thread Dmitry Vyukov
On Thu, Mar 10, 2016 at 8:31 PM, Arnaldo Carvalho de Melo wrote: > Em Thu, Mar 10, 2016 at 07:35:57PM +0100, Dmitry Vyukov escreveu: >> On Tue, Jan 26, 2016 at 8:30 PM, Arnaldo Carvalho de Melo >> wrote: >> > Em Tue, Jan 26, 2016 at 08:27:48PM +0100, Dmitry Vyukov escreveu: >> >> On Fri, Jan 22,

Re: net: use-after-free in recvmmsg

2016-03-10 Thread Arnaldo Carvalho de Melo
Em Thu, Mar 10, 2016 at 07:35:57PM +0100, Dmitry Vyukov escreveu: > On Tue, Jan 26, 2016 at 8:30 PM, Arnaldo Carvalho de Melo > wrote: > > Em Tue, Jan 26, 2016 at 08:27:48PM +0100, Dmitry Vyukov escreveu: > >> On Fri, Jan 22, 2016 at 10:16 PM, Arnaldo Carvalho de Melo > >> wrote: > >> > Em Fri,

Re: net: use-after-free in recvmmsg

2016-03-10 Thread Dmitry Vyukov
On Tue, Jan 26, 2016 at 8:30 PM, Arnaldo Carvalho de Melo wrote: > Em Tue, Jan 26, 2016 at 08:27:48PM +0100, Dmitry Vyukov escreveu: >> On Fri, Jan 22, 2016 at 10:16 PM, Arnaldo Carvalho de Melo >> wrote: >> > Em Fri, Jan 22, 2016 at 09:39:53PM +0100, Dmitry Vyukov escreveu: >> >> I am on commit

Re: net: use-after-free in recvmmsg

2016-01-26 Thread Arnaldo Carvalho de Melo
Em Tue, Jan 26, 2016 at 08:27:48PM +0100, Dmitry Vyukov escreveu: > On Fri, Jan 22, 2016 at 10:16 PM, Arnaldo Carvalho de Melo > wrote: > > Em Fri, Jan 22, 2016 at 09:39:53PM +0100, Dmitry Vyukov escreveu: > >> I am on commit 30f05309bde49295e02e45c7e615f73aa4e0ccc2 (Jan 20). > >> Seems to be add

Re: net: use-after-free in recvmmsg

2016-01-26 Thread Dmitry Vyukov
On Fri, Jan 22, 2016 at 10:16 PM, Arnaldo Carvalho de Melo wrote: > Em Fri, Jan 22, 2016 at 09:39:53PM +0100, Dmitry Vyukov escreveu: >> While running syzkaller fuzzer I've hit the following use-after-free: > > > >> Call Trace: >> [] __asan_report_load8_noabort+0x3e/0x40 >> mm/kasan/report.c:295

Re: net: use-after-free in recvmmsg

2016-01-22 Thread Arnaldo Carvalho de Melo
Em Fri, Jan 22, 2016 at 09:39:53PM +0100, Dmitry Vyukov escreveu: > While running syzkaller fuzzer I've hit the following use-after-free: > Call Trace: > [] __asan_report_load8_noabort+0x3e/0x40 > mm/kasan/report.c:295 > [] __sys_recvmmsg+0x6fa/0x7f0 net/socket.c:2261 > [< inline >]

net: use-after-free in recvmmsg

2016-01-22 Thread Dmitry Vyukov
Hello, While running syzkaller fuzzer I've hit the following use-after-free: == BUG: KASAN: use-after-free in __sys_recvmmsg+0x6fa/0x7f0 at addr 88003b689ce0 Read of size 8 by task syz-executor/11997 =