Re: block: use after free in bio_uncopy_user/copy_page_to_iter

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 05/04/2016 10:50 AM, Douglas Gilbert wrote:
> On 2016-05-04 09:56 AM, Sasha Levin wrote:
>> On 04/17/2016 06:44 PM, Sasha Levin wrote:
>>> On 04/17/2016 02:37 PM, Christoph Hellwig wrote:
>>>>> Adding Doug as this involves the SG driver, which has a slightly
>>>>> unusual usage of the blk-map.c code.
>>>>>
>>>>> Does anyone know if the __asan_storeN in the trace implies the memory
>>>>> stored to was invalid and not the memory read from?
>>> Yes. In this case it attempted to write to memory that was already freed.
>>
>> Ping? I'm still seeing bunch of these in -next.
> 
> And again ... (as requested 3 weeks ago):
>   So could you send me the user space program that caused this?

Sorry, didn't see the original mail.

It reproduces with syzkaller (https://github.com/google/syzkaller), I don't
have any easier way to reproduce it.


Thanks,
Sasha
--
To unsubscribe from this list: send the line "unsubscribe linux-block" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux RAID]     [Linux SCSI]     [Linux ATA RAID]     [IDE]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Device Mapper]

  Powered by Linux