On Wed, Jan 13, 2016 at 12:58:34PM +0100, Dmitry Vyukov wrote: > > The following program triggers use-after-free in skcipher_sock_destruct. > This is on upstream commit 03891f9c853d5c4473224478a1e03ea00d70ff8d + > all pending patches from > git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6.git + > 4 latest Herbert patches. OK, the check_key function is buggy in that it doesn't lock the child socket so if you make two syscalls on the child socket at the same time you can end up freeing the parent socket. Please try these two patches. Thanks, -- Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To unsubscribe from this list: send the line "unsubscribe linux-crypto" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html