Re: BUG: KASAN: use-after-free in udp_lib_get_port

2016-10-19 Thread Baozeng Ding
^ 88002f163c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 88002f163d00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ====== Best Regards, Baozeng Ding On 2016/10/17 3:53, Co

Re: BUG: KASAN: use-after-free in udp_lib_get_port

2016-10-19 Thread Baozeng Ding
^ 88002f163c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 88002f163d00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ====== Best Regards, Baozeng Ding On 2016/10/17 3:53,

BUG: slab-out-of-bounds in bio_alloc_bioset

2016-05-24 Thread Baozeng Ding
0 00 00 00 00 00 00 00 00 00 00 fc fc ^ 8800187aa080: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 8800187aa100: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc == == Best Regards, Baozeng Ding

BUG: slab-out-of-bounds in bio_alloc_bioset

2016-05-24 Thread Baozeng Ding
0 00 00 00 00 00 00 00 00 00 00 fc fc ^ 8800187aa080: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 8800187aa100: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc == == Best Regards, Baozeng Ding

BUG: net/ipv4: KASAN: use-after-free in tcp_v4_rcv

2016-05-15 Thread Baozeng Ding
y state around the buggy address: 880038027880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 880038027900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 880038027980: fc fc fc fc fc fc fc fc fb fb fb fb fb fb fb fb ^ 880038027a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 880038027a80: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc == Best Regards, Baozeng Ding

BUG: net/ipv4: KASAN: use-after-free in tcp_v4_rcv

2016-05-15 Thread Baozeng Ding
y state around the buggy address: 880038027880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 880038027900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 880038027980: fc fc fc fc fc fc fc fc fb fb fb fb fb fb fb fb ^ 880038027a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 880038027a80: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc == Best Regards, Baozeng Ding

BUG: mm/slub NULL-ptr deref in get_freepointer

2016-05-15 Thread Baozeng Ding
86/entry/entry_64.S:207 Code: 89 54 05 00 4d 89 e8 49 8b 7f 08 48 89 de 48 89 4c 24 68 66 83 6c 24 68 01 4c 8b 4c 24 68 e8 7f fe ff ff 84 c0 74 cc 49 63 47 20 <49> 8b 0c 04 48 85 c9 74 0c 4d 89 e5 48 8b 53 10 49 89 cc eb bb RIP [< inline >] get_freepointer mm/slub.c:245 RIP [] deactivate_slab+0x99/0x710 mm/slub.c:1893 RSP ---[ end trace b34379b339f95a27 ]--- Best Regards, Baozeng Ding

BUG: mm/slub NULL-ptr deref in get_freepointer

2016-05-15 Thread Baozeng Ding
86/entry/entry_64.S:207 Code: 89 54 05 00 4d 89 e8 49 8b 7f 08 48 89 de 48 89 4c 24 68 66 83 6c 24 68 01 4c 8b 4c 24 68 e8 7f fe ff ff 84 c0 74 cc 49 63 47 20 <49> 8b 0c 04 48 85 c9 74 0c 4d 89 e5 48 8b 53 10 49 89 cc eb bb RIP [< inline >] get_freepointer mm/slub.c:245 RIP [] deactivate_slab+0x99/0x710 mm/slub.c:1893 RSP ---[ end trace b34379b339f95a27 ]--- Best Regards, Baozeng Ding

Re: Sound: BUG: KASAN: use-after-free in kill_fasync

2016-04-20 Thread Baozeng Ding
On 2016/4/6 19:37, Baozeng Ding wrote: On 2016/4/5 22:18, Takashi Iwai wrote: On Tue, 05 Apr 2016 15:51:30 +0200, Baozeng Ding wrote: Hi all, I've got the following report (use-after-free in kill_fasync) while running syzkaller. Unfortunately no reproducer.The kernel version is 4.5 (on Mar

Re: Sound: BUG: KASAN: use-after-free in kill_fasync

2016-04-20 Thread Baozeng Ding
On 2016/4/6 19:37, Baozeng Ding wrote: On 2016/4/5 22:18, Takashi Iwai wrote: On Tue, 05 Apr 2016 15:51:30 +0200, Baozeng Ding wrote: Hi all, I've got the following report (use-after-free in kill_fasync) while running syzkaller. Unfortunately no reproducer.The kernel version is 4.5 (on Mar

net/sctp: stack-out-of-bounds in sctp_getsockopt

2016-03-22 Thread Baozeng Ding
xe8\x18\x3d\x7f\x0e\x2f\xe9\x06\xf9\xb6\xcc\x60\xcc\x38\x6c\x9a\x78\xa7\x7c\x61", 1037); getsockopt(sock_dup, IPPROTO_IP, 0x81, (void *)0x2bf3ul, (socklen_t *)0x20003000ul); return 0; } Best Regards, Baozeng Ding

net/sctp: stack-out-of-bounds in sctp_getsockopt

2016-03-22 Thread Baozeng Ding
xe8\x18\x3d\x7f\x0e\x2f\xe9\x06\xf9\xb6\xcc\x60\xcc\x38\x6c\x9a\x78\xa7\x7c\x61", 1037); getsockopt(sock_dup, IPPROTO_IP, 0x81, (void *)0x2bf3ul, (socklen_t *)0x20003000ul); return 0; } Best Regards, Baozeng Ding

net/bluetooth: use-after-free in hci_event_packet

2016-03-20 Thread Baozeng Ding
node+0x3b0/0x3b0 kernel/kernel/kthread.c:285 Memory state around the buggy address: 88043ef6e200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 88043ef6e280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc >88043ef6e300: fc fc fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ 88043ef6e380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 88043ef6e400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb Best Regards, Baozeng Ding

net/bluetooth: use-after-free in hci_event_packet

2016-03-20 Thread Baozeng Ding
node+0x3b0/0x3b0 kernel/kernel/kthread.c:285 Memory state around the buggy address: 88043ef6e200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc 88043ef6e280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc >88043ef6e300: fc fc fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ 88043ef6e380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 88043ef6e400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb Best Regards, Baozeng Ding

kernel/irq: Null-ptr deref on handle_irq_event_percpu function

2016-03-18 Thread Baozeng Ding
+linux-kernel and irq maitainer. Best Regards, Baozeng Ding On Thu, Feb 25, 2016 at 04:16:10AM -0500, Red Hat Product Security wrote: > On Wed Feb 24 08:44:30 2016, splovi...@gmail.com wrote: > > Dear all, > > > > I hit the following bug when fuzzing kernel using > &g

kernel/irq: Null-ptr deref on handle_irq_event_percpu function

2016-03-18 Thread Baozeng Ding
+linux-kernel and irq maitainer. Best Regards, Baozeng Ding On Thu, Feb 25, 2016 at 04:16:10AM -0500, Red Hat Product Security wrote: > On Wed Feb 24 08:44:30 2016, splovi...@gmail.com wrote: > > Dear all, > > > > I hit the following bug when fuzzing kernel using > &g

net/ppp: use-after-free in ppp_unregister_channel

2016-03-18 Thread Baozeng Ding
nd the buggy address: 880064e21680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 880064e21700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb >880064e21780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff880064e21800: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 880064e21880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb == Best Regards, Baozeng Ding

net/ppp: use-after-free in ppp_unregister_channel

2016-03-18 Thread Baozeng Ding
nd the buggy address: 880064e21680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 880064e21700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb >880064e21780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff880064e21800: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb 880064e21880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb == Best Regards, Baozeng Ding