Re: use-after free bug in hacked 4.16 kernel, related to fq_flow_dequeue

2018-08-13 Thread Toke Høiland-Jørgensen
Ben Greear writes: > On 08/02/2018 01:20 PM, Toke Høiland-Jørgensen wrote: >> Ben Greear writes: >> >>> On 08/02/2018 12:45 PM, Toke Høiland-Jørgensen wrote: Ben Greear writes: > This is from my hacked kernel, could be my fault. I thought the fq > guys might want to know

Re: use-after free bug in hacked 4.16 kernel, related to fq_flow_dequeue

2018-08-12 Thread Ben Greear
On 08/02/2018 01:20 PM, Toke Høiland-Jørgensen wrote: Ben Greear writes: On 08/02/2018 12:45 PM, Toke Høiland-Jørgensen wrote: Ben Greear writes: This is from my hacked kernel, could be my fault. I thought the fq guys might want to know however... Hmm, nothing obvious comes to mind;

Re: use-after free bug in hacked 4.16 kernel, related to fq_flow_dequeue

2018-08-02 Thread Toke Høiland-Jørgensen
Ben Greear writes: > On 08/02/2018 12:45 PM, Toke Høiland-Jørgensen wrote: >> Ben Greear writes: >> >>> This is from my hacked kernel, could be my fault. I thought the fq >>> guys might want to know however... >> >> Hmm, nothing obvious comes to mind; fq_flow_dequeue() just dequeues a >> packet

Re: use-after free bug in hacked 4.16 kernel, related to fq_flow_dequeue

2018-08-02 Thread Ben Greear
On 08/02/2018 12:45 PM, Toke Høiland-Jørgensen wrote: Ben Greear writes: This is from my hacked kernel, could be my fault. I thought the fq guys might want to know however... Hmm, nothing obvious comes to mind; fq_flow_dequeue() just dequeues a packet from the queue; it only has two memory

Re: use-after free bug in hacked 4.16 kernel, related to fq_flow_dequeue

2018-08-02 Thread Toke Høiland-Jørgensen
Ben Greear writes: > This is from my hacked kernel, could be my fault. I thought the fq > guys might want to know however... Hmm, nothing obvious comes to mind; fq_flow_dequeue() just dequeues a packet from the queue; it only has two memory derefs, to fq->lock and flow->queue. Don't see why

use-after free bug in hacked 4.16 kernel, related to fq_flow_dequeue

2018-08-01 Thread Ben Greear
This is from my hacked kernel, could be my fault. I thought the fq guys might want to know however... == BUG: KASAN: use-after-free in fq_flow_dequeue+0x353/0x3c0 [mac80211] Read of size 4 at addr 88013d92a700 by task rmmod/813