Re: KASAN: stack-out-of-bounds Read in rds_sendmsg
From: Eric Biggers <hidden>
Date: 2018-01-31 02:16:43
Also in:
linux-rdma, lkml
From: Eric Biggers <hidden>
Date: 2018-01-31 02:16:43
Also in:
linux-rdma, lkml
On Thu, Dec 21, 2017 at 08:44:32AM -0800, Santosh Shilimkar wrote:
+Avinash On 12/21/2017 1:10 AM, syzbot wrote:quoted
syzkaller has found reproducer for the following crash on[..]quoted
audit: type=1400 audit(1513847224.110:7): avc: denied { map } for pid=3157 comm="syzkaller455006" path="/root/syzkaller455006870" dev="sda1" ino=16481 scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=1 ================================================================== BUG: KASAN: stack-out-of-bounds in rds_rdma_bytes net/rds/send.c:1013 [inline]Could you please post the discussed fix if you are ready with it ? This new report is same as last one and cmesg length check should address it. Regards, Santosh
This crash seems to have stopped occurring. I assume it was fixed by commit 14e138a86f63 (thanks Avinash!), so let's tell syzbot so that it can start reporting crashes in the same place again: #syz fix: RDS: Check cmsg_len before dereferencing CMSG_DATA - Eric