Thread (5 messages) flat view 5 messages, 2 authors, 2022-06-24

Re: KASAN: use-after-free Read in cfusbl_device_notify

From: Eric Dumazet <edumazet@google.com>
Date: 2022-06-24 06:32:49
Also in: lkml

On Fri, Jun 24, 2022 at 8:25 AM Dae R. Jeong [off-list ref] wrote:
On Fri, Jun 24, 2022 at 08:15:54AM +0200, Eric Dumazet wrote:
quoted
On Fri, Jun 24, 2022 at 8:08 AM Dae R. Jeong [off-list ref] wrote:
quoted
Hello,

We observed a crash "KASAN: use-after-free Read in cfusbl_device_notify" during fuzzing.
This is a known problem.

Some drivers do not like NETDEV_UNREGISTER being delivered multiple times.

Make sure in your fuzzing to have NET_DEV_REFCNT_TRACKER=y

Thanks.
Our config already have CONFIG_NET_DEV_REFCNT_TRACKER=y.
Are you also setting netdev_unregister_timeout_secs to a smaller value ?

netdev_unregister_timeout_secs
------------------------------

Unregister network device timeout in seconds.
This option controls the timeout (in seconds) used to issue a warning while
waiting for a network device refcount to drop to 0 during device
unregistration. A lower value may be useful during bisection to detect
a leaked reference faster. A larger value may be useful to prevent false
warnings on slow/loaded systems.
Default value is 10, minimum 1, maximum 3600.

Anyway, this UAF report seems not interesting.

Thank you for your quick reply.


Best regards,
Dae R. Jeong.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help