Thread (6 messages) flat view 6 messages, 3 authors, 2026-08-26

Re: [BUG] KASAN: slab-use-after-free Read in slip_receive_buf

From: Eric Dumazet <edumazet@google.com>
Date: 2026-08-25 15:27:25
Also in: lkml

On Tue, Aug 25, 2026 at 5:07 PM Jaeyoung Chung [off-list ref] wrote:
Hello,

We found a "KASAN: slab-use-after-free Read in slip_receive_buf" on Linux v7.2.
The issue was found by our own race fuzzer. We have not analyzed the root cause,
so we do not have a proposed fix to offer.

To reproduce the race reliably, we applied the delay patch below to the
kernel and ran the C reproducer as root inside an x86_64 QEMU guest. The
crash log we observed, the delay patch and the reproducer are all included
below.

The following kernel config options are required to reproduce the issue:
    CONFIG_SLIP=y
    CONFIG_LEGACY_TIOCSTI=y
    CONFIG_UNIX98_PTYS=y
    CONFIG_TTY=y
    CONFIG_KASAN=y

We hope this report is useful. Please let us know if any further
information would help.

Reported-by: Eulgyu Kim <redacted>
Reported-by: Jaeyoung Chung <redacted>
This rings a bell; I had a local syzbot report for this issue a while back.

I think we should remove slip_hangup().
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help