Re: KASAN: use-after-free Read in p54u_load_firmware_cb

2019-05-18 Thread Christian Lamparter
Hello, On Saturday, May 18, 2019 7:49:49 PM CEST you wrote: > On Sat, 18 May 2019, syzbot wrote: > > > > syzbot has tested the proposed patch but the reproducer still triggered > > crash: > > KASAN: use-after-free Read in usb_driver_release_interface > > > > usb 1-1: Loading firmware file isl3

Re: KASAN: use-after-free Read in p54u_load_firmware_cb

2019-05-18 Thread syzbot
Hello, syzbot has tested the proposed patch and the reproducer did not trigger crash: Reported-and-tested-by: syzbot+200d4bb11b23d9293...@syzkaller.appspotmail.com Tested on: commit: 43151d6c usb-fuzzer: main usb gadget fuzzer driver git tree: https://github.com/google/kasa

Re: KASAN: use-after-free Read in p54u_load_firmware_cb

2019-05-18 Thread Alan Stern
On Sat, 18 May 2019, syzbot wrote: > Hello, > > syzbot has tested the proposed patch but the reproducer still triggered > crash: > KASAN: use-after-free Read in usb_driver_release_interface > > usb 1-1: Loading firmware file isl3887usb > usb 1-1: Direct firmware load for isl3887usb failed with

Re: KASAN: use-after-free Read in p54u_load_firmware_cb

2019-05-18 Thread syzbot
Hello, syzbot has tested the proposed patch but the reproducer still triggered crash: KASAN: use-after-free Read in usb_driver_release_interface usb 1-1: Loading firmware file isl3887usb usb 1-1: Direct firmware load for isl3887usb failed with error -2 usb 1-1: Firmware not found. p54usb 1-1:

Re: KASAN: use-after-free Read in p54u_load_firmware_cb

2019-05-18 Thread Alan Stern
On Sat, 18 May 2019, syzbot wrote: > Hello, > > syzbot tried to test the proposed patch but build/boot failed: One of these times I'll get it right... Alan Stern #syz test: https://github.com/google/kasan.git usb-fuzzer drivers/net/wireless/intersil/p54/p54usb.c | 37 +++--

Re: KASAN: use-after-free Read in p54u_load_firmware_cb

2019-05-17 Thread Christian Lamparter
On Monday, May 13, 2019 3:28:30 PM CEST Oliver Neukum wrote: > On Mo, 2019-05-13 at 03:23 -0700, syzbot wrote: > > syzbot has found a reproducer for the following crash on: > > > > HEAD commit:43151d6c usb-fuzzer: main usb gadget fuzzer driver > > git tree: https://github.com/google/kasa

KASAN: use-after-free Read in p54u_load_firmware_cb

2019-05-06 Thread syzbot
Hello, syzbot found the following crash on: HEAD commit:43151d6c usb-fuzzer: main usb gadget fuzzer driver git tree: https://github.com/google/kasan.git usb-fuzzer console output: https://syzkaller.appspot.com/x/log.txt?x=142b312ca0 kernel config: https://syzkaller.appspot.com/x/.