Re: sound: heap out-of-bounds write in dummy_systimer_prepare

2016-02-07 Thread Takashi Iwai
On Sat, 06 Feb 2016 19:26:11 +0100, Dmitry Vyukov wrote: > > Hello, > > I am still seeing these eap out-of-bounds writes in > dummy_systimer_prepare. Even when we've disabled the hrtimer sysctl. > The fuzzer does not change sysctls at the moment and I think we've > overlooked a very simple possib

sound: heap out-of-bounds write in dummy_systimer_prepare

2016-02-06 Thread Dmitry Vyukov
Hello, I am still seeing these eap out-of-bounds writes in dummy_systimer_prepare. Even when we've disabled the hrtimer sysctl. The fuzzer does not change sysctls at the moment and I think we've overlooked a very simple possibility that can happen when sysctls are not changed (i.e. triggered by an

Re: sound: heap out-of-bounds write in dummy_systimer_prepare

2016-01-27 Thread Takashi Iwai
On Thu, 28 Jan 2016 07:38:08 +0100, Takashi Iwai wrote: > > The easiest fix for this is obviously to disable the switch via > sysfs like below. Meanwhile we may copy the ops to the runtime > instance so that it won't affect the running stream. This can be done > for 4.6, while disabling sysfs fo

Re: sound: heap out-of-bounds write in dummy_systimer_prepare

2016-01-27 Thread Takashi Iwai
On Wed, 27 Jan 2016 10:55:45 +0100, Dmitry Vyukov wrote: > > Hello, > > I've got the following report while running syzkaller fuzzer: > > == > BUG: KASAN: slab-out-of-bounds in dummy_systimer_prepare+0x268/0x2a0 > at addr 880060

sound: heap out-of-bounds write in dummy_systimer_prepare

2016-01-27 Thread Dmitry Vyukov
Hello, I've got the following report while running syzkaller fuzzer: == BUG: KASAN: slab-out-of-bounds in dummy_systimer_prepare+0x268/0x2a0 at addr 88006067aa30 Write of size 4 by task syz-executor/5841 =