KASAN: use-after-free Read in fb_mode_is_equal

syzbot syzbot+f11cda116c57db68c227 at syzkaller.appspotmail.com
Wed Dec 25 15:26:00 UTC 2019


syzbot has bisected this bug to:

commit 13ff178ccd6d3b8074c542a911300b79c4eec255
Author: Daniel Vetter <daniel.vetter at ffwll.ch>
Date:   Tue May 28 09:02:53 2019 +0000

     fbcon: Call fbcon_mode_deleted/new_modelist directly

bisection log:  https://syzkaller.appspot.com/x/bisect.txt?x=1737c63ee00000
start commit:   46cf053e Linux 5.5-rc3
git tree:       upstream
final crash:    https://syzkaller.appspot.com/x/report.txt?x=14b7c63ee00000
console output: https://syzkaller.appspot.com/x/log.txt?x=10b7c63ee00000
kernel config:  https://syzkaller.appspot.com/x/.config?x=ed9d672709340e35
dashboard link: https://syzkaller.appspot.com/bug?extid=f11cda116c57db68c227
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=12bf72c6e00000

Reported-by: syzbot+f11cda116c57db68c227 at syzkaller.appspotmail.com
Fixes: 13ff178ccd6d ("fbcon: Call fbcon_mode_deleted/new_modelist directly")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection


More information about the dri-devel mailing list