From mboxrd@z Thu Jan 1 00:00:00 1970 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Subject: KASAN: slab-out-of-bounds Read in hex_string From: syzbot Message-Id: <000000000000bc95620587b1748e@google.com> Date: Mon, 29 Apr 2019 13:52:01 -0700 To: andreyknvl@google.com, gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org, rafael@kernel.org, stern@rowland.harvard.edu, syzkaller-bugs@googlegroups.com List-ID: SGVsbG8sCgpzeXpib3QgaGFzIHRlc3RlZCB0aGUgcHJvcG9zZWQgcGF0Y2ggYW5kIHRoZSByZXBy b2R1Y2VyIGRpZCBub3QgdHJpZ2dlciAgCmNyYXNoOgoKUmVwb3J0ZWQtYW5kLXRlc3RlZC1ieTog IApzeXpib3QrYTlmZWZkMThjN2IyNDBmMTljNTRAc3l6a2FsbGVyLmFwcHNwb3RtYWlsLmNvbQoK VGVzdGVkIG9uOgoKY29tbWl0OiAgICAgICAgIDQzMTUxZDZjIHVzYi1mdXp6ZXI6IG1haW4gdXNi IGdhZGdldCBmdXp6ZXIgZHJpdmVyCmdpdCB0cmVlOiAgICAgICBodHRwczovL2dpdGh1Yi5jb20v Z29vZ2xlL2thc2FuLmdpdCB1c2ItZnV6emVyCmtlcm5lbCBjb25maWc6ICBodHRwczovL3N5emth bGxlci5hcHBzcG90LmNvbS94Ly5jb25maWc/eD00MTgzZWVlZjY1MGQxMjM0CmNvbXBpbGVyOiAg ICAgICBnY2MgKEdDQykgOS4wLjAgMjAxODEyMzEgKGV4cGVyaW1lbnRhbCkKcGF0Y2g6ICAgICAg ICAgIGh0dHBzOi8vc3l6a2FsbGVyLmFwcHNwb3QuY29tL3gvcGF0Y2guZGlmZj94PTE2YzU5Nzg4 YTAwMDAwCgpOb3RlOiB0ZXN0aW5nIGlzIGRvbmUgYnkgYSByb2JvdCBhbmQgaXMgYmVzdC1lZmZv cnQgb25seS4K From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.6 required=3.0 tests=FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_PASS,URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7E513C43219 for ; Mon, 29 Apr 2019 20:52:06 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 56CFE2075E for ; Mon, 29 Apr 2019 20:52:06 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729405AbfD2UwC (ORCPT ); Mon, 29 Apr 2019 16:52:02 -0400 Received: from mail-it1-f197.google.com ([209.85.166.197]:59240 "EHLO mail-it1-f197.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729393AbfD2UwC (ORCPT ); Mon, 29 Apr 2019 16:52:02 -0400 Received: by mail-it1-f197.google.com with SMTP id j203so619069itb.8 for ; Mon, 29 Apr 2019 13:52:01 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:in-reply-to:message-id:subject :from:to; bh=cAm7uQCoto51MF3DbmJ8qiz81JKkTC17o7TMeFgJuaY=; b=db9BmTQ/p2HZWZ7KW/d+8Ev5X2pRms3gnowBctbYo8FRiOOJN+2bnDjTp4Y/L30QUU WlnNB1ppKAXVJi8X2s+huYr1iWSSWI640QDVmoZfw5wiuhoPuAn7qygnm4JHQrvfs3qb OC4y39QlSD2GqKcmS7CmO1ne1N2kdXKCrIqq9r5EPa0fg5j1F7F9Ch25k9Hoxxuijf/j SZ0K9iSUaCao4VlPM1HghR89UIi8+UUhWMmubN2hvgLZmdil+sdf9p08npcNRCcOY4un M2vx3BS1pB1B/xn7Wx1+LwqL2q3Xf5IuOelHT85MzxftX+lFoJGO02lZcn0fT8Y2ur1r 9H4g== X-Gm-Message-State: APjAAAWzLU10WGyVR7v6sRcX3F3cU9z8bZQu4BBGqhutnh7Fau5uokgI 9Uycbl4HZamVkJyyMkT0yMo1bdDgTowElMK/9WUaOJNWhsT4 X-Google-Smtp-Source: APXvYqyg99LXgoRoX1mVoG+8rJWflXeP0VnHXkeYnUb/6Pad7ERsbjPwrPKxbVCLbUsaqJ76+2WrDzCRDW1FhvTF17AK/n1I2Fcz MIME-Version: 1.0 X-Received: by 2002:a6b:b989:: with SMTP id j131mr27265452iof.131.1556571121028; Mon, 29 Apr 2019 13:52:01 -0700 (PDT) Date: Mon, 29 Apr 2019 13:52:01 -0700 In-Reply-To: X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <000000000000bc95620587b1748e@google.com> Subject: Re: KASAN: slab-out-of-bounds Read in hex_string From: syzbot To: andreyknvl@google.com, gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org, rafael@kernel.org, stern@rowland.harvard.edu, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8"; delsp="yes"; format="flowed" Sender: linux-usb-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-usb@vger.kernel.org Message-ID: <20190429205201.7cMyNqjAfW3mGFKA1mfT0jgY0sCfPGeacnk0xqvwDBk@z> Hello, syzbot has tested the proposed patch and the reproducer did not trigger crash: Reported-and-tested-by: syzbot+a9fefd18c7b240f19c54@syzkaller.appspotmail.com Tested on: commit: 43151d6c usb-fuzzer: main usb gadget fuzzer driver git tree: https://github.com/google/kasan.git usb-fuzzer kernel config: https://syzkaller.appspot.com/x/.config?x=4183eeef650d1234 compiler: gcc (GCC) 9.0.0 20181231 (experimental) patch: https://syzkaller.appspot.com/x/patch.diff?x=16c59788a00000 Note: testing is done by a robot and is best-effort only.