* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2019-12-16 13:15 KASAN: use-after-free Read in __media_entity_remove_links syzbot
@ 2023-07-11 13:00 ` syzbot
2023-07-12 21:11 ` Laurent Pinchart
2023-10-10 21:11 ` syzbot
` (5 subsequent siblings)
6 siblings, 1 reply; 12+ messages in thread
From: syzbot @ 2023-07-11 13:00 UTC (permalink / raw)
To: andreyknvl, laurent.pinchart, linux-kernel, linux-media,
linux-usb, mchehab, nogikh, sakari.ailus, syzkaller-bugs
This bug is marked as fixed by commit:
media: uvcvideo: Avoid cyclic entity chains due to malformed
But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and new crashes with
the same signature are ignored.
Kernel: Linux
Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
---
[1] I expect the commit to be present in:
1. for-kernelci branch of
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
2. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
3. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
4. main branch of
git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
The full list of 9 trees can be found at
https://syzkaller.appspot.com/upstream/repos
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2023-07-11 13:00 ` [syzbot] " syzbot
@ 2023-07-12 21:11 ` Laurent Pinchart
2023-07-20 11:54 ` Aleksandr Nogikh
0 siblings, 1 reply; 12+ messages in thread
From: Laurent Pinchart @ 2023-07-12 21:11 UTC (permalink / raw)
To: syzbot
Cc: andreyknvl, linux-kernel, linux-media, linux-usb, mchehab,
nogikh, sakari.ailus, syzkaller-bugs
On Tue, Jul 11, 2023 at 06:00:08AM -0700, syzbot wrote:
> This bug is marked as fixed by commit:
> media: uvcvideo: Avoid cyclic entity chains due to malformed
>
> But I can't find it in the tested trees[1] for more than 90 days.
> Is it a correct commit? Please update it by replying:
#syz fix: media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
Can a commit ID be used as well ?
> Until then the bug is still considered open and new crashes with
> the same signature are ignored.
>
> Kernel: Linux
> Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
>
> ---
> [1] I expect the commit to be present in:
>
> 1. for-kernelci branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
>
> 2. master branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
>
> 3. master branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
>
> 4. main branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
>
> The full list of 9 trees can be found at
> https://syzkaller.appspot.com/upstream/repos
--
Regards,
Laurent Pinchart
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2023-07-12 21:11 ` Laurent Pinchart
@ 2023-07-20 11:54 ` Aleksandr Nogikh
0 siblings, 0 replies; 12+ messages in thread
From: Aleksandr Nogikh @ 2023-07-20 11:54 UTC (permalink / raw)
To: Laurent Pinchart
Cc: syzbot, andreyknvl, linux-kernel, linux-media, linux-usb,
mchehab, sakari.ailus, syzkaller-bugs
On Wed, Jul 12, 2023 at 11:11 PM Laurent Pinchart
<laurent.pinchart@ideasonboard.com> wrote:
>
> On Tue, Jul 11, 2023 at 06:00:08AM -0700, syzbot wrote:
> > This bug is marked as fixed by commit:
> > media: uvcvideo: Avoid cyclic entity chains due to malformed
> >
> > But I can't find it in the tested trees[1] for more than 90 days.
> > Is it a correct commit? Please update it by replying:
>
> #syz fix: media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
Thanks for providing the correct name!
>
> Can a commit ID be used as well ?
The problem with commit hashes is that we fuzz quite a number of
different Linux trees and every new commit might appear in all of them
with totally different hashes. Name is a much more reliable
identifier, so that's what we currently require in #syz fix.
>
> > Until then the bug is still considered open and new crashes with
> > the same signature are ignored.
> >
> > Kernel: Linux
> > Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
> >
> > ---
> > [1] I expect the commit to be present in:
> >
> > 1. for-kernelci branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
> >
> > 2. master branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
> >
> > 3. master branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
> >
> > 4. main branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
> >
> > The full list of 9 trees can be found at
> > https://syzkaller.appspot.com/upstream/repos
>
> --
> Regards,
>
> Laurent Pinchart
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2019-12-16 13:15 KASAN: use-after-free Read in __media_entity_remove_links syzbot
2023-07-11 13:00 ` [syzbot] " syzbot
@ 2023-10-10 21:11 ` syzbot
2023-10-24 21:11 ` syzbot
` (4 subsequent siblings)
6 siblings, 0 replies; 12+ messages in thread
From: syzbot @ 2023-10-10 21:11 UTC (permalink / raw)
To: andreyknvl, laurent.pinchart, linux-kernel, linux-media,
linux-usb, mchehab, nogikh, sakari.ailus, syzkaller-bugs
This bug is marked as fixed by commit:
media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and new crashes with
the same signature are ignored.
Kernel: Linux
Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
---
[1] I expect the commit to be present in:
1. for-kernelci branch of
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
2. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
3. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
4. main branch of
git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
The full list of 9 trees can be found at
https://syzkaller.appspot.com/upstream/repos
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2019-12-16 13:15 KASAN: use-after-free Read in __media_entity_remove_links syzbot
2023-07-11 13:00 ` [syzbot] " syzbot
2023-10-10 21:11 ` syzbot
@ 2023-10-24 21:11 ` syzbot
2023-11-07 21:12 ` syzbot
` (3 subsequent siblings)
6 siblings, 0 replies; 12+ messages in thread
From: syzbot @ 2023-10-24 21:11 UTC (permalink / raw)
To: andreyknvl, laurent.pinchart, linux-kernel, linux-media,
linux-usb, mchehab, nogikh, sakari.ailus, syzkaller-bugs
This bug is marked as fixed by commit:
media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and new crashes with
the same signature are ignored.
Kernel: Linux
Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
---
[1] I expect the commit to be present in:
1. for-kernelci branch of
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
2. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
3. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
4. main branch of
git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
The full list of 9 trees can be found at
https://syzkaller.appspot.com/upstream/repos
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2019-12-16 13:15 KASAN: use-after-free Read in __media_entity_remove_links syzbot
` (2 preceding siblings ...)
2023-10-24 21:11 ` syzbot
@ 2023-11-07 21:12 ` syzbot
2023-11-21 21:13 ` syzbot
` (2 subsequent siblings)
6 siblings, 0 replies; 12+ messages in thread
From: syzbot @ 2023-11-07 21:12 UTC (permalink / raw)
To: andreyknvl, laurent.pinchart, linux-kernel, linux-media,
linux-usb, mchehab, nogikh, sakari.ailus, syzkaller-bugs
This bug is marked as fixed by commit:
media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and new crashes with
the same signature are ignored.
Kernel: Linux
Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
---
[1] I expect the commit to be present in:
1. for-kernelci branch of
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
2. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
3. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
4. main branch of
git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
The full list of 9 trees can be found at
https://syzkaller.appspot.com/upstream/repos
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2019-12-16 13:15 KASAN: use-after-free Read in __media_entity_remove_links syzbot
` (3 preceding siblings ...)
2023-11-07 21:12 ` syzbot
@ 2023-11-21 21:13 ` syzbot
2023-11-21 21:45 ` Laurent Pinchart
2023-12-06 11:40 ` syzbot
2023-12-20 11:41 ` syzbot
6 siblings, 1 reply; 12+ messages in thread
From: syzbot @ 2023-11-21 21:13 UTC (permalink / raw)
To: andreyknvl, laurent.pinchart, linux-kernel, linux-media,
linux-usb, mchehab, nogikh, sakari.ailus, syzkaller-bugs
This bug is marked as fixed by commit:
media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and new crashes with
the same signature are ignored.
Kernel: Linux
Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
---
[1] I expect the commit to be present in:
1. for-kernelci branch of
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
2. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
3. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
4. main branch of
git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
The full list of 9 trees can be found at
https://syzkaller.appspot.com/upstream/repos
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2023-11-21 21:13 ` syzbot
@ 2023-11-21 21:45 ` Laurent Pinchart
2023-11-22 11:39 ` Aleksandr Nogikh
0 siblings, 1 reply; 12+ messages in thread
From: Laurent Pinchart @ 2023-11-21 21:45 UTC (permalink / raw)
To: syzbot
Cc: andreyknvl, linux-kernel, linux-media, linux-usb, mchehab,
nogikh, sakari.ailus, syzkaller-bugs
On Tue, Nov 21, 2023 at 01:13:15PM -0800, syzbot wrote:
> This bug is marked as fixed by commit:
> media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
>
> But I can't find it in the tested trees[1] for more than 90 days.
> Is it a correct commit? Please update it by replying:
>
> #syz fix: exact-commit-title
What logic does syzbot use to try and find the commit upstream ? There's
a commit with the exact same subject, what was missing to find it
automatically ?
> Until then the bug is still considered open and new crashes with
> the same signature are ignored.
>
> Kernel: Linux
> Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
>
> ---
> [1] I expect the commit to be present in:
>
> 1. for-kernelci branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
>
> 2. master branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
>
> 3. master branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
>
> 4. main branch of
> git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
>
> The full list of 9 trees can be found at
> https://syzkaller.appspot.com/upstream/repos
--
Regards,
Laurent Pinchart
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2023-11-21 21:45 ` Laurent Pinchart
@ 2023-11-22 11:39 ` Aleksandr Nogikh
0 siblings, 0 replies; 12+ messages in thread
From: Aleksandr Nogikh @ 2023-11-22 11:39 UTC (permalink / raw)
To: Laurent Pinchart
Cc: syzbot, andreyknvl, linux-kernel, linux-media, linux-usb,
mchehab, sakari.ailus, syzkaller-bugs
Thanks for reporting the problem!
Syzbot looked at the last ~1.5 years of commit history to find the
commit, which is almost always enough, but not in this particular
case.
I've filed https://github.com/google/syzkaller/issues/4347 to fix the
syzbot code.
--
Aleksandr
On Tue, Nov 21, 2023 at 10:45 PM Laurent Pinchart
<laurent.pinchart@ideasonboard.com> wrote:
>
> On Tue, Nov 21, 2023 at 01:13:15PM -0800, syzbot wrote:
> > This bug is marked as fixed by commit:
> > media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
> >
> > But I can't find it in the tested trees[1] for more than 90 days.
> > Is it a correct commit? Please update it by replying:
> >
> > #syz fix: exact-commit-title
>
> What logic does syzbot use to try and find the commit upstream ? There's
> a commit with the exact same subject, what was missing to find it
> automatically ?
>
> > Until then the bug is still considered open and new crashes with
> > the same signature are ignored.
> >
> > Kernel: Linux
> > Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
> >
> > ---
> > [1] I expect the commit to be present in:
> >
> > 1. for-kernelci branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
> >
> > 2. master branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
> >
> > 3. master branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
> >
> > 4. main branch of
> > git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
> >
> > The full list of 9 trees can be found at
> > https://syzkaller.appspot.com/upstream/repos
>
> --
> Regards,
>
> Laurent Pinchart
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2019-12-16 13:15 KASAN: use-after-free Read in __media_entity_remove_links syzbot
` (4 preceding siblings ...)
2023-11-21 21:13 ` syzbot
@ 2023-12-06 11:40 ` syzbot
2023-12-20 11:41 ` syzbot
6 siblings, 0 replies; 12+ messages in thread
From: syzbot @ 2023-12-06 11:40 UTC (permalink / raw)
To: andreyknvl, laurent.pinchart, linux-kernel, linux-media,
linux-usb, mchehab, nogikh, sakari.ailus, syzkaller-bugs
This bug is marked as fixed by commit:
media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and new crashes with
the same signature are ignored.
Kernel: Linux
Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
---
[1] I expect the commit to be present in:
1. for-kernelci branch of
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
2. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
3. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
4. main branch of
git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
The full list of 9 trees can be found at
https://syzkaller.appspot.com/upstream/repos
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [syzbot] KASAN: use-after-free Read in __media_entity_remove_links
2019-12-16 13:15 KASAN: use-after-free Read in __media_entity_remove_links syzbot
` (5 preceding siblings ...)
2023-12-06 11:40 ` syzbot
@ 2023-12-20 11:41 ` syzbot
6 siblings, 0 replies; 12+ messages in thread
From: syzbot @ 2023-12-20 11:41 UTC (permalink / raw)
To: andreyknvl, laurent.pinchart, linux-kernel, linux-media,
linux-usb, mchehab, nogikh, sakari.ailus, syzkaller-bugs
This bug is marked as fixed by commit:
media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and new crashes with
the same signature are ignored.
Kernel: Linux
Dashboard link: https://syzkaller.appspot.com/bug?extid=0b0095300dfeb8a83dc8
---
[1] I expect the commit to be present in:
1. for-kernelci branch of
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git
2. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git
3. master branch of
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git
4. main branch of
git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git
The full list of 9 trees can be found at
https://syzkaller.appspot.com/upstream/repos
^ permalink raw reply [flat|nested] 12+ messages in thread