From: Eric Dumazet
Date: Wed, 16 Aug 2017 09:41:54 -0700
> From: Eric Dumazet
>
> syszkaller reported use-after-free in tipc [1]
>
> When msg->rep skb is freed, set the pointer to NULL,
> so that caller does not free it again.
...
> Signed-off-by: Eric Dumazet
> Reported-by: Dmitry Vyukov
From: Eric Dumazet
syszkaller reported use-after-free in tipc [1]
When msg->rep skb is freed, set the pointer to NULL,
so that caller does not free it again.
[1]
==
BUG: KASAN: use-after-free in skb_push+0xd4/0xe0 net/core/skbuff.