Re: [PATCH net] tipc: fix use-after-free

2017-08-18 Thread David Miller
From: Eric Dumazet Date: Wed, 16 Aug 2017 09:41:54 -0700 > From: Eric Dumazet > > syszkaller reported use-after-free in tipc [1] > > When msg->rep skb is freed, set the pointer to NULL, > so that caller does not free it again. ... > Signed-off-by: Eric Dumazet > Reported-by: Dmitry Vyukov

[PATCH net] tipc: fix use-after-free

2017-08-16 Thread Eric Dumazet
From: Eric Dumazet syszkaller reported use-after-free in tipc [1] When msg->rep skb is freed, set the pointer to NULL, so that caller does not free it again. [1] == BUG: KASAN: use-after-free in skb_push+0xd4/0xe0 net/core/skbuff.