Re: [PATCH net-next] net: fix use-after-free in kfree_skb_list

2019-06-03 Thread David Miller
From: Eric Dumazet Date: Sun, 2 Jun 2019 11:24:18 -0700 > syzbot reported nasty use-after-free [1] > > Lets remove frag_list field from structs ip_fraglist_iter > and ip6_fraglist_iter. This seens not needed anyway. ... > Fixes: 0feca6190f88 ("net: ipv6: add skbuff fraglist splitter") > Fixes:

Re: [PATCH net-next] net: fix use-after-free in kfree_skb_list

2019-06-03 Thread Pablo Neira Ayuso
On Sun, Jun 02, 2019 at 11:24:18AM -0700, Eric Dumazet wrote: > syzbot reported nasty use-after-free [1] > > Lets remove frag_list field from structs ip_fraglist_iter > and ip6_fraglist_iter. This seens not needed anyway. > > [1] : > BUG: KASAN: use-after-free in kfree_skb_list+0x5d/0x60 net/core

[PATCH net-next] net: fix use-after-free in kfree_skb_list

2019-06-02 Thread Eric Dumazet
syzbot reported nasty use-after-free [1] Lets remove frag_list field from structs ip_fraglist_iter and ip6_fraglist_iter. This seens not needed anyway. [1] : BUG: KASAN: use-after-free in kfree_skb_list+0x5d/0x60 net/core/skbuff.c:706 Read of size 8 at addr 888085a3cbc0 by task syz-executor30