Re: net/ipv6: double free in ipip6_dev_free

2017-02-08 Thread Cong Wang
On Wed, Feb 8, 2017 at 5:56 AM, Dmitry Vyukov wrote: > First dev->tstats was freed here: > > 1376 static int ipip6_tunnel_init(struct net_device *dev) > 1377 { > 1378 struct ip_tunnel *tunnel = netdev_priv(dev); > 1379 int err; > 1380 > 1381 tunnel->dev = dev; > 1382

net/ipv6: double free in ipip6_dev_free

2017-02-08 Thread Dmitry Vyukov
Hello, I've got the following report while running syzkaller fuzzer on eb60f01302b24ce93108414e2c4c673cb7cd6e05: kernel BUG at mm/percpu.c:689! invalid opcode: [#1] SMP KASAN Dumping ftrace buffer: (ftrace buffer empty) Modules linked in: CPU: 0 PID: 15692 Comm: syz-executor1 Not tainted