From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from r3-25.sinamail.sina.com.cn (r3-25.sinamail.sina.com.cn [202.108.3.25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6CBB71EC01B for ; Sat, 21 Feb 2026 14:36:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=202.108.3.25 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771684603; cv=none; b=PTU5oJvu/Aw8uUNmfIIWMu9i/0T4MIOmr21qnkLbKliMsosNUjvKlV9L99/HxZViUPLGe9C+Nj85PY3McxNfcDA/It6sega+FmKbQDPcEeZ/9VJpT3GKQBebkd7zzn8GnWnquf+SOuZOi7++BQZVvhFExrw/H1LR1gaYFzp3uyA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771684603; c=relaxed/simple; bh=9qGkByqNpuOR5link/SsjdHeQyeIpKmS4w8FDhinfu8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=om2XlQxK5UGfFW84uGcY+DjxZUzf5FUpow+2lyhs6M+033U8Z1hfuRxUVkacQK/EIOqJKIo+YR0F5k7iEgkyykQowCf/7f0r6qhfmGy5s57Msluwww3T6YMr5sQO1BCFZAGcfshFU/MVp4Vw0sgevOzaZogKAamxGjMDbtzBOMc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=sina.com; spf=pass smtp.mailfrom=sina.com; dkim=pass (1024-bit key) header.d=sina.com header.i=@sina.com header.b=Er3F5RLB; arc=none smtp.client-ip=202.108.3.25 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=sina.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=sina.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=sina.com header.i=@sina.com header.b="Er3F5RLB" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sina.com; s=201208; t=1771684598; bh=3JbXupx6DGezU1htgLfh0RZbcl1wiF6qjO4VW9tLdyg=; h=From:Subject:Date:Message-ID; b=Er3F5RLB9Yi6S7i+49jVP9KcZpqFXi47QABuhITt6T8s9C6UbGZL1+aC2MyTQNWhX FDsa78QY7WNVx2FQ3/3/4oeikLKw0hDTfvExiFe/6o/kbVabogy0c4lj7a+hF3+sHz pne9u4MBNGBekIWYgee1El4JpqmyMbcv6jtashgQ= X-SMAIL-HELO: localhost.localdomain Received: from unknown (HELO localhost.localdomain)([114.249.62.144]) by sina.com (10.54.253.31) with ESMTP id 6999C2CC00003710; Sat, 21 Feb 2026 22:35:58 +0800 (CST) X-Sender: hdanton@sina.com X-Auth-ID: hdanton@sina.com Authentication-Results: sina.com; spf=none smtp.mailfrom=hdanton@sina.com; dkim=none header.i=none; dmarc=none action=none header.from=hdanton@sina.com X-SMAIL-MID: 096176816282 X-SMAIL-UIID: 95ACC5F326D449A4879549A463AE6F49-20260221-223558-1 From: Hillf Danton To: syzbot Cc: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [media?] KASAN: slab-use-after-free Read in dvb_frontend_release (3) Date: Sat, 21 Feb 2026 22:35:46 +0800 Message-ID: <20260221143547.3277-1-hdanton@sina.com> In-Reply-To: <6992e4aa.a70a0220.2c38d7.00e9.GAE@google.com> References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit > Date: Mon, 16 Feb 2026 01:34:34 -0800 [thread overview] > syzbot has found a reproducer for the following issue on: > > HEAD commit: c22e26bd0906 Merge tag 'landlock-7.0-rc1' of git://git.ker.. > git tree: upstream > console output: https://syzkaller.appspot.com/x/log.txt?x=16bcf6e6580000 > kernel config: https://syzkaller.appspot.com/x/.config?x=6428d17febdfb14e > dashboard link: https://syzkaller.appspot.com/bug?extid=ae466a728017ec940b41 > compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15ce3652580000 > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1121515a580000 #syz test --- x/drivers/media/dvb-core/dvb_frontend.c +++ y/drivers/media/dvb-core/dvb_frontend.c @@ -2911,6 +2911,8 @@ static int dvb_frontend_release(struct i mb(); } + dvb_device_get(dvbdev); // for removing dev + dvb_device_get(dvbdev); // for releasing dev ret = dvb_generic_release(inode, file); if (dvbdev->users == -1) { @@ -2931,6 +2933,8 @@ static int dvb_frontend_release(struct i fe->ops.ts_bus_ctrl(fe, 0); } + dvb_remove_device(dvbdev); + dvb_device_put(dvbdev); dvb_frontend_put(fe); return ret; --