)]}'
{
  "commit": "ddd7e8b7b84836c584a284b98ca9bd7a348a0558",
  "tree": "c8a21a008907fb45d666bfd2d767c41c39fa31e2",
  "parents": [
    "e07f317d5a289f06b7eb9025d2ada744cf22c940"
  ],
  "author": {
    "name": "Liu Jian",
    "email": "liujian56@huawei.com",
    "time": "Fri Jul 16 12:06:17 2021 +0800"
  },
  "committer": {
    "name": "Greg Kroah-Hartman",
    "email": "gregkh@linuxfoundation.org",
    "time": "Sun Sep 12 08:58:26 2021 +0200"
  },
  "message": "igmp: Add ip_mc_list lock in ip_check_mc_rcu\n\ncommit 23d2b94043ca8835bd1e67749020e839f396a1c2 upstream.\n\nI got below panic when doing fuzz test:\n\nKernel panic - not syncing: panic_on_warn set ...\nCPU: 0 PID: 4056 Comm: syz-executor.3 Tainted: G    B             5.14.0-rc1-00195-gcff5c4254439-dirty #2\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.0-59-gc9ba5276e321-prebuilt.qemu.org 04/01/2014\nCall Trace:\ndump_stack_lvl+0x7a/0x9b\npanic+0x2cd/0x5af\nend_report.cold+0x5a/0x5a\nkasan_report+0xec/0x110\nip_check_mc_rcu+0x556/0x5d0\n__mkroute_output+0x895/0x1740\nip_route_output_key_hash_rcu+0x2d0/0x1050\nip_route_output_key_hash+0x182/0x2e0\nip_route_output_flow+0x28/0x130\nudp_sendmsg+0x165d/0x2280\nudpv6_sendmsg+0x121e/0x24f0\ninet6_sendmsg+0xf7/0x140\nsock_sendmsg+0xe9/0x180\n____sys_sendmsg+0x2b8/0x7a0\n___sys_sendmsg+0xf0/0x160\n__sys_sendmmsg+0x17e/0x3c0\n__x64_sys_sendmmsg+0x9e/0x100\ndo_syscall_64+0x3b/0x90\nentry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x462eb9\nCode: f7 d8 64 89 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 48 89 f8\n 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e\n 3d 01 f0 ff ff 73 01 c3 48 c7 c1 bc ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f3df5af1c58 EFLAGS: 00000246 ORIG_RAX: 0000000000000133\nRAX: ffffffffffffffda RBX: 000000000073bf00 RCX: 0000000000462eb9\nRDX: 0000000000000312 RSI: 0000000020001700 RDI: 0000000000000007\nRBP: 0000000000000004 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007f3df5af26bc\nR13: 00000000004c372d R14: 0000000000700b10 R15: 00000000ffffffff\n\nIt is one use-after-free in ip_check_mc_rcu.\nIn ip_mc_del_src, the ip_sf_list of pmc has been freed under pmc-\u003elock protection.\nBut access to ip_sf_list in ip_check_mc_rcu is not protected by the lock.\n\nSigned-off-by: Liu Jian \u003cliujian56@huawei.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Lee Jones \u003clee.jones@linaro.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "00576bae183d30518e376ad3846d4fe6025aaea7",
      "old_mode": 33188,
      "old_path": "net/ipv4/igmp.c",
      "new_id": "0c321996c6eb0f20801a81a7ff9d2b134c0453bc",
      "new_mode": 33188,
      "new_path": "net/ipv4/igmp.c"
    }
  ]
}
