[Android 5.15] KASAN: use-after-free Write in igrab

3 views
Skip to first unread message

syzbot

unread,
Dec 23, 2023, 1:24:25 PM12/23/23
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 28e3f5851a99 Revert "HID: core: store the unique system id..
git tree: android13-5.15-lts
console+strace: https://syzkaller.appspot.com/x/log.txt?x=12321111e80000
kernel config: https://syzkaller.appspot.com/x/.config?x=77b14bc9a56d2541
dashboard link: https://syzkaller.appspot.com/bug?extid=2d747cdee917b5e40432
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1143739ee80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1036c111e80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/ae34678aaf41/disk-28e3f585.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ce3daedc6cc4/vmlinux-28e3f585.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ced16d9f3bc0/bzImage-28e3f585.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/f9e6a6d495c2/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2d747c...@syzkaller.appspotmail.com

R10: 000000000001063a R11: 0000000000000246 R12: 00007fd6a9115390
R13: 0000000000000000 R14: 00007fd6a9116100 R15: 00007fd6a9057ce0
</TASK>
---[ end trace ff080d703fec6b03 ]---
==================================================================
BUG: KASAN: use-after-free in instrument_atomic_read_write include/linux/instrumented.h:101 [inline]
BUG: KASAN: use-after-free in atomic_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:511 [inline]
BUG: KASAN: use-after-free in queued_spin_lock include/asm-generic/qspinlock.h:82 [inline]
BUG: KASAN: use-after-free in do_raw_spin_lock include/linux/spinlock.h:187 [inline]
BUG: KASAN: use-after-free in __raw_spin_lock include/linux/spinlock_api_smp.h:143 [inline]
BUG: KASAN: use-after-free in _raw_spin_lock+0x97/0x1b0 kernel/locking/spinlock.c:154
Write of size 4 at addr ffff8881091b8698 by task syz-executor140/296

CPU: 0 PID: 296 Comm: syz-executor140 Tainted: G W 5.15.141-syzkaller-00899-g28e3f5851a99 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x151/0x1b7 lib/dump_stack.c:106
print_address_description+0x87/0x3b0 mm/kasan/report.c:248
__kasan_report mm/kasan/report.c:427 [inline]
kasan_report+0x179/0x1c0 mm/kasan/report.c:444
kasan_check_range+0x293/0x2a0 mm/kasan/generic.c:189
__kasan_check_write+0x14/0x20 mm/kasan/shadow.c:37
instrument_atomic_read_write include/linux/instrumented.h:101 [inline]
atomic_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:511 [inline]
queued_spin_lock include/asm-generic/qspinlock.h:82 [inline]
do_raw_spin_lock include/linux/spinlock.h:187 [inline]
__raw_spin_lock include/linux/spinlock_api_smp.h:143 [inline]
_raw_spin_lock+0x97/0x1b0 kernel/locking/spinlock.c:154
spin_lock include/linux/spinlock.h:363 [inline]
igrab+0x20/0xa0 fs/inode.c:1346
f2fs_sync_inode_meta+0x14d/0x2a0 fs/f2fs/checkpoint.c:1157
block_operations fs/f2fs/checkpoint.c:1265 [inline]
f2fs_write_checkpoint+0xab4/0x1fb0 fs/f2fs/checkpoint.c:1659
f2fs_issue_checkpoint+0x31b/0x4d0
f2fs_sync_fs+0x186/0x2f0 fs/f2fs/super.c:1695
sync_filesystem+0x1cf/0x250 fs/sync.c:66
f2fs_quota_off_umount+0x20e/0x220 fs/f2fs/super.c:2896
f2fs_put_super+0xb9/0xc10 fs/f2fs/super.c:1582
generic_shutdown_super+0x157/0x2e0 fs/super.c:475
kill_block_super+0x7e/0xe0 fs/super.c:1414
kill_f2fs_super+0x2f9/0x3c0 fs/f2fs/super.c:4610
deactivate_locked_super+0xad/0x110 fs/super.c:335
deactivate_super+0xbe/0xf0 fs/super.c:366
cleanup_mnt+0x45c/0x510 fs/namespace.c:1143
__cleanup_mnt+0x19/0x20 fs/namespace.c:1150
task_work_run+0x129/0x190 kernel/task_work.c:164
exit_task_work include/linux/task_work.h:32 [inline]
do_exit+0xc48/0x2ca0 kernel/exit.c:878
do_group_exit+0x141/0x310 kernel/exit.c:1000
__do_sys_exit_group kernel/exit.c:1011 [inline]
__se_sys_exit_group kernel/exit.c:1009 [inline]
__x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1009
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x61/0xcb
RIP: 0033:0x7fd6a9089a09
Code: Unable to access opcode bytes at RIP 0x7fd6a90899df.
RSP: 002b:00007ffeda018d88 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007fd6a9089a09
RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000001
RBP: 00007fd6a9115390 R08: ffffffffffffffb8 R09: 00007ffeda018e60
R10: 000000000001063a R11: 0000000000000246 R12: 00007fd6a9115390
R13: 0000000000000000 R14: 00007fd6a9116100 R15: 00007fd6a9057ce0
</TASK>

Allocated by task 296:
kasan_save_stack mm/kasan/common.c:38 [inline]
kasan_set_track mm/kasan/common.c:45 [inline]
set_alloc_info mm/kasan/common.c:433 [inline]
__kasan_slab_alloc+0xb1/0xe0 mm/kasan/common.c:466
kasan_slab_alloc include/linux/kasan.h:217 [inline]
slab_post_alloc_hook+0x53/0x2c0 mm/slab.h:550
slab_alloc_node mm/slub.c:3240 [inline]
slab_alloc mm/slub.c:3248 [inline]
kmem_cache_alloc+0xf5/0x200 mm/slub.c:3253
f2fs_kmem_cache_alloc fs/f2fs/f2fs.h:2795 [inline]
f2fs_alloc_inode+0x26/0x340 fs/f2fs/super.c:1406
alloc_inode fs/inode.c:236 [inline]
iget_locked+0x174/0x860 fs/inode.c:1244
f2fs_iget+0x55/0x4de0 fs/f2fs/inode.c:489
f2fs_lookup+0x410/0xd80 fs/f2fs/namei.c:551
lookup_open fs/namei.c:3370 [inline]
open_last_lookups fs/namei.c:3462 [inline]
path_openat+0x1194/0x2f40 fs/namei.c:3669
do_filp_open+0x21c/0x460 fs/namei.c:3699
do_sys_openat2+0x13f/0x830 fs/open.c:1234
do_sys_open fs/open.c:1250 [inline]
__do_sys_open fs/open.c:1258 [inline]
__se_sys_open fs/open.c:1254 [inline]
__x64_sys_open+0x221/0x270 fs/open.c:1254
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x61/0xcb

Freed by task 296:
kasan_save_stack mm/kasan/common.c:38 [inline]
kasan_set_track+0x4b/0x70 mm/kasan/common.c:45
kasan_set_free_info+0x23/0x40 mm/kasan/generic.c:370
____kasan_slab_free+0x126/0x160 mm/kasan/common.c:365
__kasan_slab_free+0x11/0x20 mm/kasan/common.c:373
kasan_slab_free include/linux/kasan.h:193 [inline]
slab_free_hook mm/slub.c:1723 [inline]
slab_free_freelist_hook+0xbd/0x190 mm/slub.c:1749
slab_free mm/slub.c:3519 [inline]
kmem_cache_free+0x116/0x2e0 mm/slub.c:3535
f2fs_free_inode+0x24/0x30 fs/f2fs/super.c:1550
i_callback+0x4b/0x70 fs/inode.c:225
rcu_do_batch+0x57a/0xc10 kernel/rcu/tree.c:2523
rcu_core+0x517/0x1020 kernel/rcu/tree.c:2763
rcu_core_si+0x9/0x10 kernel/rcu/tree.c:2776
__do_softirq+0x26d/0x5bf kernel/softirq.c:565

Last potentially related work creation:
kasan_save_stack+0x3b/0x60 mm/kasan/common.c:38
__kasan_record_aux_stack+0xd3/0xf0 mm/kasan/generic.c:348
kasan_record_aux_stack_noalloc+0xb/0x10 mm/kasan/generic.c:358
__call_rcu kernel/rcu/tree.c:3007 [inline]
call_rcu+0x133/0x12a0 kernel/rcu/tree.c:3087
destroy_inode fs/inode.c:291 [inline]
evict+0x5df/0x630 fs/inode.c:602
dispose_list fs/inode.c:620 [inline]
evict_inodes+0x5db/0x660 fs/inode.c:670
generic_shutdown_super+0x9c/0x2e0 fs/super.c:454
kill_block_super+0x7e/0xe0 fs/super.c:1414
kill_f2fs_super+0x2f9/0x3c0 fs/f2fs/super.c:4610
deactivate_locked_super+0xad/0x110 fs/super.c:335
deactivate_super+0xbe/0xf0 fs/super.c:366
cleanup_mnt+0x45c/0x510 fs/namespace.c:1143
__cleanup_mnt+0x19/0x20 fs/namespace.c:1150
task_work_run+0x129/0x190 kernel/task_work.c:164
exit_task_work include/linux/task_work.h:32 [inline]
do_exit+0xc48/0x2ca0 kernel/exit.c:878
do_group_exit+0x141/0x310 kernel/exit.c:1000
__do_sys_exit_group kernel/exit.c:1011 [inline]
__se_sys_exit_group kernel/exit.c:1009 [inline]
__x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1009
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x61/0xcb

The buggy address belongs to the object at ffff8881091b8610
which belongs to the cache f2fs_inode_cache of size 1424
The buggy address is located 136 bytes inside of
1424-byte region [ffff8881091b8610, ffff8881091b8ba0)
The buggy address belongs to the page:
page:ffffea0004246e00 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1091b8
head:ffffea0004246e00 order:3 compound_mapcount:0 compound_pincount:0
flags: 0x4000000000010200(slab|head|zone=1)
raw: 4000000000010200 0000000000000000 dead000000000122 ffff888103d99200
raw: 0000000000000000 0000000080150015 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 3, migratetype Reclaimable, gfp_mask 0xd2050(__GFP_IO|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC|__GFP_RECLAIMABLE), pid 296, ts 23856839949, free_ts 0
set_page_owner include/linux/page_owner.h:33 [inline]
post_alloc_hook+0x1a3/0x1b0 mm/page_alloc.c:2604
prep_new_page+0x1b/0x110 mm/page_alloc.c:2610
get_page_from_freelist+0x3550/0x35d0 mm/page_alloc.c:4484
__alloc_pages+0x27e/0x8f0 mm/page_alloc.c:5776
allocate_slab mm/slub.c:1932 [inline]
new_slab+0x9a/0x4e0 mm/slub.c:1995
___slab_alloc+0x39e/0x830 mm/slub.c:3028
__slab_alloc+0x4a/0x90 mm/slub.c:3115
slab_alloc_node mm/slub.c:3206 [inline]
slab_alloc mm/slub.c:3248 [inline]
kmem_cache_alloc+0x134/0x200 mm/slub.c:3253
f2fs_kmem_cache_alloc fs/f2fs/f2fs.h:2795 [inline]
f2fs_alloc_inode+0x26/0x340 fs/f2fs/super.c:1406
alloc_inode fs/inode.c:236 [inline]
iget_locked+0x174/0x860 fs/inode.c:1244
f2fs_iget+0x55/0x4de0 fs/f2fs/inode.c:489
f2fs_lookup+0x410/0xd80 fs/f2fs/namei.c:551
lookup_open fs/namei.c:3370 [inline]
open_last_lookups fs/namei.c:3462 [inline]
path_openat+0x1194/0x2f40 fs/namei.c:3669
do_filp_open+0x21c/0x460 fs/namei.c:3699
do_sys_openat2+0x13f/0x830 fs/open.c:1234
do_sys_open fs/open.c:1250 [inline]
__do_sys_open fs/open.c:1258 [inline]
__se_sys_open fs/open.c:1254 [inline]
__x64_sys_open+0x221/0x270 fs/open.c:1254
page_owner free stack trace missing

Memory state around the buggy address:
ffff8881091b8580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
ffff8881091b8600: fc fc fa fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff8881091b8680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
^
ffff8881091b8700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
ffff8881091b8780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages