general protection fault in reset_buffer_flags

5 views
Skip to first unread message

syzbot

unread,
Apr 10, 2019, 12:14:08 PM4/10/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: d33692e8 Merge 4.14.74 into android-4.14
git tree: android-4.14
console output: https://syzkaller.appspot.com/x/log.txt?x=105e0e3a400000
kernel config: https://syzkaller.appspot.com/x/.config?x=decf36ad71cd0a75
dashboard link: https://syzkaller.appspot.com/bug?extid=bee4eb38cf90371a5dd6
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14634bb9400000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+bee4eb...@syzkaller.appspotmail.com

pts pts2216: tty_release: tty->count(2) != (#fd's(1) + #kopen's(0))
pts pts2217: tty_release: tty->count(2) != (#fd's(1) + #kopen's(0))
pts pts2218: tty_release: tty->count(2) != (#fd's(1) + #kopen's(0))
kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] PREEMPT SMP KASAN NOPTI
Modules linked in:
CPU: 0 PID: 8983 Comm: syz-executor0 Not tainted 4.14.74+ #17
task: ffff8801ccdbde00 task.stack: ffff8801ca2f8000
RIP: 0010:reset_buffer_flags+0x21/0x150 drivers/tty/n_tty.c:323
RSP: 0018:ffff8801ca2ff8e0 EFLAGS: 00010202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 000000000000044c RSI: ffff8801ccdbe680 RDI: 0000000000002260
RBP: ffff8801ca21a200 R08: 0000000000002adc R09: ffffffffb4ad9d80
R10: ffff8801ccdbe680 R11: 0000000000000001 R12: ffff8801ca21a438
R13: ffff8801ca2ff938 R14: ffff8801cf2774e0 R15: 0000000000000007
FS: 00007f25ab6e9700(0000) GS:ffff8801d7600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000072c000 CR3: 00000001ccd00006 CR4: 00000000001606b0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
n_tty_flush_buffer+0x49/0xeb drivers/tty/n_tty.c:361
set_termios+0x259/0x440 drivers/tty/tty_ioctl.c:403
tty_mode_ioctl+0x6ad/0x920 drivers/tty/tty_ioctl.c:776
n_tty_ioctl_helper+0x3f/0x350 drivers/tty/tty_ioctl.c:939
n_tty_ioctl+0x43/0x2e0 drivers/tty/n_tty.c:2452
tty_ioctl+0x551/0x13e0 drivers/tty/tty_io.c:2654
vfs_ioctl fs/ioctl.c:46 [inline]
file_ioctl fs/ioctl.c:500 [inline]
do_vfs_ioctl+0x1a0/0x1030 fs/ioctl.c:684
SYSC_ioctl fs/ioctl.c:701 [inline]
SyS_ioctl+0x7e/0xb0 fs/ioctl.c:692
do_syscall_64+0x19b/0x4b0 arch/x86/entry/common.c:289
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x457579
RSP: 002b:00007f25ab6e8c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000457579
RDX: 0000000020000040 RSI: 0000000000005408 RDI: 0000000000000006
RBP: 000000000072bf00 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f25ab6e96d4
R13: 00000000004c0d8f R14: 00000000004d1788 R15: 00000000ffffffff
Code: 41 ff 5b 5d e9 31 bb 5e ff 90 53 48 89 fb e8 27 bb 5e ff 48 8d bb 60
22 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00
0f 85 0f 01 00 00 48 c7 83 60 22 00 00 00 00 00 00
RIP: reset_buffer_flags+0x21/0x150 drivers/tty/n_tty.c:323 RSP:
ffff8801ca2ff8e0
pts pts2219: tty_release: tty->count(2) != (#fd's(1) + #kopen's(0))
---[ end trace bbef0c1ebc324471 ]---


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages