panic: in_pcb_lport: laddrp NULL for v4 inp ADDR

9 views
Skip to first unread message

syzbot

unread,
Jun 3, 2019, 9:41:05 AM6/3/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: c7cdb4a8 Another partial revert of r301289.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=143c685aa00000
dashboard link: https://syzkaller.appspot.com/bug?extid=2609a378d89264ff5a42

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2609a3...@syzkaller.appspotmail.com

panic: in_pcb_lport: laddrp NULL for v4 inp 0xfffff8000b3c25b8
cpuid = 1
time = 39
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0020dee660
vpanic() at vpanic+0x1e0/frame 0xfffffe0020dee6c0
panic() at panic+0x43/frame 0xfffffe0020dee720
in_pcb_lport() at in_pcb_lport+0x4c7/frame 0xfffffe0020dee7b0
in6_pcbsetport() at in6_pcbsetport+0xc3/frame 0xfffffe0020dee7f0
in6_pcbbind() at in6_pcbbind+0x26a/frame 0xfffffe0020dee8a0
tcp6_usr_listen() at tcp6_usr_listen+0x176/frame 0xfffffe0020dee900
solisten() at solisten+0x7a/frame 0xfffffe0020dee940
kern_listen() at kern_listen+0x132/frame 0xfffffe0020dee980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0020deeab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0020deeab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x41311a, rsp =
0x7fffdfffdf38, rbp = 0x2 ---
KDB: enter: panic
[ thread pid 34300 tid 100440 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jun 3, 2019, 10:00:05 AM6/3/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: c7cdb4a8 Another partial revert of r301289.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17c8d0f2a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=2609a378d89264ff5a42
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17229e36a00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=142b920ea00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2609a3...@syzkaller.appspotmail.com

login: panic: in_pcb_lport: laddrp NULL for v4 inp 0xfffff8000b33e988
cpuid = 0
time = 1559570156
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001f695660
vpanic() at vpanic+0x1e0/frame 0xfffffe001f6956c0
panic() at panic+0x43/frame 0xfffffe001f695720
in_pcb_lport() at in_pcb_lport+0x4c7/frame 0xfffffe001f6957b0
in6_pcbsetport() at in6_pcbsetport+0xc3/frame 0xfffffe001f6957f0
in6_pcbbind() at in6_pcbbind+0x26a/frame 0xfffffe001f6958a0
tcp6_usr_listen() at tcp6_usr_listen+0x176/frame 0xfffffe001f695900
solisten() at solisten+0x7a/frame 0xfffffe001f695940
kern_listen() at kern_listen+0x132/frame 0xfffffe001f695980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001f695ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001f695ab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x458a4a, rsp =
0x7fffdffdcf88, rbp = 0x6b72c0 ---
KDB: enter: panic
[ thread pid 759 tid 100104 ]
Reply all
Reply to author
Forward
0 new messages