panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/kern/uipc_sockbuf.c:LINE

2 views
Skip to first unread message

syzbot

unread,
May 4, 2019, 11:45:06 PM5/4/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 58510286 arm64: Properly restore PAN when done with usersp..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1756a348a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=739444d532c4df2cc827

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+739444...@syzkaller.appspotmail.com

panic: mtx_lock() of spin mutex (null) @
/syzkaller/managers/main/kernel/sys/kern/uipc_sockbuf.c:252
cpuid = 0
time = 36
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0016ad95b0
vpanic() at vpanic+0x1e0/frame 0xfffffe0016ad9610
panic() at panic+0x43/frame 0xfffffe0016ad9670
__mtx_lock_flags() at __mtx_lock_flags+0x1fd/frame 0xfffffe0016ad96d0
socantrcvmore() at socantrcvmore+0x2c/frame 0xfffffe0016ad96f0
sctp_notify_assoc_change() at sctp_notify_assoc_change+0x5c9/frame
0xfffffe0016ad9770
sctp_abort_an_association() at sctp_abort_an_association+0xff/frame
0xfffffe0016ad97b0
sctp_threshold_management() at sctp_threshold_management+0x30d/frame
0xfffffe0016ad9810
sctp_t1init_timer() at sctp_t1init_timer+0x82/frame 0xfffffe0016ad9850
sctp_timeout_handler() at sctp_timeout_handler+0x8f1/frame
0xfffffe0016ad98e0
softclock_call_cc() at softclock_call_cc+0x1dd/frame 0xfffffe0016ad99b0
softclock() at softclock+0xa3/frame 0xfffffe0016ad99f0
ithread_loop() at ithread_loop+0x2f2/frame 0xfffffe0016ad9a60
fork_exit() at fork_exit+0xb0/frame 0xfffffe0016ad9ab0
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0016ad9ab0
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 12 tid 100018 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 16, 2019, 8:32:07 PM10/16/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 7c87e295 Update some comments; no functional changes. Som..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=125bb173600000
dashboard link: https://syzkaller.appspot.com/bug?extid=739444d532c4df2cc827
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1434b57f600000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+739444...@syzkaller.appspotmail.com

login: panic: mtx_lock() of spin mutex (null) @
/syzkaller/managers/main/kernel/sys/kern/uipc_sockbuf.c:360
cpuid = 0
time = 1571272035
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001a162fe0
vpanic() at vpanic+0x1c7/frame 0xfffffe001a163050
panic() at panic+0x43/frame 0xfffffe001a1630b0
__mtx_lock_flags() at __mtx_lock_flags+0x203/frame 0xfffffe001a163110
socantrcvmore() at socantrcvmore+0x2c/frame 0xfffffe001a163130
sctp_notify_assoc_change() at sctp_notify_assoc_change+0x5b8/frame
0xfffffe001a1631a0
sctp_process_control() at sctp_process_control+0x8622/frame
0xfffffe001a163610
sctp_common_input_processing() at sctp_common_input_processing+0x751/frame
0xfffffe001a1637a0
sctp_input_with_port() at sctp_input_with_port+0x301/frame
0xfffffe001a163890
sctp_input() at sctp_input+0x1f/frame 0xfffffe001a1638b0
ip_input() at ip_input+0x2df/frame 0xfffffe001a163950
swi_net() at swi_net+0x21d/frame 0xfffffe001a1639f0
ithread_loop() at ithread_loop+0x2f2/frame 0xfffffe001a163a60
fork_exit() at fork_exit+0xac/frame 0xfffffe001a163ab0
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe001a163ab0
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 12 tid 100020 ]
Stopped at kdb_enter+0x67: movq $0,0x14776c6(%rip)

Mark Johnston

unread,
Sep 7, 2021, 5:51:40 PM9/7/21
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:LINE
Reply all
Reply to author
Forward
0 new messages