panic: uma: Freed item ADDR did not belong to zone mbuf_cluster

4 views
Skip to first unread message

syzbot

unread,
Oct 4, 2019, 2:20:07 AM10/4/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 1fc6d3f3 Remove aw_ehci from NOTES to fix LINT kernel buil..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15de1713600000
dashboard link: https://syzkaller.appspot.com/bug?extid=71e41396e31680408286
userspace arch: i386

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+71e413...@syzkaller.appspotmail.com

if_delmpanic: uma: Freed item 0xfffff80045732000 did not belong to zone
mbuf_cluster

cpuid = 1
time = 1570169980
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0022b766b0
vpanic() at vpanic+0x1e0/frame 0xfffffe0022b76710
panic() at panic+0x43/frame 0xfffffe0022b76770
uma_dbg_free() at uma_dbg_free+0x26b/frame 0xfffffe0022b767c0
uma_zfree_arg() at uma_zfree_arg+0x1a2/frame 0xfffffe0022b76850
mb_free_ext() at mb_free_ext+0x24f/frame 0xfffffe0022b76890
freebsd32_sendmsg() at freebsd32_sendmsg+0x6b4/frame 0xfffffe0022b76970
ia32_syscall() at ia32_syscall+0x46a/frame 0xfffffe0022b76ab0
int0x80_syscall_common() at int0x80_syscall_common+0x9c/frame 0x8142fca
KDB: enter: panic
[ thread pid 1576 tid 100678 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jan 2, 2020, 1:20:05 AM1/2/20
to syzkaller-f...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages