panic: Duplicate free of ADDR from zone ADDR(16) slab ADDR(241)

6 views
Skip to first unread message

syzbot

unread,
May 15, 2019, 3:41:08 PM5/15/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: dfdde018 LinuxKPI: Add get_random_u32 function.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10735522a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=b1fa5f317601296c2224

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b1fa5f...@syzkaller.appspotmail.com

panic: Duplicate free of 0xfffff8000445af10 from zone
0xfffff80004021000(16) slab 0xfffff8000445af90(241)

cpuid = 1
time = 22
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00269d56b0
vpanic() at vpanic+0x1e0/frame 0xfffffe00269d5710
panic() at panic+0x43/frame 0xfffffe00269d5770
uma_dbg_free() at uma_dbg_free+0x246/frame 0xfffffe00269d57c0
uma_zfree_arg() at uma_zfree_arg+0x1c1/frame 0xfffffe00269d5850
free() at free+0xed/frame 0xfffffe00269d5890
nfsrv_nfsuserdport() at nfsrv_nfsuserdport+0x1f9/frame 0xfffffe00269d58c0
nfssvc_nfscommon() at nfssvc_nfscommon+0x97f/frame 0xfffffe00269d5950
sys_nfssvc() at sys_nfssvc+0x133/frame 0xfffffe00269d5980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00269d5ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00269d5ab0
--- syscall (155, FreeBSD ELF64, sys_nfssvc), rip = 0x2000028d, rsp =
0x7fffdfffdeb8, rbp = 0xa ---
KDB: enter: panic
[ thread pid 6974 tid 100340 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 25, 2019, 4:48:06 AM10/25/19
to syzkaller-f...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages