Fatal trap 9: general protection fault in sctp_copy_skeylist

8 views
Skip to first unread message

syzbot

unread,
Jun 6, 2019, 3:44:06 PM6/6/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: f6eb4393 Add myself (arrowd) to calendar.freebsd.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11ac3d86a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=08a486f7e6966f1c3cfb

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+08a486...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 1; apic id = 01
instruction pointer = 0x20:0xffffffff812c1d3c
stack pointer = 0x28:0xfffffe0020e45780
frame pointer = 0x28:0xfffffe0020e457c0
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 42096 (syz-executor.0)
trap number = 9
panic: general protection fault
cpuid = 1
time = 69
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0020e45450
vpanic() at vpanic+0x1e0/frame 0xfffffe0020e454b0
panic() at panic+0x43/frame 0xfffffe0020e45510
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0020e45590
trap() at trap+0xba/frame 0xfffffe0020e456b0
calltrap() at calltrap+0x8/frame 0xfffffe0020e456b0
--- trap 0x9, rip = 0xffffffff812c1d3c, rsp = 0xfffffe0020e45780, rbp =
0xfffffe0020e457c0 ---
sctp_copy_skeylist() at sctp_copy_skeylist+0x8c/frame 0xfffffe0020e457c0
sctp_initialize_auth_params() at sctp_initialize_auth_params+0x319/frame
0xfffffe0020e45820
sctp_connect() at sctp_connect+0x4a6/frame 0xfffffe0020e45880
soconnectat() at soconnectat+0x183/frame 0xfffffe0020e458e0
kern_connectat() at kern_connectat+0x1ff/frame 0xfffffe0020e45940
sys_connect() at sys_connect+0xd9/frame 0xfffffe0020e45980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0020e45ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0020e45ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x4131ba, rsp =
0x7fffdfffdf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 42096 tid 100852 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jun 6, 2019, 4:10:06 PM6/6/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: f6eb4393 Add myself (arrowd) to calendar.freebsd.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=14ed7a2ea00000
dashboard link: https://syzkaller.appspot.com/bug?extid=08a486f7e6966f1c3cfb
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1686a74aa00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+08a486...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 0; apic id = 00
instruction pointer = 0x20:0xffffffff812c1d3c
stack pointer = 0x28:0xfffffe0020ec7780
frame pointer = 0x28:0xfffffe0020ec77c0
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 869 (syz-executor.0)
trap number = 9
panic: general protection fault
cpuid = 0
time = 1559851433
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0020ec7450
vpanic() at vpanic+0x1e0/frame 0xfffffe0020ec74b0
panic() at panic+0x43/frame 0xfffffe0020ec7510
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0020ec7590
trap() at trap+0xba/frame 0xfffffe0020ec76b0
calltrap() at calltrap+0x8/frame 0xfffffe0020ec76b0
--- trap 0x9, rip = 0xffffffff812c1d3c, rsp = 0xfffffe0020ec7780, rbp =
0xfffffe0020ec77c0 ---
sctp_copy_skeylist() at sctp_copy_skeylist+0x8c/frame 0xfffffe0020ec77c0
sctp_initialize_auth_params() at sctp_initialize_auth_params+0x319/frame
0xfffffe0020ec7820
sctp_connect() at sctp_connect+0x4a6/frame 0xfffffe0020ec7880
soconnectat() at soconnectat+0x183/frame 0xfffffe0020ec78e0
kern_connectat() at kern_connectat+0x1ff/frame 0xfffffe0020ec7940
sys_connect() at sys_connect+0xd9/frame 0xfffffe0020ec7980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0020ec7ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0020ec7ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x4131ba, rsp =
0x7fffdfffdf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 869 tid 100176 ]
Reply all
Reply to author
Forward
0 new messages