Fatal trap 9: general protection fault in udp6_common_ctlinput

4 views
Skip to first unread message

syzbot

unread,
Aug 23, 2019, 1:10:07 AM8/23/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 83d64190 When we have errors resetting the device before w..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=171dbcb6600000
dashboard link: https://syzkaller.appspot.com/bug?extid=87ebdac00a7efe8c1209

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+87ebda...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 1; apic id = 01
instruction pointer = 0x20:0xffffffff8143a9a2
stack pointer = 0x28:0xfffffe001f5dd5f0
frame pointer = 0x28:0xfffffe001f5dd650
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 1585 (ifconfig)
trap number = 9
panic: general protection fault
cpuid = 1
time = 1566536992
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001f5dd2c0
vpanic() at vpanic+0x1e0/frame 0xfffffe001f5dd320
panic() at panic+0x43/frame 0xfffffe001f5dd380
trap_fatal() at trap_fatal+0x4de/frame 0xfffffe001f5dd400
trap() at trap+0xba/frame 0xfffffe001f5dd520
calltrap() at calltrap+0x8/frame 0xfffffe001f5dd520
--- trap 0x9, rip = 0xffffffff8143a9a2, rsp = 0xfffffe001f5dd5f0, rbp =
0xfffffe001f5dd650 ---
udp6_common_ctlinput() at udp6_common_ctlinput+0x22/frame 0xfffffe001f5dd650
pfctlinput() at pfctlinput+0x73/frame 0xfffffe001f5dd690
if_up() at if_up+0x62/frame 0xfffffe001f5dd6d0
ifhwioctl() at ifhwioctl+0x1385/frame 0xfffffe001f5dd760
ifioctl() at ifioctl+0x5d0/frame 0xfffffe001f5dd840
kern_ioctl() at kern_ioctl+0x465/frame 0xfffffe001f5dd8b0
sys_ioctl() at sys_ioctl+0x267/frame 0xfffffe001f5dd980
amd64_syscall() at amd64_syscall+0x479/frame 0xfffffe001f5ddab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001f5ddab0
--- syscall (54, FreeBSD ELF64, sys_ioctl), rip = 0x8004882ca, rsp =
0x7fffffffe408, rbp = 0x7fffffffe460 ---
KDB: enter: panic
[ thread pid 1585 tid 100076 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Nov 21, 2019, 12:10:05 AM11/21/19
to syzkaller-f...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages