Hello,
syzbot found the following issue on:
HEAD commit: a507f147e6f0 Linux 6.1.70
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=10990a09e80000
kernel config:
https://syzkaller.appspot.com/x/.config?x=374c4f371d017411
dashboard link:
https://syzkaller.appspot.com/bug?extid=60eed284973197052313
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/941b73df0eaf/disk-a507f147.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/37f3d867ad6f/vmlinux-a507f147.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/aeb318de7a8d/bzImage-a507f147.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+60eed2...@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: slab-out-of-bounds in dns_resolver_preparse+0xcaf/0xd20 net/dns_resolver/dns_key.c:127
Read of size 1 at addr ffff888074b4db44 by task syz-executor.3/19807
CPU: 1 PID: 19807 Comm: syz-executor.3 Not tainted 6.1.70-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
print_address_description mm/kasan/report.c:284 [inline]
print_report+0x15f/0x4f0 mm/kasan/report.c:395
kasan_report+0x136/0x160 mm/kasan/report.c:495
dns_resolver_preparse+0xcaf/0xd20 net/dns_resolver/dns_key.c:127
key_create_or_update+0x47b/0xbf0 security/keys/key.c:861
__do_sys_add_key security/keys/keyctl.c:134 [inline]
__se_sys_add_key+0x33b/0x480 security/keys/keyctl.c:74
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7efe31a7cce9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007efe3289f0c8 EFLAGS: 00000246 ORIG_RAX: 00000000000000f8
RAX: ffffffffffffffda RBX: 00007efe31b9bf80 RCX: 00007efe31a7cce9
RDX: 0000000020000080 RSI: 0000000000000000 RDI: 00000000200003c0
RBP: 00007efe31ac947a R08: 000000000238251f R09: 0000000000000000
R10: 0000000000000004 R11: 0000000000000246 R12: 0000000000000000
R13: 000000000000000b R14: 00007efe31b9bf80 R15: 00007ffd6ea6df68
</TASK>
Allocated by task 19807:
kasan_save_stack mm/kasan/common.c:45 [inline]
kasan_set_track+0x4b/0x70 mm/kasan/common.c:52
____kasan_kmalloc mm/kasan/common.c:374 [inline]
__kasan_kmalloc+0x97/0xb0 mm/kasan/common.c:383
kasan_kmalloc include/linux/kasan.h:211 [inline]
__do_kmalloc_node mm/slab_common.c:955 [inline]
__kmalloc_node+0xb3/0x230 mm/slab_common.c:962
kmalloc_node include/linux/slab.h:579 [inline]
kvmalloc_node+0x6e/0x180 mm/util.c:581
kvmalloc include/linux/slab.h:706 [inline]
__do_sys_add_key security/keys/keyctl.c:116 [inline]
__se_sys_add_key+0x26c/0x480 security/keys/keyctl.c:74
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x63/0xcd
The buggy address belongs to the object at ffff888074b4db40
which belongs to the cache kmalloc-8 of size 8
The buggy address is located 4 bytes inside of
8-byte region [ffff888074b4db40, ffff888074b4db48)
The buggy address belongs to the physical page:
page:ffffea0001d2d340 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x74b4d
flags: 0xfff00000000200(slab|node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000200 ffffea0001ec7680 dead000000000002 ffff888012441280
raw: 0000000000000000 0000000080660066 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 0, migratetype Unmovable, gfp_mask 0x12a20(GFP_ATOMIC|__GFP_NOWARN|__GFP_NORETRY), pid 26, tgid 26 (kworker/1:1), ts 261471784693, free_ts 261467680635
set_page_owner include/linux/page_owner.h:31 [inline]
post_alloc_hook+0x18d/0x1b0 mm/page_alloc.c:2513
prep_new_page mm/page_alloc.c:2520 [inline]
get_page_from_freelist+0x31a1/0x3320 mm/page_alloc.c:4279
__alloc_pages+0x28d/0x770 mm/page_alloc.c:5545
alloc_slab_page+0x6a/0x150 mm/slub.c:1794
allocate_slab mm/slub.c:1939 [inline]
new_slab+0x84/0x2d0 mm/slub.c:1992
___slab_alloc+0xc20/0x1270 mm/slub.c:3180
__slab_alloc mm/slub.c:3279 [inline]
slab_alloc_node mm/slub.c:3364 [inline]
__kmem_cache_alloc_node+0x19f/0x260 mm/slub.c:3437
__do_kmalloc_node mm/slab_common.c:954 [inline]
__kmalloc+0xa1/0x230 mm/slab_common.c:968
kmalloc_array include/linux/slab.h:605 [inline]
kcalloc include/linux/slab.h:636 [inline]
nsim_fib6_event_init drivers/net/netdevsim/fib.c:810 [inline]
nsim_fib6_prepare_event drivers/net/netdevsim/fib.c:947 [inline]
nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1003 [inline]
nsim_fib_event_nb+0x1e3/0x1070 drivers/net/netdevsim/fib.c:1043
notifier_call_chain kernel/notifier.c:87 [inline]
atomic_notifier_call_chain+0x17c/0x2c0 kernel/notifier.c:225
call_fib_notifiers+0x2d/0x60 net/core/fib_notifier.c:35
call_fib6_entry_notifiers net/ipv6/ip6_fib.c:402 [inline]
fib6_add_rt2node net/ipv6/ip6_fib.c:1224 [inline]
fib6_add+0x1b66/0x3c80 net/ipv6/ip6_fib.c:1478
__ip6_ins_rt net/ipv6/route.c:1305 [inline]
ip6_ins_rt+0x102/0x170 net/ipv6/route.c:1315
__ipv6_ifa_notify+0x5bc/0x11d0 net/ipv6/addrconf.c:6169
ipv6_ifa_notify net/ipv6/addrconf.c:6208 [inline]
addrconf_dad_completed+0x17d/0xcb0 net/ipv6/addrconf.c:4224
addrconf_dad_work+0xd8e/0x16b0
page last free stack trace:
reset_page_owner include/linux/page_owner.h:24 [inline]
free_pages_prepare mm/page_alloc.c:1440 [inline]
free_pcp_prepare mm/page_alloc.c:1490 [inline]
free_unref_page_prepare+0xf63/0x1120 mm/page_alloc.c:3358
free_unref_page+0x33/0x3e0 mm/page_alloc.c:3453
free_slab mm/slub.c:2031 [inline]
discard_slab mm/slub.c:2037 [inline]
__unfreeze_partials+0x1b7/0x210 mm/slub.c:2586
put_cpu_partial+0x17b/0x250 mm/slub.c:2662
qlink_free mm/kasan/quarantine.c:168 [inline]
qlist_free_all+0x76/0xe0 mm/kasan/quarantine.c:187
kasan_quarantine_reduce+0x156/0x170 mm/kasan/quarantine.c:294
__kasan_slab_alloc+0x1f/0x70 mm/kasan/common.c:305
kasan_slab_alloc include/linux/kasan.h:201 [inline]
slab_post_alloc_hook+0x52/0x3a0 mm/slab.h:737
slab_alloc_node mm/slub.c:3398 [inline]
kmem_cache_alloc_node+0x136/0x310 mm/slub.c:3443
__alloc_skb+0xde/0x670 net/core/skbuff.c:505
alloc_skb include/linux/skbuff.h:1276 [inline]
alloc_skb_with_frags+0xa4/0x740 net/core/skbuff.c:6154
sock_alloc_send_pskb+0x915/0xa50 net/core/sock.c:2738
sock_alloc_send_skb include/net/sock.h:1907 [inline]
mld_newpack+0x1c0/0xa90 net/ipv6/mcast.c:1748
add_grhead net/ipv6/mcast.c:1851 [inline]
add_grec+0x1492/0x19a0 net/ipv6/mcast.c:1989
mld_send_cr net/ipv6/mcast.c:2115 [inline]
mld_ifc_work+0x68f/0xc90 net/ipv6/mcast.c:2653
process_one_work+0x8a9/0x11d0 kernel/workqueue.c:2292
Memory state around the buggy address:
ffff888074b4da00: fb fc fc fc fc 05 fc fc fc fc 05 fc fc fc fc 05
ffff888074b4da80: fc fc fc fc 06 fc fc fc fc 05 fc fc fc fc fa fc
>ffff888074b4db00: fc fc fc 05 fc fc fc fc 04 fc fc fc fc fa fc fc
^
ffff888074b4db80: fc fc fb fc fc fc fc fb fc fc fc fc fb fc fc fc
ffff888074b4dc00: fc fb fc fc fc fc fa fc fc fc fc fa fc fc fc fc
==================================================================
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup