kernel BUG in vhost_get_vq_desc

5 views
Skip to first unread message

syzbot

unread,
Aug 22, 2022, 9:56:36 PM8/22/22
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=15f0ac47080000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=08137bebdd5e8db5de18
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+08137b...@syzkaller.appspotmail.com

netlink: 20 bytes leftover after parsing attributes in process `syz-executor.4'.
netlink: 20 bytes leftover after parsing attributes in process `syz-executor.4'.
netlink: 20 bytes leftover after parsing attributes in process `syz-executor.4'.
------------[ cut here ]------------
kernel BUG at drivers/vhost/vhost.c:2247!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 12717 Comm: vhost-12714 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/22/2022
RIP: 0010:vhost_get_vq_desc+0x1d52/0x22c0 drivers/vhost/vhost.c:2247
Code: 00 00 00 48 c7 c6 80 20 3d 89 48 c7 c7 b0 4b 22 8b 48 89 ca 48 c1 e1 04 48 01 d9 e8 38 06 60 fd e9 74 ff ff ff e8 6e 0e 3b fb <0f> 0b e8 67 0e 3b fb 44 89 e2 b9 10 00 00 00 48 c7 c6 80 1e 3d 89
RSP: 0018:ffff88808f86fb30 EFLAGS: 00010293
RAX: ffff88804d8ee3c0 RBX: 0000000000000001 RCX: ffffffff862767f7
RDX: 0000000000000000 RSI: ffffffff86277702 RDI: 0000000000000003
RBP: 0000000000000000 R08: 0000000000000400 R09: 0000000000000000
R10: 0000000000000003 R11: 0000000000000000 R12: 000000000000008b
R13: 0000000000000001 R14: dffffc0000000000 R15: ffff88804996f6a8
FS: 0000000000000000(0000) GS:ffff8880ba100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2fc24000 CR3: 000000009e957000 CR4: 00000000003406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
vhost_vsock_handle_tx_kick+0x202/0xa30 drivers/vhost/vsock.c:460
vhost_worker+0x293/0x480 drivers/vhost/vhost.c:362
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
Modules linked in:
---[ end trace 5a41d81d8eb779a4 ]---
RIP: 0010:vhost_get_vq_desc+0x1d52/0x22c0 drivers/vhost/vhost.c:2247
Code: 00 00 00 48 c7 c6 80 20 3d 89 48 c7 c7 b0 4b 22 8b 48 89 ca 48 c1 e1 04 48 01 d9 e8 38 06 60 fd e9 74 ff ff ff e8 6e 0e 3b fb <0f> 0b e8 67 0e 3b fb 44 89 e2 b9 10 00 00 00 48 c7 c6 80 1e 3d 89
RSP: 0018:ffff88808f86fb30 EFLAGS: 00010293
RAX: ffff88804d8ee3c0 RBX: 0000000000000001 RCX: ffffffff862767f7
RDX: 0000000000000000 RSI: ffffffff86277702 RDI: 0000000000000003
RBP: 0000000000000000 R08: 0000000000000400 R09: 0000000000000000
R10: 0000000000000003 R11: 0000000000000000 R12: 000000000000008b
R13: 0000000000000001 R14: dffffc0000000000 R15: ffff88804996f6a8
FS: 0000000000000000(0000) GS:ffff8880ba000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1d9f34e2e0 CR3: 000000009e957000 CR4: 00000000003406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Feb 27, 2023, 8:46:33 PM2/27/23
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages