[v6.6] WARNING in inet_sock_destruct (2)

0 views
Skip to first unread message

syzbot

unread,
Jan 9, 2026, 7:38:25 PM (2 days ago) Jan 9
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 5fa4793a2d2d Linux 6.6.119
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=125145fa580000
kernel config: https://syzkaller.appspot.com/x/.config?x=691a6769a86ac817
dashboard link: https://syzkaller.appspot.com/bug?extid=c1ff5aa334cbeba54710
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/63699875f1dd/disk-5fa4793a.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/8506652fcb6f/vmlinux-5fa4793a.xz
kernel image: https://storage.googleapis.com/syzbot-assets/1b30ceed1710/bzImage-5fa4793a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c1ff5a...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:155 inet_sock_destruct+0x689/0x7a0 net/ipv4/af_inet.c:155
Modules linked in:
CPU: 0 PID: 16 Comm: ksoftirqd/0 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
RIP: 0010:inet_sock_destruct+0x689/0x7a0 net/ipv4/af_inet.c:155
Code: ff ff e8 4a 53 8c f8 0f 0b e9 48 fe ff ff e8 3e 53 8c f8 0f 0b 41 80 3c 1c 00 0f 85 74 fe ff ff e9 77 fe ff ff e8 27 53 8c f8 <0f> 0b e9 dd fe ff ff 89 f9 80 e1 07 80 c1 03 38 c1 0f 8c 38 fc ff
RSP: 0018:ffffc900001579a8 EFLAGS: 00010246
RAX: ffffffff88f93d99 RBX: dffffc0000000000 RCX: ffff88801b265a00
RDX: 0000000000000100 RSI: 0000000000000090 RDI: 0000000000000000
RBP: 0000000000000090 R08: ffff88807c1e7677 R09: 1ffff1100f83cece
R10: dffffc0000000000 R11: ffffed100f83cecf R12: ffff88807c1e7400
R13: dffffc0000000000 R14: ffff88807c1e7628 R15: ffffffff8e082180
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000555591a8e808 CR3: 0000000064345000 CR4: 00000000003506f0
Call Trace:
<TASK>
__sk_destruct+0x83/0x660 net/core/sock.c:2196
rcu_do_batch kernel/rcu/tree.c:2194 [inline]
rcu_core+0xcc4/0x1720 kernel/rcu/tree.c:2467
handle_softirqs+0x280/0x820 kernel/softirq.c:578
run_ksoftirqd+0x9c/0xf0 kernel/softirq.c:950
smpboot_thread_fn+0x635/0xa00 kernel/smpboot.c:164
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jan 10, 2026, 12:29:25 AM (2 days ago) Jan 10
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 5fa4793a2d2d Linux 6.6.119
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=156f519a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=691a6769a86ac817
dashboard link: https://syzkaller.appspot.com/bug?extid=c1ff5aa334cbeba54710
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=178c49fc580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/63699875f1dd/disk-5fa4793a.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/8506652fcb6f/vmlinux-5fa4793a.xz
kernel image: https://storage.googleapis.com/syzbot-assets/1b30ceed1710/bzImage-5fa4793a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c1ff5a...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 22 at net/ipv4/af_inet.c:155 inet_sock_destruct+0x689/0x7a0 net/ipv4/af_inet.c:155
Modules linked in:
CPU: 1 PID: 22 Comm: ksoftirqd/1 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
RIP: 0010:inet_sock_destruct+0x689/0x7a0 net/ipv4/af_inet.c:155
Code: ff ff e8 4a 53 8c f8 0f 0b e9 48 fe ff ff e8 3e 53 8c f8 0f 0b 41 80 3c 1c 00 0f 85 74 fe ff ff e9 77 fe ff ff e8 27 53 8c f8 <0f> 0b e9 dd fe ff ff 89 f9 80 e1 07 80 c1 03 38 c1 0f 8c 38 fc ff
RSP: 0018:ffffc900001c79a8 EFLAGS: 00010246
RAX: ffffffff88f93d99 RBX: dffffc0000000000 RCX: ffff88801c263c00
RDX: 0000000000000100 RSI: 0000000000000090 RDI: 0000000000000000
RBP: 0000000000000090 R08: ffff8880314fb537 R09: 1ffff1100629f6a6
R10: dffffc0000000000 R11: ffffed100629f6a7 R12: ffff8880314fb2c0
R13: dffffc0000000000 R14: ffff8880314fb4e8 R15: ffffffff8e082180
FS: 0000000000000000(0000) GS:ffff8880b8f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055e2e6ee4950 CR3: 000000000cb30000 CR4: 00000000003506e0
Call Trace:
<TASK>
__sk_destruct+0x83/0x660 net/core/sock.c:2196
rcu_do_batch kernel/rcu/tree.c:2194 [inline]
rcu_core+0xcc4/0x1720 kernel/rcu/tree.c:2467
handle_softirqs+0x280/0x820 kernel/softirq.c:578
run_ksoftirqd+0x9c/0xf0 kernel/softirq.c:950
smpboot_thread_fn+0x635/0xa00 kernel/smpboot.c:164
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Jan 10, 2026, 6:45:24 PM (2 days ago) Jan 10
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 5fa4793a2d2d Linux 6.6.119
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1413899a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=691a6769a86ac817
dashboard link: https://syzkaller.appspot.com/bug?extid=c1ff5aa334cbeba54710
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1213899a580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=134c699a580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/63699875f1dd/disk-5fa4793a.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/8506652fcb6f/vmlinux-5fa4793a.xz
kernel image: https://storage.googleapis.com/syzbot-assets/1b30ceed1710/bzImage-5fa4793a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c1ff5a...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 992 at net/ipv4/af_inet.c:155 inet_sock_destruct+0x689/0x7a0 net/ipv4/af_inet.c:155
Modules linked in:
CPU: 0 PID: 992 Comm: kworker/u4:5 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
Workqueue: events_unbound bpf_map_free_deferred
RIP: 0010:inet_sock_destruct+0x689/0x7a0 net/ipv4/af_inet.c:155
Code: ff ff e8 4a 53 8c f8 0f 0b e9 48 fe ff ff e8 3e 53 8c f8 0f 0b 41 80 3c 1c 00 0f 85 74 fe ff ff e9 77 fe ff ff e8 27 53 8c f8 <0f> 0b e9 dd fe ff ff 89 f9 80 e1 07 80 c1 03 38 c1 0f 8c 38 fc ff
RSP: 0018:ffffc90000007be8 EFLAGS: 00010246
RAX: ffffffff88f93d99 RBX: dffffc0000000000 RCX: ffff88802257da00
RDX: 0000000000000100 RSI: 0000000000000090 RDI: 0000000000000000
RBP: 0000000000000090 R08: ffff888027fb10f7 R09: 1ffff11004ff621e
R10: dffffc0000000000 R11: ffffed1004ff621f R12: ffff888027fb0e80
R13: dffffc0000000000 R14: ffff888027fb10a8 R15: ffffffff8e082180
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f5bab3e8f98 CR3: 000000005f7d4000 CR4: 00000000003506f0
Call Trace:
<IRQ>
__sk_destruct+0x83/0x660 net/core/sock.c:2196
rcu_do_batch kernel/rcu/tree.c:2194 [inline]
rcu_core+0xcc4/0x1720 kernel/rcu/tree.c:2467
handle_softirqs+0x280/0x820 kernel/softirq.c:578
do_softirq+0xed/0x180 kernel/softirq.c:479
</IRQ>
<TASK>
__local_bh_enable_ip+0x178/0x1c0 kernel/softirq.c:406
lock_sock include/net/sock.h:1767 [inline]
sock_map_free+0x119/0x3c0 net/core/sock_map.c:353
bpf_map_free_deferred+0xfc/0x120 kernel/bpf/syscall.c:703
process_one_work kernel/workqueue.c:2634 [inline]
process_scheduled_works+0xa45/0x15b0 kernel/workqueue.c:2711
worker_thread+0xa55/0xfc0 kernel/workqueue.c:2792
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>


---
Reply all
Reply to author
Forward
0 new messages