Hello,
syzbot found the following issue on:
HEAD commit: dc5c83b7f5f8 Linux 6.1.178
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=128d22a9580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link:
https://syzkaller.appspot.com/bug?extid=6b46673c8ec480a9c2c2
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/96393e4697a3/disk-dc5c83b7.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/0d4afce44fab/vmlinux-dc5c83b7.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/4787e310d875/Image-dc5c83b7.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+6b4667...@syzkaller.appspotmail.com
Unable to handle kernel paging request at virtual address dfff80000000000a
KASAN: null-ptr-deref in range [0x0000000000000050-0x0000000000000057]
Mem abort info:
ESR = 0x0000000096000006
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x06: level 2 translation fault
Data abort info:
ISV = 0, ISS = 0x00000006
CM = 0, WnR = 0
[dfff80000000000a] address between user and kernel address ranges
Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP
Modules linked in:
CPU: 1 PID: 9421 Comm: syz.2.957 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : dummy_queue+0x16c/0x700 drivers/usb/gadget/udc/dummy_hcd.c:717
lr : gadget_to_dummy_hcd drivers/usb/gadget/udc/dummy_hcd.c:316 [inline]
lr : dummy_queue+0x138/0x700 drivers/usb/gadget/udc/dummy_hcd.c:716
sp : ffff8000080175b0
x29: ffff8000080175e0 x28: 1fffe0001a1d481b x27: ffff0000d0ea4c00
x26: ffff0001009b2000 x25: dfff800000000000 x24: ffff0000d0ea40d8
x23: dfff800000000000 x22: 1fffe00020136400 x21: 0000000000000050
x20: ffff0000d0ea40e0 x19: ffff0001009b2010 x18: 0000000000000000
x17: 0000000000a000ae x16: ffff8000082dd244 x15: 0000000000000000
x14: 0000000000000001 x13: 1fffe0001b8bfd90 x12: 0000000000000000
x11: ff0080000dcee100 x10: 0000000000000000 x9 : 0000000000000658
x8 : 000000000000000a x7 : 0000000000000000 x6 : 000000000000003f
x5 : 0000000000000040 x4 : 0000000000000001 x3 : 0000000000000000
x2 : 0000000000000a20 x1 : 0000000000000003 x0 : 0000000000000005
Call trace:
dummy_queue+0x16c/0x700 drivers/usb/gadget/udc/dummy_hcd.c:717
usb_ep_queue+0xe4/0x494 drivers/usb/gadget/udc/core.c:305
eth_start_xmit+0x6b0/0xc5c drivers/usb/gadget/function/u_ether.c:590
__netdev_start_xmit include/linux/netdevice.h:4894 [inline]
netdev_start_xmit include/linux/netdevice.h:4908 [inline]
xmit_one net/core/dev.c:3695 [inline]
dev_hard_start_xmit+0x234/0x8c8 net/core/dev.c:3711
sch_direct_xmit+0x234/0x4ac net/sched/sch_generic.c:345
__dev_xmit_skb net/core/dev.c:3932 [inline]
__dev_queue_xmit+0x1394/0x3154 net/core/dev.c:4337
dev_queue_xmit include/linux/netdevice.h:3051 [inline]
lapbeth_data_transmit+0x1f4/0x290 drivers/net/wan/lapbether.c:259
lapb_data_transmit+0x8c/0xb0 net/lapb/lapb_iface.c:447
lapb_transmit_buffer+0x160/0x200 net/lapb/lapb_out.c:149
lapb_send_control+0x228/0x324 net/lapb/lapb_subr.c:251
lapb_t1timer_expiry+0x458/0x808 net/lapb/lapb_timer.c:-1
call_timer_fn+0x1b8/0x96c kernel/time/timer.c:1701
expire_timers kernel/time/timer.c:1752 [inline]
__run_timers+0x478/0x6d8 kernel/time/timer.c:2023
run_timer_softirq+0x7c/0x114 kernel/time/timer.c:2036
handle_softirqs+0x318/0xc90 kernel/softirq.c:596
__do_softirq+0x14/0x20 kernel/softirq.c:630
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:80
call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:897
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:85
invoke_softirq kernel/softirq.c:477 [inline]
__irq_exit_rcu+0x23c/0x430 kernel/softirq.c:679
irq_exit_rcu+0x14/0x84 kernel/softirq.c:691
__el1_irq arch/arm64/kernel/entry-common.c:472 [inline]
el1_interrupt+0x38/0x54 arch/arm64/kernel/entry-common.c:486
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:491
el1h_64_irq+0x64/0x68 arch/arm64/kernel/entry.S:581
arch_local_irq_restore arch/arm64/include/asm/irqflags.h:122 [inline]
console_emit_next_record+0x640/0x808 kernel/printk/printk.c:2783
console_flush_all kernel/printk/printk.c:-1 [inline]
console_unlock+0x240/0x57c kernel/printk/printk.c:2906
vprintk_emit+0x160/0x2f0 kernel/printk/printk.c:2303
vprintk_default+0x54/0x80 kernel/printk/printk.c:2318
vprintk+0x200/0x2a0 kernel/printk/printk_safe.c:45
_printk+0xe0/0x130 kernel/printk/printk.c:2328
binder_user_error+0x1c4/0x1cc drivers/android/binder.c:162
binder_transaction+0xaa4/0x5510 drivers/android/binder.c:3031
binder_thread_write drivers/android/binder.c:4009 [inline]
binder_ioctl_write_read+0x10d0/0x8bcc drivers/android/binder.c:5069
binder_ioctl+0x45c/0x1b18 drivers/android/binder.c:5356
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:870 [inline]
__se_sys_ioctl fs/ioctl.c:856 [inline]
__arm64_sys_ioctl+0x14c/0x1c8 fs/ioctl.c:856
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x290 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x13c/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x5c/0x134 arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x128 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
Code: 96b01b31 f94002a8 91014115 d343fea8 (38f96908)
---[ end trace 0000000000000000 ]---
----------------
Code disassembly (best guess):
0: 96b01b31 bl 0xfffffffffac06cc4
4: f94002a8 ldr x8, [x21]
8: 91014115 add x21, x8, #0x50
c: d343fea8 lsr x8, x21, #3
* 10: 38f96908 ldrsb w8, [x8, x25] <-- trapping instruction
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup