[v5.15] WARNING in port100_send_cmd_async/usb_submit_urb

1 view
Skip to first unread message

syzbot

unread,
Aug 4, 2026, 2:24:24 PM (3 days ago) Aug 4
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6e2fd6534337 Linux 5.15.213
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=148a4bb9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=f62394b2df7895a14882
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d7b46606b13d/disk-6e2fd653.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/da120fdeb081/vmlinux-6e2fd653.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3c2643457e3f/bzImage-6e2fd653.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+f62394...@syzkaller.appspotmail.com

------------[ cut here ]------------
URB ffff88801e8fe700 submitted while active
WARNING: CPU: 0 PID: 4258 at drivers/usb/core/urb.c:378 usb_submit_urb+0xfba/0x18d0 drivers/usb/core/urb.c:378
Modules linked in:
CPU: 0 PID: 4258 Comm: kworker/0:4 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: usb_hub_wq hub_event
RIP: 0010:usb_submit_urb+0xfba/0x18d0 drivers/usb/core/urb.c:378
Code: c5 8a 44 89 ea e8 c6 d8 d6 03 e9 f3 fb ff ff e8 5c c9 96 fb c6 05 e5 22 95 07 01 48 c7 c7 20 37 c5 8a 48 89 de e8 66 f6 d2 03 <0f> 0b e9 bc f0 ff ff e8 3a c9 96 fb eb 1f e8 33 c9 96 fb 44 8b 64
RSP: 0018:ffffc900031deda0 EFLAGS: 00010246
RAX: 3ed29b0288069e00 RBX: ffff88801e8fe700 RCX: 0000000000100000
RDX: ffffc90013ef9000 RSI: 000000000001476a RDI: 000000000001476b
RBP: 1ffff1100c08130a R08: ffffc900031de8c7 R09: 1ffff9200063bd18
R10: dffffc0000000000 R11: fffff5200063bd19 R12: 0000000000000cc0
R13: 1ffff1100c081309 R14: ffff88801e8fe708 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b9000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffdd2649a58 CR3: 000000002371e000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
port100_send_frame_async drivers/nfc/port100.c:783 [inline]
port100_send_cmd_async+0x81c/0xc60 drivers/nfc/port100.c:879
port100_send_cmd_sync drivers/nfc/port100.c:919 [inline]
port100_set_command_type+0x1c4/0x380 drivers/nfc/port100.c:990
port100_probe+0x9ea/0xdb0 drivers/nfc/port100.c:1570
usb_probe_interface+0x5be/0xae0 drivers/usb/core/driver.c:396
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x276/0xc70 drivers/base/dd.c:595
__driver_probe_device+0x1f5/0x390 drivers/base/dd.c:775
driver_probe_device+0x4f/0x420 drivers/base/dd.c:805
__device_attach_driver+0x2b0/0x500 drivers/base/dd.c:927
bus_for_each_drv+0x184/0x210 drivers/base/bus.c:429
__device_attach+0x2a7/0x480 drivers/base/dd.c:999
bus_probe_device+0xba/0x1d0 drivers/base/bus.c:489
device_add+0xbcf/0x1050 drivers/base/core.c:3427
usb_set_configuration+0x19d5/0x2030 drivers/usb/core/message.c:2223
usb_generic_driver_probe+0x89/0x150 drivers/usb/core/generic.c:238
usb_probe_device+0x126/0x250 drivers/usb/core/driver.c:293
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x276/0xc70 drivers/base/dd.c:595
__driver_probe_device+0x1f5/0x390 drivers/base/dd.c:775
driver_probe_device+0x4f/0x420 drivers/base/dd.c:805
__device_attach_driver+0x2b0/0x500 drivers/base/dd.c:927
bus_for_each_drv+0x184/0x210 drivers/base/bus.c:429
__device_attach+0x2a7/0x480 drivers/base/dd.c:999
bus_probe_device+0xba/0x1d0 drivers/base/bus.c:489
device_add+0xbcf/0x1050 drivers/base/core.c:3427
usb_new_device+0x9f6/0x15d0 drivers/usb/core/hub.c:2632
hub_port_connect drivers/usb/core/hub.c:5497 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5637 [inline]
port_event drivers/usb/core/hub.c:5799 [inline]
hub_event+0x2b8d/0x5260 drivers/usb/core/hub.c:5881
process_one_work+0x867/0xff0 kernel/workqueue.c:2310
worker_thread+0xad7/0x12a0 kernel/workqueue.c:2457
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 4, 2026, 3:31:36 PM (3 days ago) Aug 4
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fb28aa725e05 Linux 6.1.180
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1525acc6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=18ac17c530797f584345
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d420eb944682/disk-fb28aa72.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/affae450ab23/vmlinux-fb28aa72.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b9e6919ed519/Image-fb28aa72.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+18ac17...@syzkaller.appspotmail.com

------------[ cut here ]------------
URB 000000003de94fec submitted while active
WARNING: CPU: 0 PID: 14 at drivers/usb/core/urb.c:379 usb_submit_urb+0xd60/0x1510 drivers/usb/core/urb.c:379
Modules linked in:
CPU: 0 PID: 14 Comm: kworker/0:1 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
Workqueue: usb_hub_wq hub_event
pstate: 62400005 (nZCv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : usb_submit_urb+0xd60/0x1510 drivers/usb/core/urb.c:379
lr : usb_submit_urb+0xd60/0x1510 drivers/usb/core/urb.c:379
sp : ffff80001cb86be0
x29: ffff80001cb86c10
x28: dfff800000000000
x27: dfff800000000000

x26: 1fffe000198ba015 x25: ffff0000db472880 x24: 1fffe000198ba014
x23: 1fffe000198ba032 x22: ffff0000cc5d00a0 x21: ffff0000db472a08
x20: ffff800017d5e000 x19: ffff0000db472a00 x18: 1fffe00033e7277e
x17: 0000000000000000 x16: ffff800011b90080 x15: 0000000000000002
x14: 0000000000000001 x13: 1fffe00033e727a3 x12: 0000000000100000
x11: 0000000000079a51 x10: ffff800032c8c000 x9 : f029debe6be71200
x8 : f029debe6be71200 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff80001cb86678 x4 : ffff800015464e80 x3 : ffff800008540904
x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000000
Call trace:
usb_submit_urb+0xd60/0x1510 drivers/usb/core/urb.c:379
port100_send_frame_async drivers/nfc/port100.c:783 [inline]
port100_send_cmd_async+0x64c/0xa30 drivers/nfc/port100.c:879
port100_send_cmd_sync drivers/nfc/port100.c:919 [inline]
port100_set_command_type+0x18c/0x32c drivers/nfc/port100.c:990
port100_probe+0x7e4/0xb34 drivers/nfc/port100.c:1570
usb_probe_interface+0x50c/0x988 drivers/usb/core/driver.c:396
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x3a0/0xac4 drivers/base/dd.c:638
__driver_probe_device+0x1c8/0x368 drivers/base/dd.c:804
driver_probe_device+0x78/0x324 drivers/base/dd.c:834
__device_attach_driver+0x28c/0x4c0 drivers/base/dd.c:962
bus_for_each_drv+0x154/0x1e4 drivers/base/bus.c:429
__device_attach+0x2a4/0x3d8 drivers/base/dd.c:1034
device_initial_probe+0x24/0x34 drivers/base/dd.c:1083
bus_probe_device+0xbc/0x1c4 drivers/base/bus.c:489
device_add+0x93c/0xe4c drivers/base/core.c:3712
usb_set_configuration+0x15ec/0x1b88 drivers/usb/core/message.c:2223
usb_generic_driver_probe+0x8c/0x148 drivers/usb/core/generic.c:238
usb_probe_device+0x120/0x258 drivers/usb/core/driver.c:293
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x3a0/0xac4 drivers/base/dd.c:638
__driver_probe_device+0x1c8/0x368 drivers/base/dd.c:804
driver_probe_device+0x78/0x324 drivers/base/dd.c:834
__device_attach_driver+0x28c/0x4c0 drivers/base/dd.c:962
bus_for_each_drv+0x154/0x1e4 drivers/base/bus.c:429
__device_attach+0x2a4/0x3d8 drivers/base/dd.c:1034
device_initial_probe+0x24/0x34 drivers/base/dd.c:1083
bus_probe_device+0xbc/0x1c4 drivers/base/bus.c:489
device_add+0x93c/0xe4c drivers/base/core.c:3712
usb_new_device+0x7e4/0x11d0 drivers/usb/core/hub.c:2659
hub_port_connect drivers/usb/core/hub.c:5517 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5657 [inline]
port_event drivers/usb/core/hub.c:5817 [inline]
hub_event+0x2254/0x3e74 drivers/usb/core/hub.c:5899
process_one_work+0x7e4/0x13bc kernel/workqueue.c:2292
worker_thread+0x8cc/0xfe8 kernel/workqueue.c:2439
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
irq event stamp: 97472
hardirqs last enabled at (97471): [<ffff80000831388c>] __up_console_sem+0xb4/0xfc kernel/printk/printk.c:261
hardirqs last disabled at (97472): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (97466): [<ffff8000081ae3bc>] softirq_handle_end kernel/softirq.c:439 [inline]
softirqs last enabled at (97466): [<ffff8000081ae3bc>] handle_softirqs+0xb1c/0xc90 kernel/softirq.c:624
softirqs last disabled at (97457): [<ffff800008020e6c>] __do_softirq+0x14/0x20 kernel/softirq.c:630
---[ end trace 0000000000000000 ]---
port100 1-1:1.0: NFC: The device does not support command type 1
port100: probe of 1-1:1.0 failed with error -16

syzbot

unread,
Aug 4, 2026, 4:48:39 PM (3 days ago) Aug 4
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: aa0e49877a2e Linux 6.6.148
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=120a7649580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0bc3d90c30838b5
dashboard link: https://syzkaller.appspot.com/bug?extid=4475ae160490d736a75d
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f83b390cfc1f/disk-aa0e4987.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/1d4bdb338edd/vmlinux-aa0e4987.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3f57c1d51ee3/bzImage-aa0e4987.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4475ae...@syzkaller.appspotmail.com

usb 9-1: SerialNumber: syz
------------[ cut here ]------------
URB ffff88802665cb00 submitted while active
WARNING: CPU: 0 PID: 11177 at drivers/usb/core/urb.c:379 usb_submit_urb+0xf15/0x17a0 drivers/usb/core/urb.c:379
Modules linked in:
CPU: 0 PID: 11177 Comm: kworker/0:10 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: usb_hub_wq hub_event
RIP: 0010:usb_submit_urb+0xf15/0x17a0 drivers/usb/core/urb.c:379
Code: 6b 8b 44 89 fa e8 fb a3 1b 04 e9 74 fc ff ff e8 91 70 1d fb c6 05 2a 01 0d 08 01 48 c7 c7 20 ee 6b 8b 48 89 de e8 2b 3e e7 fa <0f> 0b e9 63 f1 ff ff e8 6f 70 1d fb eb 12 e8 68 70 1d fb 41 bc 80
RSP: 0018:ffffc90005396d00 EFLAGS: 00010246
RAX: e9219a95ad172400 RBX: ffff88802665cb00 RCX: 0000000000100000
RDX: ffffc900176b8000 RSI: 00000000000364cb RDI: 00000000000364cc
RBP: dffffc0000000000 R08: ffffc90005396a07 R09: 1ffff92000a72d40
R10: dffffc0000000000 R11: fffff52000a72d41 R12: 0000000000000cc0
R13: 1ffff1100b5e3109 R14: ffff88802665cb08 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2b1df58e9c CR3: 000000002e7e4000 CR4: 00000000003506f0
Call Trace:
<TASK>
port100_send_frame_async drivers/nfc/port100.c:783 [inline]
port100_send_cmd_async+0x81c/0xc60 drivers/nfc/port100.c:879
port100_send_cmd_sync drivers/nfc/port100.c:919 [inline]
port100_set_command_type+0x1c8/0x380 drivers/nfc/port100.c:990
port100_probe+0x9f1/0xdb0 drivers/nfc/port100.c:1570
usb_probe_interface+0x5c2/0xaf0 drivers/usb/core/driver.c:396
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x247/0xae0 drivers/base/dd.c:717
__driver_probe_device+0x1f5/0x390 drivers/base/dd.c:879
driver_probe_device+0x4f/0x420 drivers/base/dd.c:909
__device_attach_driver+0x2ca/0x510 drivers/base/dd.c:1037
bus_for_each_drv+0x252/0x2e0 drivers/base/bus.c:459
__device_attach+0x2c1/0x420 drivers/base/dd.c:1109
bus_probe_device+0x180/0x260 drivers/base/bus.c:580
device_add+0x87c/0xc40 drivers/base/core.c:3700
usb_set_configuration+0x1ad0/0x2150 drivers/usb/core/message.c:2265
usb_generic_driver_probe+0x8d/0x150 drivers/usb/core/generic.c:238
usb_probe_device+0x12a/0x260 drivers/usb/core/driver.c:293
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x247/0xae0 drivers/base/dd.c:717
__driver_probe_device+0x1f5/0x390 drivers/base/dd.c:879
driver_probe_device+0x4f/0x420 drivers/base/dd.c:909
__device_attach_driver+0x2ca/0x510 drivers/base/dd.c:1037
bus_for_each_drv+0x252/0x2e0 drivers/base/bus.c:459
__device_attach+0x2c1/0x420 drivers/base/dd.c:1109
bus_probe_device+0x180/0x260 drivers/base/bus.c:580
device_add+0x87c/0xc40 drivers/base/core.c:3700
usb_new_device+0x995/0x1550 drivers/usb/core/hub.c:2660
hub_port_connect drivers/usb/core/hub.c:5529 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5669 [inline]
port_event drivers/usb/core/hub.c:5833 [inline]
hub_event+0x29d5/0x4a80 drivers/usb/core/hub.c:5915
process_one_work kernel/workqueue.c:2657 [inline]
process_scheduled_works+0xa60/0x1600 kernel/workqueue.c:2734
worker_thread+0xa5e/0xfe0 kernel/workqueue.c:2815
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>

syzbot

unread,
Aug 4, 2026, 8:44:33 PM (3 days ago) Aug 4
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: fb28aa725e05 Linux 6.1.180
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11075bb9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=18ac17c530797f584345
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12df4bb9580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=173a93b9580000
usb 1-1: Product: syz
usb 1-1: Manufacturer: syz
usb 1-1: SerialNumber: syz
------------[ cut here ]------------
URB 00000000d369d7e7 submitted while active
WARNING: CPU: 1 PID: 22 at drivers/usb/core/urb.c:379 usb_submit_urb+0xd60/0x1510 drivers/usb/core/urb.c:379
Modules linked in:
CPU: 1 PID: 22 Comm: kworker/1:0 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
Workqueue: usb_hub_wq hub_event
pstate: 62400005 (nZCv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : usb_submit_urb+0xd60/0x1510 drivers/usb/core/urb.c:379
lr : usb_submit_urb+0xd60/0x1510 drivers/usb/core/urb.c:379
sp : ffff80001cc16be0
x29: ffff80001cc16c10 x28: dfff800000000000 x27: dfff800000000000
x26: 1fffe0001b4b9915 x25: ffff0000d59ac680 x24: 1fffe0001b4b9914
x23: 1fffe0001b4b9932 x22: ffff0000da5cc8a0 x21: ffff0000d59ade08
x20: ffff800017d5e000 x19: ffff0000d59ade00 x18: 1fffe00033e7697e
x17: 0000000000000000 x16: ffff800011b90080 x15: 0000000000000000
x14: 0000000000000001 x13: 1fffe00033e769a3 x12: 0000000000000000
x11: ff00800008195f70 x10: 0000000000000000 x9 : b4fc46f096a44c00
x8 : b4fc46f096a44c00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff80001cc16678 x4 : ffff800015464e80 x3 : ffff800008540904
irq event stamp: 19674
hardirqs last enabled at (19673): [<ffff80000831388c>] __up_console_sem+0xb4/0xfc kernel/printk/printk.c:261
hardirqs last disabled at (19674): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (19668): [<ffff8000081ae3bc>] softirq_handle_end kernel/softirq.c:439 [inline]
softirqs last enabled at (19668): [<ffff8000081ae3bc>] handle_softirqs+0xb1c/0xc90 kernel/softirq.c:624
softirqs last disabled at (19659): [<ffff800008020e6c>] __do_softirq+0x14/0x20 kernel/softirq.c:630
---[ end trace 0000000000000000 ]---
port100 1-1:1.0: NFC: The device does not support command type 1
port100: probe of 1-1:1.0 failed with error -16


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages