[v6.1] KASAN: use-after-free Read in release_card_device

2 views
Skip to first unread message

syzbot

unread,
Jul 31, 2026, 4:33:35 AMJul 31
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fb28aa725e05 Linux 6.1.180
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=145578c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=7dd58bbfcf207cdb201d
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d420eb944682/disk-fb28aa72.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/affae450ab23/vmlinux-fb28aa72.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b9e6919ed519/Image-fb28aa72.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7dd58b...@syzkaller.appspotmail.com

==================================================================
BUG: KASAN: use-after-free in snd_card_do_free sound/core/init.c:612 [inline]
BUG: KASAN: use-after-free in release_card_device+0x188/0x198 sound/core/init.c:145
Read of size 1 at addr ffff0000d587cd99 by task syz.3.209/5232

CPU: 1 PID: 5232 Comm: syz.3.209 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
Call trace:
dump_backtrace+0x1c4/0x1f0 arch/arm64/kernel/stacktrace.c:158
show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:165
__dump_stack+0x30/0x40 lib/dump_stack.c:88
dump_stack_lvl+0xf4/0x15c lib/dump_stack.c:106
print_address_description+0x88/0x218 mm/kasan/report.c:316
print_report+0x50/0x68 mm/kasan/report.c:420
kasan_report+0xa8/0xfc mm/kasan/report.c:524
__asan_report_load1_noabort+0x2c/0x38 mm/kasan/report_generic.c:348
snd_card_do_free sound/core/init.c:612 [inline]
release_card_device+0x188/0x198 sound/core/init.c:145
device_release+0x94/0x1b4 drivers/base/core.c:-1
kobject_cleanup lib/kobject.c:681 [inline]
kobject_release lib/kobject.c:712 [inline]
kref_put include/linux/kref.h:65 [inline]
kobject_put+0x2a8/0x41c lib/kobject.c:729
put_device+0x28/0x40 drivers/base/core.c:3820
snd_card_file_remove+0x2e4/0x340 sound/core/init.c:1147
snd_pcm_oss_release+0x1e4/0x230 sound/core/oss/pcm_oss.c:2597
snd_disconnect_release+0x224/0x298 sound/core/init.c:438
__fput+0x1b4/0x7b0 fs/file_table.c:320
____fput+0x20/0x30 fs/file_table.c:348
task_work_run+0x1f4/0x280 kernel/task_work.c:203
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
do_notify_resume+0x20f8/0x2c84 arch/arm64/kernel/signal.c:1151
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_svc+0x98/0x128 arch/arm64/kernel/entry-common.c:638
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

The buggy address belongs to the physical page:
page:00000000898d10f0 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x11587c
flags: 0x5ffc00000000000(node=0|zone=2|lastcpupid=0x7ff)
raw: 05ffc00000000000 fffffc0003ba2b08 ffff00019f3ce0b0 0000000000000000
raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
ffff0000d587cc80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff0000d587cd00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff0000d587cd80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff0000d587ce00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff0000d587ce80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
------------[ cut here ]------------
WARNING: CPU: 1 PID: 5232 at mm/slab_common.c:904 free_large_kmalloc+0x30/0x158 mm/slab_common.c:905
Modules linked in:
CPU: 1 PID: 5232 Comm: syz.3.209 Tainted: G B syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
pstate: 42400005 (nZcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : free_large_kmalloc+0x30/0x158 mm/slab_common.c:905
lr : kfree+0xf4/0x1a8 mm/slab_common.c:982
sp : ffff800020e37830
x29: ffff800020e37830 x28: ffff0000caa1bf10 x27: 1ffff00002d37378
x26: 1fffe0001ab0f91e x25: 1fffe0001ab0f925 x24: 000000000000000d
x23: dfff800000000000 x22: dfff800000000000 x21: 0000000000040000
x20: ffff0000d587c080 x19: fffffc0003561f00 x18: 1fffe00033e7697e
x17: ffff80001537d000 x16: ffff800011b90080 x15: 0000000040000000
x14: 0000000000000001 x13: 1ffff00002ff016c x12: 0000000000000000
x11: ff0080000808d058 x10: ffffffffffffffff x9 : 0000000000000000
x8 : ffff800017d5d000 x7 : ffff800011cec160 x6 : ffff80000825ab50
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff800008195a38
x2 : 0000000000000001 x1 : ffff0000d587c080 x0 : fffffc0003561f00
Call trace:
free_large_kmalloc+0x30/0x158 mm/slab_common.c:905
kfree+0xf4/0x1a8 mm/slab_common.c:982
snd_card_do_free sound/core/init.c:613 [inline]
release_card_device+0x130/0x198 sound/core/init.c:145
device_release+0x94/0x1b4 drivers/base/core.c:-1
kobject_cleanup lib/kobject.c:681 [inline]
kobject_release lib/kobject.c:712 [inline]
kref_put include/linux/kref.h:65 [inline]
kobject_put+0x2a8/0x41c lib/kobject.c:729
put_device+0x28/0x40 drivers/base/core.c:3820
snd_card_file_remove+0x2e4/0x340 sound/core/init.c:1147
snd_pcm_oss_release+0x1e4/0x230 sound/core/oss/pcm_oss.c:2597
snd_disconnect_release+0x224/0x298 sound/core/init.c:438
__fput+0x1b4/0x7b0 fs/file_table.c:320
____fput+0x20/0x30 fs/file_table.c:348
task_work_run+0x1f4/0x280 kernel/task_work.c:203
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
do_notify_resume+0x20f8/0x2c84 arch/arm64/kernel/signal.c:1151
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_svc+0x98/0x128 arch/arm64/kernel/entry-common.c:638
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 18551
hardirqs last enabled at (18551): [<ffff80000825abe4>] raw_spin_rq_unlock_irq kernel/sched/sched.h:1374 [inline]
hardirqs last enabled at (18551): [<ffff80000825abe4>] finish_lock_switch+0xb0/0x1c8 kernel/sched/core.c:5005
hardirqs last disabled at (18550): [<ffff800011c630f8>] __schedule+0x294/0x1a6c kernel/sched/core.c:6461
softirqs last enabled at (18428): [<ffff8000081ae3bc>] softirq_handle_end kernel/softirq.c:439 [inline]
softirqs last enabled at (18428): [<ffff8000081ae3bc>] handle_softirqs+0xb1c/0xc90 kernel/softirq.c:624
softirqs last disabled at (18415): [<ffff800008020e6c>] __do_softirq+0x14/0x20 kernel/softirq.c:630
---[ end trace 0000000000000000 ]---
object pointer: 0x00000000837825f9


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 18, 2026, 7:15:37 AM (4 days ago) Aug 18
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: e4f7d8be268e Linux 6.1.182
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17ac76c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=7dd58bbfcf207cdb201d
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13d27949580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1350b679580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7cd9b1875376/disk-e4f7d8be.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/4b5d35d18c31/vmlinux-e4f7d8be.xz
kernel image: https://storage.googleapis.com/syzbot-assets/d5ee64c2af77/Image-e4f7d8be.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7dd58b...@syzkaller.appspotmail.com

==================================================================
BUG: KASAN: use-after-free in snd_card_do_free sound/core/init.c:612 [inline]
BUG: KASAN: use-after-free in release_card_device+0x188/0x198 sound/core/init.c:145
Read of size 1 at addr ffff0000d5a50d99 by task syz.3.20/4527

CPU: 1 PID: 4527 Comm: syz.3.20 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
Call trace:
dump_backtrace+0x1c4/0x1f0 arch/arm64/kernel/stacktrace.c:158
show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:165
__dump_stack+0x30/0x40 lib/dump_stack.c:88
dump_stack_lvl+0xf4/0x15c lib/dump_stack.c:106
print_address_description+0x88/0x218 mm/kasan/report.c:316
print_report+0x50/0x68 mm/kasan/report.c:420
kasan_report+0xa8/0xfc mm/kasan/report.c:524
__asan_report_load1_noabort+0x2c/0x38 mm/kasan/report_generic.c:348
snd_card_do_free sound/core/init.c:612 [inline]
release_card_device+0x188/0x198 sound/core/init.c:145
device_release+0x94/0x1b4 drivers/base/core.c:-1
kobject_cleanup lib/kobject.c:681 [inline]
kobject_release lib/kobject.c:712 [inline]
kref_put include/linux/kref.h:65 [inline]
kobject_put+0x2a8/0x41c lib/kobject.c:729
put_device+0x28/0x40 drivers/base/core.c:3820
snd_card_file_remove+0x2e4/0x340 sound/core/init.c:1147
snd_pcm_release+0x120/0x14c sound/core/pcm_native.c:2932
snd_disconnect_release+0x224/0x298 sound/core/init.c:438
__fput+0x1b4/0x7b0 fs/file_table.c:320
____fput+0x20/0x30 fs/file_table.c:348
task_work_run+0x1f4/0x280 kernel/task_work.c:203
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
do_notify_resume+0x20f8/0x2c84 arch/arm64/kernel/signal.c:1151
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_svc+0x98/0x128 arch/arm64/kernel/entry-common.c:638
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

The buggy address belongs to the physical page:
page:00000000b08c66eb refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x115a50
flags: 0x5ffc00000000000(node=0|zone=2|lastcpupid=0x7ff)
raw: 05ffc00000000000 fffffc0003bfa508 ffff00019f3ce0b0 0000000000000000
raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
ffff0000d5a50c80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff0000d5a50d00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff0000d5a50d80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff0000d5a50e00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff0000d5a50e80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Aug 19, 2026, 8:29:34 PM (2 days ago) Aug 19
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 0eb903b5b519 Linux 5.15.216
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13b37815580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=c7c0e8197e9af1b74a75
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/c8b89e4b2795/disk-0eb903b5.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9bf7510653f7/vmlinux-0eb903b5.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ca66c80f4649/bzImage-0eb903b5.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c7c0e8...@syzkaller.appspotmail.com

==================================================================
BUG: KASAN: use-after-free in snd_card_do_free sound/core/init.c:601 [inline]
BUG: KASAN: use-after-free in release_card_device+0x1e1/0x1f0 sound/core/init.c:145
Read of size 1 at addr ffff88802b810df9 by task syz.5.78/4705

CPU: 1 PID: 4705 Comm: syz.5.78 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Call Trace:
<TASK>
dump_stack_lvl+0x188/0x250 lib/dump_stack.c:106
print_address_description+0x60/0x2d0 mm/kasan/report.c:248
__kasan_report mm/kasan/report.c:434 [inline]
kasan_report+0xdf/0x130 mm/kasan/report.c:451
snd_card_do_free sound/core/init.c:601 [inline]
release_card_device+0x1e1/0x1f0 sound/core/init.c:145
device_release+0x92/0x1c0 drivers/base/core.c:-1
kobject_cleanup lib/kobject.c:713 [inline]
kobject_release lib/kobject.c:744 [inline]
kref_put include/linux/kref.h:65 [inline]
kobject_put+0x217/0x450 lib/kobject.c:761
snd_card_file_remove+0x32d/0x380 sound/core/init.c:1132
snd_pcm_release+0x12b/0x150 sound/core/pcm_native.c:2918
__fput+0x212/0x8c0 fs/file_table.c:311
task_work_run+0x125/0x1a0 kernel/task_work.c:188
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
exit_to_user_mode_loop+0x10f/0x130 kernel/entry/common.c:181
exit_to_user_mode_prepare+0xee/0x180 kernel/entry/common.c:214
__syscall_exit_to_user_mode_work kernel/entry/common.c:296 [inline]
syscall_exit_to_user_mode+0x16/0x40 kernel/entry/common.c:307
do_syscall_64+0x58/0xa0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f9ad95400d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffeb7207068 EFLAGS: 00000246 ORIG_RAX: 00000000000001b4
RAX: 0000000000000000 RBX: 00007f9ad97c9da0 RCX: 00007f9ad95400d9
RDX: 0000000000000000 RSI: 000000000000001e RDI: 0000000000000003
RBP: 00007f9ad97c9da0 R08: 0000000000000006 R09: 0000000000000000
R10: 00007f9ad97c9cb0 R11: 0000000000000246 R12: 000000000001782a
R13: 00007f9ad97c7fac R14: 0000000000017691 R15: 00007ffeb7207170
</TASK>

The buggy address belongs to the page:
page:ffffea0000ae0400 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x2b810
flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000000 ffffea00017a3d08 ffff8880b91409f0 0000000000000000
raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 2, migratetype Unmovable, gfp_mask 0x40dc0(GFP_KERNEL|__GFP_COMP|__GFP_ZERO), pid 1, ts 21051619173, free_ts 96563709354
prep_new_page mm/page_alloc.c:2426 [inline]
get_page_from_freelist+0x24f6/0x2670 mm/page_alloc.c:4192
__alloc_pages+0x1ee/0x480 mm/page_alloc.c:5501
__alloc_pages_node include/linux/gfp.h:570 [inline]
alloc_pages_node include/linux/gfp.h:584 [inline]
kmalloc_large_node+0x7d/0x1a0 mm/slub.c:4426
__kmalloc_node_track_caller+0x219/0x3a0 mm/slub.c:4949
alloc_dr drivers/base/devres.c:116 [inline]
__devres_alloc_node+0x49/0x110 drivers/base/devres.c:162
snd_devm_card_new+0x74/0x150 sound/core/init.c:225
loopback_probe+0x14d/0x1a20 sound/drivers/aloop.c:1730
platform_probe+0x137/0x1c0 drivers/base/platform.c:1391
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x276/0xc70 drivers/base/dd.c:595
__driver_probe_device+0x1f5/0x390 drivers/base/dd.c:775
driver_probe_device+0x4f/0x420 drivers/base/dd.c:805
__device_attach_driver+0x2b0/0x500 drivers/base/dd.c:927
bus_for_each_drv+0x184/0x210 drivers/base/bus.c:429
__device_attach+0x2a7/0x480 drivers/base/dd.c:999
bus_probe_device+0xba/0x1d0 drivers/base/bus.c:489
device_add+0xbcf/0x1050 drivers/base/core.c:3427
page last free stack trace:
reset_page_owner include/linux/page_owner.h:24 [inline]
free_pages_prepare mm/page_alloc.c:1340 [inline]
free_pcp_prepare mm/page_alloc.c:1391 [inline]
free_unref_page_prepare+0x637/0x6c0 mm/page_alloc.c:3317
free_unref_page+0x8f/0x2a0 mm/page_alloc.c:3396
free_nonslab_page+0xde/0x150 mm/slub.c:3540
release_nodes drivers/base/devres.c:501 [inline]
devres_release_all+0x1a9/0x230 drivers/base/devres.c:530
__device_release_driver drivers/base/dd.c:1251 [inline]
device_release_driver_internal+0x496/0x710 drivers/base/dd.c:1282
unbind_store+0x2e2/0x300 drivers/base/bus.c:193
kernfs_fop_write_iter+0x3a8/0x500 fs/kernfs/file.c:296
call_write_iter include/linux/fs.h:2173 [inline]
new_sync_write fs/read_write.c:507 [inline]
vfs_write+0x748/0xd70 fs/read_write.c:594
ksys_write+0x153/0x260 fs/read_write.c:647
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0

Memory state around the buggy address:
ffff88802b810c80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88802b810d00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88802b810d80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff88802b810e00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88802b810e80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================


---

syzbot

unread,
Aug 20, 2026, 5:50:35 AM (2 days ago) Aug 20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0eb903b5b519 Linux 5.15.216
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=149eee79580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=c7c0e8197e9af1b74a75
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16dc0e79580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11dc0e79580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/c8b89e4b2795/disk-0eb903b5.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9bf7510653f7/vmlinux-0eb903b5.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ca66c80f4649/bzImage-0eb903b5.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c7c0e8...@syzkaller.appspotmail.com

==================================================================
BUG: KASAN: use-after-free in snd_card_do_free sound/core/init.c:601 [inline]
BUG: KASAN: use-after-free in release_card_device+0x1e1/0x1f0 sound/core/init.c:145
Read of size 1 at addr ffff88802b23cdf9 by task syz.0.17/4419

CPU: 0 PID: 4419 Comm: syz.0.17 Not tainted syzkaller #0
RIP: 0033:0x7f88489010d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffd949681c8 EFLAGS: 00000246 ORIG_RAX: 00000000000001b4
RAX: 0000000000000000 RBX: 00007f8848b8ada0 RCX: 00007f88489010d9
RDX: 0000000000000000 RSI: 000000000000001e RDI: 0000000000000003
RBP: 00007f8848b8ada0 R08: 0000000000000006 R09: 0000000000000000
R10: 00007f8848b8acb0 R11: 0000000000000246 R12: 0000000000014479
R13: 00007f8848b88fac R14: 0000000000014171 R15: 00007ffd949682d0
</TASK>

The buggy address belongs to the page:
page:ffffea0000ac8f00 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x2b23c
flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000000 ffffea00016c8d08 ffff8880b90409f0 0000000000000000
raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 2, migratetype Unmovable, gfp_mask 0x40dc0(GFP_KERNEL|__GFP_COMP|__GFP_ZERO), pid 1, ts 20730674319, free_ts 83130327143
ffff88802b23cc80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88802b23cd00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88802b23cd80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff88802b23ce00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88802b23ce80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================


---
Reply all
Reply to author
Forward
0 new messages