Hello,
syzbot found the following issue on:
HEAD commit: deda38367d8c Fix a long-standing bug in ec_asn1_group2pkpa..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=1412305f980000
kernel config:
https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link:
https://syzkaller.appspot.com/bug?extid=6d4e7ef4eca1cb4a742d
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/bdcd510adba7/disk-deda3836.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/f66c25b1dfcd/bsd-deda3836.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/c83d778526be/kernel-deda3836.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+6d4e7e...@syzkaller.appspotmail.com
panic: Data modified on freelist: word 6 of object 0xffff80000131b000 size 0x1800 previous type proc (0xdeaf4153 != 0xdeaf4152)
Starting stack trace...
panic(ffffffff830133e2) at panic+0x1ba sys/kern/subr_prf.c:229
malloc(1800,29,9) at malloc+0xd7c sys/kern/kern_malloc.c:349
unveil_add(ffff80002a4d0020,ffff80002a53d858,ffff80002a53d913) at unveil_add+0x1dd sys/kern/kern_unveil.c:423
sys_unveil(ffff80002a4d0020,ffff80002a53da40,ffff80002a53d990) at sys_unveil+0x60c sys/kern/vfs_syscalls.c:1020
syscall(ffff80002a53da40) at syscall+0x97e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7eecbff73d70, count: 251
End of stack trace.
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup