malloc: free list modified: proc

5 views
Skip to first unread message

syzbot

unread,
Oct 11, 2024, 9:44:26 PM10/11/24
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: deda38367d8c Fix a long-standing bug in ec_asn1_group2pkpa..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1412305f980000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=6d4e7ef4eca1cb4a742d

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/bdcd510adba7/disk-deda3836.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/f66c25b1dfcd/bsd-deda3836.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c83d778526be/kernel-deda3836.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6d4e7e...@syzkaller.appspotmail.com

panic: Data modified on freelist: word 6 of object 0xffff80000131b000 size 0x1800 previous type proc (0xdeaf4153 != 0xdeaf4152)

Starting stack trace...
panic(ffffffff830133e2) at panic+0x1ba sys/kern/subr_prf.c:229
malloc(1800,29,9) at malloc+0xd7c sys/kern/kern_malloc.c:349
unveil_add(ffff80002a4d0020,ffff80002a53d858,ffff80002a53d913) at unveil_add+0x1dd sys/kern/kern_unveil.c:423
sys_unveil(ffff80002a4d0020,ffff80002a53da40,ffff80002a53d990) at sys_unveil+0x60c sys/kern/vfs_syscalls.c:1020
syscall(ffff80002a53da40) at syscall+0x97e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7eecbff73d70, count: 251
End of stack trace.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jan 9, 2025, 8:44:18 PM1/9/25
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages