general protection fault in uprobe_mmap

12 views
Skip to first unread message

syzbot

unread,
Nov 27, 2018, 12:40:04 AM11/27/18
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 1efb6ee3edea bpf: fix check of allowed specifiers in bpf_t..
git tree: bpf
console output: https://syzkaller.appspot.com/x/log.txt?x=10f9e26d400000
kernel config: https://syzkaller.appspot.com/x/.config?x=7e5cbc38ae27657e
dashboard link: https://syzkaller.appspot.com/bug?extid=2c999a87518cc8529105
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
CC: [ac...@kernel.org alexander...@linux.intel.com
jo...@redhat.com linux-...@vger.kernel.org mi...@redhat.com
namh...@kernel.org pet...@infradead.org]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2c999a...@syzkaller.appspotmail.com

kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] PREEMPT SMP KASAN
kasan: CONFIG_KASAN_INLINE enabled
CPU: 1 PID: 8204 Comm: modprobe Not tainted 4.20.0-rc1+ #86
kasan: GPF could be caused by NULL-ptr deref or user memory access
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:perf_trace_lock_acquire+0xd2/0x800 include/trace/events/lock.h:13
Code: 20 f2 f2 f2 f2 c7 40 24 00 f2 f2 f2 65 48 8b 04 25 28 00 00 00 48 89
45 d0 31 c0 48 8d 46 18 48 89 85 60 fe ff ff 48 c1 e8 03 <80> 3c 10 00 0f
85 83 05 00 00 48 8b 85 70 fe ff ff 48 8b 78 18 48
RSP: 0018:ffff880191e26fe0 EFLAGS: 00010802
RAX: 1c01ffd844e147fb RBX: ffff8801ca6ca9a8 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: e00ffec2270a3fc0 RDI: ffffffff89583960
RBP: ffff880191e271b8 R08: 0000000000000000 R09: 0000000000000001
R10: ffffffff8160e420 R11: ffffffff8a1638cf R12: ffffffff89583960
R13: 0000000000000000 R14: ffff880191e27190 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff8801daf00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f5f1fc93010 CR3: 00000001be168000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
trace_lock_acquire include/trace/events/lock.h:13 [inline]
lock_acquire+0x385/0x520 kernel/locking/lockdep.c:3843
__mutex_lock_common kernel/locking/mutex.c:925 [inline]
__mutex_lock+0x166/0x16f0 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
uprobe_mmap+0x285/0x1130 kernel/events/uprobes.c:1342
mmap_region+0x5fa/0x1cd0 mm/mmap.c:1832
do_mmap+0xa22/0x1230 mm/mmap.c:1559
do_mmap_pgoff include/linux/mm.h:2320 [inline]
vm_mmap_pgoff+0x213/0x2c0 mm/util.c:350
ksys_mmap_pgoff+0x4da/0x660 mm/mmap.c:1609
__do_sys_mmap arch/x86/kernel/sys_x86_64.c:100 [inline]
__se_sys_mmap arch/x86/kernel/sys_x86_64.c:91 [inline]
__x64_sys_mmap+0xe9/0x1b0 arch/x86/kernel/sys_x86_64.c:91
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f5f1fa8c3ea
Code: 48 8d 3d 81 69 00 00 b2 84 e8 52 ec ff ff f7 d8 89 05 ae ad 20 00 eb
c6 90 90 90 90 90 90 90 90 49 89 ca b8 09 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 73 01 c3 48 8d 0d 8a ad 20 00 31 d2 48 29 c2 89
RSP: 002b:00007ffd27129488 EFLAGS: 00000246 ORIG_RAX: 0000000000000009
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f5f1fa8c3ea
RDX: 0000000000000001 RSI: 00000000000033ef RDI: 0000000000000000
RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000002 R11: 0000000000000246 R12: 00007f5f1fc97090
R13: ffffffffffffffff R14: 0000000000000000 R15: 00007f5f1fc97570
Modules linked in:
---[ end trace d188eea425ead331 ]---
general protection fault: 0000 [#2] PREEMPT SMP KASAN
CPU: 0 PID: 8206 Comm: blkid Tainted: G D 4.20.0-rc1+ #86
RIP: 0010:perf_trace_lock_acquire+0xd2/0x800 include/trace/events/lock.h:13
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Code: 20 f2 f2 f2 f2 c7 40 24 00 f2 f2 f2 65 48 8b 04 25 28 00 00 00 48 89
45 d0 31 c0 48 8d 46 18 48 89 85 60 fe ff ff 48 c1 e8 03 <80> 3c 10 00 0f
85 83 05 00 00 48 8b 85 70 fe ff ff 48 8b 78 18 48
RIP: 0010:perf_trace_lock_acquire+0xd2/0x800 include/trace/events/lock.h:13
RSP: 0018:ffff880191e26fe0 EFLAGS: 00010802
Code: 20 f2 f2 f2 f2 c7 40 24 00 f2 f2 f2 65 48 8b 04 25 28 00 00 00 48 89
45 d0 31 c0 48 8d 46 18 48 89 85 60 fe ff ff 48 c1 e8 03 <80> 3c 10 00 0f
85 83 05 00 00 48 8b 85 70 fe ff ff 48 8b 78 18 48
RAX: 1c01ffd844e147fb RBX: ffff8801ca6ca9a8 RCX: 0000000000000000
RSP: 0018:ffff880192fbeb40 EFLAGS: 00010802
RDX: dffffc0000000000 RSI: e00ffec2270a3fc0 RDI: ffffffff89583960
RAX: 1c01ffd879d3d5ab RBX: ffff8801ca6ca9a8 RCX: 0000000000000000
RBP: ffff880191e271b8 R08: 0000000000000000 R09: 0000000000000001
RDX: dffffc0000000000 RSI: e00ffec3ce9ead40 RDI: ffffffff89583960
R10: ffffffff8160e420 R11: ffffffff8a1638cf R12: ffffffff89583960
RBP: ffff880192fbed18 R08: 0000000000000000 R09: 0000000000000001
R13: 0000000000000000 R14: ffff880191e27190 R15: 0000000000000000
R10: ffffffff8160e420 R11: ffffffff8a1638cf R12: ffffffff89583960
FS: 0000000000000000(0000) GS:ffff8801daf00000(0000) knlGS:0000000000000000
R13: 0000000000000000 R14: ffff880192fbecf0 R15: 0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
FS: 0000000000000000(0000) GS:ffff8801dae00000(0000) knlGS:0000000000000000
CR2: 00007f5f1fc93010 CR3: 00000001be168000 CR4: 00000000001406e0
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
CR2: 0000000000625208 CR3: 00000001d80b8000 CR4: 00000000001406f0
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
May 24, 2019, 1:43:04 AM5/24/19
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages