Hello,
syzkaller hit the following crash on
38c5eb93aca9dc1b21a2c96d583ce7f9886a44e6
git://
git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/master
compiler: gcc (GCC) 7.1.1 20170620
.config is attached
Raw console output is attached.
CC: [
a...@kernel.org dan...@iogearbox.net linux-...@vger.kernel.org
net...@vger.kernel.org]
kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] SMP KASAN
Dumping ftrace buffer:
(ftrace buffer empty)
Modules linked in:
CPU: 1 PID: 1336 Comm: kworker/1:2 Not tainted 4.14.0-rc1+ #47
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: events bpf_map_free_deferred
task: ffff8801d2e76300 task.stack: ffff8801d2d50000
RIP: 0010:smap_list_remove kernel/bpf/sockmap.c:539 [inline]
RIP: 0010:sock_map_free+0x276/0x870 kernel/bpf/sockmap.c:572
RSP: 0000:ffff8801d2d573e8 EFLAGS: 00010206
RAX: 000000000000004d RBX: ffff8801d41b63c0 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff85b382a0 RDI: 0000000000000282
RBP: ffff8801d2d57510 R08: ffff8801d2d56d38 R09: ffff8801d2d56d30
R10: ffff8801d2d56ca8 R11: 1ffff1003a5ceef3 R12: 0000000000000001
R13: ffff8801ca184e00 R14: ffff8801d2d57980 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8801db300000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2625f78e99 CR3: 00000001c6bd0000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
bpf_map_free_deferred+0xac/0xd0 kernel/bpf/syscall.c:209
process_one_work+0xbfa/0x1bd0 kernel/workqueue.c:2119
worker_thread+0x223/0x1860 kernel/workqueue.c:2253
sctp: [Deprecated]: syz-executor0 (pid 8450) Use of struct sctp_assoc_value
in delayed_ack socket option.
Use struct sctp_sack_info instead
kthread+0x39c/0x470 kernel/kthread.c:231
ret_from_fork+0x2a/0x40 arch/x86/entry/entry_64.S:431
Code: 85 00 05 00 00 48 8b 85 28 ff ff ff 48 03 98 90 00 00 00 48 8b 85 20
ff ff ff 48 05 68 02 00 00 48 89 85 30 ff ff ff 48 c1 e8 03 <42> 80 3c 38
00 0f 85 be 04 00 00 48 8b 85 20 ff ff ff 4c 8b a0
RIP: smap_list_remove kernel/bpf/sockmap.c:539 [inline] RSP:
ffff8801d2d573e8
RIP: sock_map_free+0x276/0x870 kernel/bpf/sockmap.c:572 RSP:
ffff8801d2d573e8
---[ end trace dbe84d06e63e996c ]---
Kernel panic - not syncing: Fatal exception in interrupt
Dumping ftrace buffer:
(ftrace buffer empty)
Kernel Offset: disabled
Rebooting in 86400 seconds..
---
This bug is generated by a dumb bot. It may contain errors.
See
https://goo.gl/tpsmEJ for details.
Direct all questions to
syzk...@googlegroups.com.
syzbot will keep track of this bug report.
Once a fix for this bug is committed, please reply to this email with:
#syz fix: exact-commit-title
To mark this as a duplicate of another syzbot report, please reply with:
#syz dup: exact-subject-of-another-report
If it's a one-off invalid bug report, please reply with:
#syz invalid
Note: if the crash happens again, it will cause creation of a new bug
report.
To upstream this report, please reply with:
#syz upstream