[moderation] [audit?] KCSAN: data-race in audit_log_start / audit_receive (3)

3 views
Skip to first unread message

syzbot

unread,
Jul 13, 2025, 8:27:30 AM7/13/25
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f31a806a62e Merge tag 'mm-hotfixes-stable-2025-07-11-16-1..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=137ace8c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a2f5ccd29a82f8aa
dashboard link: https://syzkaller.appspot.com/bug?extid=6d907adde6b34c3139e0
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
CC: [au...@vger.kernel.org epa...@redhat.com linux-...@vger.kernel.org pa...@paul-moore.com]

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0d6fd83de663/disk-3f31a806.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9300f7fd06ab/vmlinux-3f31a806.xz
kernel image: https://storage.googleapis.com/syzbot-assets/2fc91c8f1294/bzImage-3f31a806.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6d907a...@syzkaller.appspotmail.com

==================================================================
BUG: KCSAN: data-race in audit_log_start / audit_receive

write to 0xffffffff88e73450 of 8 bytes by task 8927 on cpu 1:
audit_ctl_unlock kernel/audit.c:243 [inline]
audit_receive+0x200d/0x2180 kernel/audit.c:1581
netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
netlink_unicast+0x5a5/0x680 net/netlink/af_netlink.c:1346
netlink_sendmsg+0x58b/0x6b0 net/netlink/af_netlink.c:1896
sock_sendmsg_nosec net/socket.c:712 [inline]
__sock_sendmsg+0x145/0x180 net/socket.c:727
sock_sendmsg+0xc1/0x130 net/socket.c:750
splice_to_socket+0x5fe/0x9a0 fs/splice.c:883
do_splice_from fs/splice.c:935 [inline]
direct_splice_actor+0x156/0x2a0 fs/splice.c:1158
splice_direct_to_actor+0x312/0x680 fs/splice.c:1102
do_splice_direct_actor fs/splice.c:1201 [inline]
do_splice_direct+0xda/0x150 fs/splice.c:1227
do_sendfile+0x380/0x650 fs/read_write.c:1370
__do_sys_sendfile64 fs/read_write.c:1431 [inline]
__se_sys_sendfile64 fs/read_write.c:1417 [inline]
__x64_sys_sendfile64+0x105/0x150 fs/read_write.c:1417
x64_sys_call+0xb39/0x2fb0 arch/x86/include/generated/asm/syscalls_64.h:41
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xd2/0x200 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

read to 0xffffffff88e73450 of 8 bytes by task 3034 on cpu 0:
audit_ctl_owner_current kernel/audit.c:256 [inline]
audit_log_start+0x129/0x6c0 kernel/audit.c:1881
common_lsm_audit+0x66/0x230 security/lsm_audit.c:442
slow_avc_audit+0x104/0x140 security/selinux/avc.c:779
avc_audit security/selinux/include/avc.h:127 [inline]
avc_has_perm+0x128/0x150 security/selinux/avc.c:1198
sock_has_perm security/selinux/hooks.c:4765 [inline]
selinux_socket_recvmsg+0x175/0x1b0 security/selinux/hooks.c:5112
security_socket_recvmsg+0x50/0x90 security/security.c:4691
sock_recvmsg+0x38/0x170 net/socket.c:1037
____sys_recvmsg+0xf5/0x280 net/socket.c:2786
___sys_recvmsg+0x11f/0x370 net/socket.c:2828
__sys_recvmsg net/socket.c:2861 [inline]
__do_sys_recvmsg net/socket.c:2867 [inline]
__se_sys_recvmsg net/socket.c:2864 [inline]
__x64_sys_recvmsg+0xd1/0x160 net/socket.c:2864
x64_sys_call+0xf19/0x2fb0 arch/x86/include/generated/asm/syscalls_64.h:48
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xd2/0x200 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

value changed: 0xffff888119f0e180 -> 0x0000000000000000

Reported by Kernel Concurrency Sanitizer on:
CPU: 0 UID: 0 PID: 3034 Comm: dhcpcd Not tainted 6.16.0-rc5-syzkaller-00266-g3f31a806a62e #0 PREEMPT(voluntary)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
==================================================================
audit: audit_backlog=65 > audit_backlog_limit=64
audit: audit_lost=12355 audit_rate_limit=0 audit_backlog_limit=64
audit: backlog limit exceeded
audit: audit_backlog=65 > audit_backlog_limit=64
audit: audit_lost=12356 audit_rate_limit=0 audit_backlog_limit=64
audit: backlog limit exceeded
audit: audit_backlog=65 > audit_backlog_limit=64
audit: audit_lost=13600 audit_rate_limit=0 audit_backlog_limit=64
audit: backlog limit exceeded
audit: audit_backlog=65 > audit_backlog_limit=64


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages