[moderation] [net?] [nfs?] BUG: unable to handle kernel paging request in percpu_counter_add_batch (2)

1 view
Skip to first unread message

syzbot

unread,
Aug 11, 2026, 8:22:37 PM (9 hours ago) Aug 11
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: f9a2394a2348 Merge tag 'mm-hotfixes-stable-2026-08-06-18-4..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=166f02c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=dd7fa9e412f91f87
dashboard link: https://syzkaller.appspot.com/bug?extid=3df77efdbb6dba91d1e4
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
CC: [Dai...@oracle.com an...@kernel.org c...@kernel.org da...@davemloft.net edum...@google.com ho...@kernel.org jla...@kernel.org ku...@kernel.org linux-...@vger.kernel.org linu...@vger.kernel.org ne...@brown.name net...@vger.kernel.org okor...@redhat.com pab...@redhat.com t...@talpey.com tro...@kernel.org]

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-f9a2394a.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/44414e53d5ba/vmlinux-f9a2394a.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a70c6743385f/bzImage-f9a2394a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3df77e...@syzkaller.appspotmail.com

BUG: unable to handle page fault for address: ffff88808c54a000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 1acd5067 P4D 1acd5067 PUD 0
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5311 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:percpu_counter_add_batch+0x50/0x1d0 lib/percpu_counter.c:98
Code: f6 48 b7 fc 48 89 5c 24 10 48 83 c3 58 49 89 de 49 c1 ee 03 43 80 3c 3e 00 74 08 48 89 df e8 07 7d 26 fd 48 89 1c 24 48 8b 03 <65> 8b 28 41 89 ef 41 c1 ff 1f 49 c1 e7 20 4c 89 6c 24 08 4d 01 ef
RSP: 0018:ffffc9000dc47810 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff888036dc4930 RCX: ffff888012f0ca80
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff888036dc48d8
RBP: ffffc9000dc47908 R08: ffff888012c3e03f R09: 1ffff11002587c07
R10: dffffc0000000000 R11: ffffed1002587c08 R12: 0000000000000020
R13: 0000000000000001 R14: 1ffff11006db8926 R15: dffffc0000000000
FS: 00007f711d27e6c0(0000) GS:ffff88808c54a000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffff88808c54a000 CR3: 000000001fde5000 CR4: 0000000000352ef0
Call Trace:
<TASK>
percpu_counter_add include/linux/percpu_counter.h:71 [inline]
percpu_counter_inc include/linux/percpu_counter.h:267 [inline]
svc_xprt_enqueue+0x2ee/0x8b0 net/sunrpc/svc_xprt.c:524
svc_xprt_received+0x10f/0x150 net/sunrpc/svc_xprt.c:248
svc_add_new_perm_xprt net/sunrpc/svc_xprt.c:260 [inline]
_svc_xprt_create+0x3d8/0x600 net/sunrpc/svc_xprt.c:290
svc_xprt_create_from_sa net/sunrpc/svc_xprt.c:332 [inline]
svc_xprt_create+0x1aa/0x280 net/sunrpc/svc_xprt.c:387
__write_ports_addxprt fs/nfsd/nfsctl.c:774 [inline]
__write_ports fs/nfsd/nfsctl.c:808 [inline]
write_ports+0x71a/0xd10 fs/nfsd/nfsctl.c:861
nfsctl_transaction_write+0x10f/0x160 fs/nfsd/nfsctl.c:112
vfs_write+0x296/0xba0 fs/read_write.c:685
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f711c39e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f711d27dfe8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f711c625fa0 RCX: 00007f711c39e0d9
RDX: 0000000000000005 RSI: 0000200000000300 RDI: 0000000000000004
RBP: 00007f711c435024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f711c626038 R14: 00007f711c625fa0 R15: 00007ffc740e4ce8
</TASK>
Modules linked in:
CR2: ffff88808c54a000
---[ end trace 0000000000000000 ]---
RIP: 0010:percpu_counter_add_batch+0x50/0x1d0 lib/percpu_counter.c:98
Code: f6 48 b7 fc 48 89 5c 24 10 48 83 c3 58 49 89 de 49 c1 ee 03 43 80 3c 3e 00 74 08 48 89 df e8 07 7d 26 fd 48 89 1c 24 48 8b 03 <65> 8b 28 41 89 ef 41 c1 ff 1f 49 c1 e7 20 4c 89 6c 24 08 4d 01 ef
RSP: 0018:ffffc9000dc47810 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff888036dc4930 RCX: ffff888012f0ca80
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff888036dc48d8
RBP: ffffc9000dc47908 R08: ffff888012c3e03f R09: 1ffff11002587c07
R10: dffffc0000000000 R11: ffffed1002587c08 R12: 0000000000000020
R13: 0000000000000001 R14: 1ffff11006db8926 R15: dffffc0000000000
FS: 00007f711d27e6c0(0000) GS:ffff88808c54a000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffff88808c54a000 CR3: 000000001fde5000 CR4: 0000000000352ef0
----------------
Code disassembly (best guess):
0: f6 48 b7 fc testb $0xfc,-0x49(%rax)
4: 48 89 5c 24 10 mov %rbx,0x10(%rsp)
9: 48 83 c3 58 add $0x58,%rbx
d: 49 89 de mov %rbx,%r14
10: 49 c1 ee 03 shr $0x3,%r14
14: 43 80 3c 3e 00 cmpb $0x0,(%r14,%r15,1)
19: 74 08 je 0x23
1b: 48 89 df mov %rbx,%rdi
1e: e8 07 7d 26 fd call 0xfd267d2a
23: 48 89 1c 24 mov %rbx,(%rsp)
27: 48 8b 03 mov (%rbx),%rax
* 2a: 65 8b 28 mov %gs:(%rax),%ebp <-- trapping instruction
2d: 41 89 ef mov %ebp,%r15d
30: 41 c1 ff 1f sar $0x1f,%r15d
34: 49 c1 e7 20 shl $0x20,%r15
38: 4c 89 6c 24 08 mov %r13,0x8(%rsp)
3d: 4d 01 ef add %r13,%r15


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages