[moderation] [nfc?] general protection fault in nfcmrvl_bulk_complete

0 views
Skip to first unread message

syzbot

unread,
Aug 21, 2026, 6:52:31 AM (24 hours ago) Aug 21
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 8d3ae59288f1 Linux 7.2
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=129836c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1d67342c314f228d
dashboard link: https://syzkaller.appspot.com/bug?extid=bf40961cc30209eb1619
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
CC: [da...@ixit.cz kr...@kernel.org linux-...@vger.kernel.org net...@vger.kernel.org oe-lin...@lists.linux.dev]

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d7827cbad2ef/disk-8d3ae592.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/eb86c4d0d627/vmlinux-8d3ae592.xz
kernel image: https://storage.googleapis.com/syzbot-assets/108cb159a1ee/bzImage-8d3ae592.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+bf4096...@syzkaller.appspotmail.com

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
CPU: 0 UID: 0 PID: 13777 Comm: syz.1.2557 Tainted: G S L syzkaller #0 PREEMPT(full)
Tainted: [S]=CPU_OUT_OF_SPEC, [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/16/2026
RIP: 0010:nfcmrvl_bulk_complete+0x33f/0x630 drivers/nfc/nfcmrvl/usb.c:71
Code: c1 e9 03 80 3c 01 00 0f 85 f8 02 00 00 49 8b ac 24 b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7d 20 48 89 f9 48 c1 e9 03 <80> 3c 01 00 0f 85 9e 02 00 00 4c 8b 7d 20 49 8d 47 18 48 89 c1 48
RSP: 0018:ffffc90000007b88 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: ffff8880736f5200 RCX: 0000000000000004
RDX: 0000000000000009 RSI: ffffffff86771a93 RDI: 0000000000000020
RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff888035cba838
R13: ffff888035cba848 R14: ffff8880736f528c R15: ffff8880736f5240
FS: 00007f783b1d56c0(0000) GS:ffff888123bde000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff9447eb7c0 CR3: 00000000480be000 CR4: 00000000003526f0
Call Trace:
<IRQ>
__usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657
usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741
dummy_timer+0xdb2/0x36f0 drivers/usb/gadget/udc/dummy_hcd.c:2019
__run_hrtimer kernel/time/hrtimer.c:2032 [inline]
__hrtimer_run_queues+0x462/0x9c0 kernel/time/hrtimer.c:2096
hrtimer_run_softirq+0x17d/0x2c0 kernel/time/hrtimer.c:2113
handle_softirqs+0x1ea/0x9b0 kernel/softirq.c:622
__do_softirq kernel/softirq.c:656 [inline]
invoke_softirq kernel/softirq.c:496 [inline]
__irq_exit_rcu+0x162/0x210 kernel/softirq.c:735
irq_exit_rcu+0x9/0x30 kernel/softirq.c:752
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0xa3/0xc0 arch/x86/kernel/apic/apic.c:1062
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:179 [inline]
RIP: 0010:_raw_spin_unlock_irqrestore+0x31/0x80 kernel/locking/spinlock.c:198
Code: f5 53 48 8b 74 24 10 48 89 fb 48 83 c7 18 e8 96 a0 26 f6 48 89 df e8 1e f0 26 f6 f7 c5 00 02 00 00 75 23 9c 58 f6 c4 02 75 37 <bf> 01 00 00 00 e8 c5 fd 15 f6 65 8b 05 ee b6 c4 08 85 c0 74 16 5b
RSP: 0018:ffffc90004cc7440 EFLAGS: 00000246
RAX: 0000000000000006 RBX: ffff888034eaf210 RCX: 0000000000000040
RDX: 0000000000000000 RSI: ffffffff8e3acef2 RDI: ffffffff8c600380
RBP: 0000000000000283 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000283
R13: ffff888034eaf210 R14: ffff88807d4122e8 R15: ffff88807d412008
spin_unlock_irqrestore include/linux/spinlock.h:408 [inline]
__pm_runtime_idle+0xc7/0x1a0 drivers/base/power/runtime.c:1130
nfcmrvl_usb_nci_open+0x133/0x1b0 drivers/nfc/nfcmrvl/usb.c:184
nfcmrvl_nci_open+0xcf/0x120 drivers/nfc/nfcmrvl/main.c:28
nci_open_device net/nfc/nci/core.c:490 [inline]
nci_dev_up+0x17b/0x680 net/nfc/nci/core.c:643
nfc_dev_up+0x1b6/0x3a0 net/nfc/core.c:118
nfc_genl_dev_up+0xa5/0xf0 net/nfc/netlink.c:775
genl_family_rcv_msg_doit+0x214/0x300 net/netlink/genetlink.c:1114
genl_family_rcv_msg net/netlink/genetlink.c:1194 [inline]
genl_rcv_msg+0x560/0x800 net/netlink/genetlink.c:1209
netlink_rcv_skb+0x159/0x420 net/netlink/af_netlink.c:2556
genl_rcv+0x28/0x40 net/netlink/genetlink.c:1218
netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
netlink_unicast+0x585/0x850 net/netlink/af_netlink.c:1345
netlink_sendmsg+0x8b0/0xda0 net/netlink/af_netlink.c:1900
sock_sendmsg_nosec net/socket.c:775 [inline]
__sock_sendmsg net/socket.c:790 [inline]
____sys_sendmsg+0xa4d/0xbe0 net/socket.c:2684
___sys_sendmsg+0x190/0x1e0 net/socket.c:2738
__sys_sendmsg+0x160/0x210 net/socket.c:2770
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f783cf9e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f783b1d5028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f783d226090 RCX: 00007f783cf9e0d9
RDX: 0000000000000000 RSI: 0000200000001000 RDI: 0000000000000005
RBP: 00007f783d035024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f783d226128 R14: 00007f783d226090 R15: 00007ffc632527a8
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:nfcmrvl_bulk_complete+0x33f/0x630 drivers/nfc/nfcmrvl/usb.c:71
Code: c1 e9 03 80 3c 01 00 0f 85 f8 02 00 00 49 8b ac 24 b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7d 20 48 89 f9 48 c1 e9 03 <80> 3c 01 00 0f 85 9e 02 00 00 4c 8b 7d 20 49 8d 47 18 48 89 c1 48
RSP: 0018:ffffc90000007b88 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: ffff8880736f5200 RCX: 0000000000000004
RDX: 0000000000000009 RSI: ffffffff86771a93 RDI: 0000000000000020
RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff888035cba838
R13: ffff888035cba848 R14: ffff8880736f528c R15: ffff8880736f5240
FS: 00007f783b1d56c0(0000) GS:ffff888123bde000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff9447eb7c0 CR3: 00000000480be000 CR4: 00000000003526f0
----------------
Code disassembly (best guess):
0: c1 e9 03 shr $0x3,%ecx
3: 80 3c 01 00 cmpb $0x0,(%rcx,%rax,1)
7: 0f 85 f8 02 00 00 jne 0x305
d: 49 8b ac 24 b8 02 00 mov 0x2b8(%r12),%rbp
14: 00
15: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
1c: fc ff df
1f: 48 8d 7d 20 lea 0x20(%rbp),%rdi
23: 48 89 f9 mov %rdi,%rcx
26: 48 c1 e9 03 shr $0x3,%rcx
* 2a: 80 3c 01 00 cmpb $0x0,(%rcx,%rax,1) <-- trapping instruction
2e: 0f 85 9e 02 00 00 jne 0x2d2
34: 4c 8b 7d 20 mov 0x20(%rbp),%r15
38: 49 8d 47 18 lea 0x18(%r15),%rax
3c: 48 89 c1 mov %rax,%rcx
3f: 48 rex.W


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages