[Android 5.10] KASAN: use-after-free Read in unaccount_page_cache_page (3)

0 views
Skip to first unread message

syzbot

unread,
Jul 21, 2026, 8:58:28 AM (18 hours ago) Jul 21
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 50b3a256e550 Merge 5.10.260 into android13-5.10-lts
git tree: android13-5.10-lts
console output: https://syzkaller.appspot.com/x/log.txt?x=15bcf789580000
kernel config: https://syzkaller.appspot.com/x/.config?x=57bdfa4a173e5087
dashboard link: https://syzkaller.appspot.com/bug?extid=6ed05d402add97425e14
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=153072b9580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=168de746580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/34994db436ce/disk-50b3a256.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/7855257a6b73/vmlinux-50b3a256.xz
kernel image: https://storage.googleapis.com/syzbot-assets/6367ad2e120a/bzImage-50b3a256.xz
mounted in repro #1: https://storage.googleapis.com/syzbot-assets/00a1725ade50/mount_0.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=128de746580000)
mounted in repro #2: https://storage.googleapis.com/syzbot-assets/f4d2e7ee30b4/mount_4.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=1499fc32580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6ed05d...@syzkaller.appspotmail.com

F2FS-fs (loop0): Cannot turn on quotas: -2 on 0
F2FS-fs (loop0): Mounted with checkpoint version = 48b305e4
==================================================================
BUG: KASAN: use-after-free in cleancache_fs_enabled_mapping include/linux/cleancache.h:56 [inline]
BUG: KASAN: use-after-free in cleancache_invalidate_page include/linux/cleancache.h:110 [inline]
BUG: KASAN: use-after-free in unaccount_page_cache_page+0x9dc/0xac0 mm/filemap.c:175
Read of size 4 at addr ffff888112ee6470 by task syz.0.26/430

CPU: 1 PID: 430 Comm: syz.0.26 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026
Call Trace:
__dump_stack+0x21/0x24 lib/dump_stack.c:77
dump_stack_lvl+0x1a7/0x208 lib/dump_stack.c:118
print_address_description+0x7f/0x2c0 mm/kasan/report.c:248
__kasan_report mm/kasan/report.c:435 [inline]
kasan_report+0x100/0x140 mm/kasan/report.c:452
__asan_report_load4_noabort+0x14/0x20 mm/kasan/report_generic.c:308
cleancache_fs_enabled_mapping include/linux/cleancache.h:56 [inline]
cleancache_invalidate_page include/linux/cleancache.h:110 [inline]
unaccount_page_cache_page+0x9dc/0xac0 mm/filemap.c:175
__delete_from_page_cache+0xc3/0x470 mm/filemap.c:243
__remove_mapping+0x581/0x6b0 mm/vmscan.c:985
shrink_page_list+0x21ee/0x4160 mm/vmscan.c:1498
shrink_inactive_list+0x90c/0xef0 mm/vmscan.c:2075
shrink_list mm/vmscan.c:2294 [inline]
shrink_lruvec+0x2806/0x2d70 mm/vmscan.c:5473
shrink_node_memcgs mm/vmscan.c:5660 [inline]
shrink_node+0xee0/0x2690 mm/vmscan.c:5690
shrink_zones mm/vmscan.c:5896 [inline]
do_try_to_free_pages+0x602/0x1590 mm/vmscan.c:5954
try_to_free_mem_cgroup_pages+0x261/0x610 mm/vmscan.c:6272
try_charge+0x426/0x1580 mm/memcontrol.c:2745
__mem_cgroup_charge+0x148/0x6d0 mm/memcontrol.c:6871
mem_cgroup_charge include/linux/memcontrol.h:458 [inline]
__add_to_page_cache_locked+0x208/0x9b0 mm/filemap.c:854
add_to_page_cache_lru+0xa7/0x210 mm/filemap.c:948
page_cache_ra_unbounded+0x438/0x790 mm/readahead.c:232
do_page_cache_ra mm/readahead.c:277 [inline]
ondemand_readahead+0x780/0xbc0 mm/readahead.c:559
page_cache_sync_ra+0x250/0x2a0 mm/readahead.c:587
page_cache_sync_readahead include/linux/pagemap.h:837 [inline]
f2fs_readdir+0x43e/0x970 fs/f2fs/dir.c:1166
iterate_dir+0x25c/0x560 fs/readdir.c:-1
__do_sys_getdents fs/readdir.c:286 [inline]
__se_sys_getdents+0xf2/0x250 fs/readdir.c:271
__x64_sys_getdents+0x7b/0x90 fs/readdir.c:271
do_syscall_64+0x31/0x40 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x61/0xcb
RIP: 0033:0x7ff9f14d9e99
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ff9f133b028 EFLAGS: 00000246 ORIG_RAX: 000000000000004e
RAX: ffffffffffffffda RBX: 00007ff9f1761fa0 RCX: 00007ff9f14d9e99
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000004
RBP: 00007ff9f156feaf R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ff9f1762038 R14: 00007ff9f1761fa0 R15: 00007ffc149b9d38

Allocated by task 401:
kasan_save_stack mm/kasan/common.c:38 [inline]
kasan_set_track mm/kasan/common.c:45 [inline]
set_alloc_info mm/kasan/common.c:430 [inline]
____kasan_kmalloc mm/kasan/common.c:509 [inline]
__kasan_kmalloc+0xd4/0x100 mm/kasan/common.c:518
kasan_kmalloc include/linux/kasan.h:254 [inline]
kmem_cache_alloc_trace+0x179/0x2e0 mm/slub.c:2979
kmalloc include/linux/slab.h:555 [inline]
kzalloc include/linux/slab.h:667 [inline]
alloc_super+0x5a/0x7d0 fs/super.c:203
sget+0x1e2/0x4c0 fs/super.c:627
mount_bdev+0xec/0x380 fs/super.c:1415
f2fs_mount+0x34/0x40 fs/f2fs/super.c:4598
legacy_get_tree+0xed/0x190 fs/fs_context.c:593
vfs_get_tree+0x89/0x260 fs/super.c:1572
do_new_mount+0x25a/0xa30 fs/namespace.c:3006
path_mount+0x581/0xca0 fs/namespace.c:3336
do_mount fs/namespace.c:3349 [inline]
__do_sys_mount fs/namespace.c:3557 [inline]
__se_sys_mount+0x320/0x390 fs/namespace.c:3534
__x64_sys_mount+0xbf/0xd0 fs/namespace.c:3534
do_syscall_64+0x31/0x40 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x61/0xcb

Freed by task 53:
kasan_save_stack mm/kasan/common.c:38 [inline]
kasan_set_track+0x4a/0x70 mm/kasan/common.c:45
kasan_set_free_info+0x23/0x40 mm/kasan/generic.c:370
____kasan_slab_free+0x125/0x160 mm/kasan/common.c:362
__kasan_slab_free+0x11/0x20 mm/kasan/common.c:370
kasan_slab_free include/linux/kasan.h:220 [inline]
slab_free_hook mm/slub.c:1600 [inline]
slab_free_freelist_hook+0xc5/0x190 mm/slub.c:1626
slab_free mm/slub.c:3208 [inline]
kfree+0xc0/0x270 mm/slub.c:4196
destroy_super_work+0x40/0x50 fs/super.c:165
process_one_work+0x6fd/0xbc0 kernel/workqueue.c:2301
worker_thread+0xa8e/0x13c0 kernel/workqueue.c:2447
kthread+0x324/0x3b0 kernel/kthread.c:313
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298

Last potentially related work creation:
kasan_save_stack+0x3a/0x60 mm/kasan/common.c:38
__kasan_record_aux_stack+0xd2/0x100 mm/kasan/generic.c:348
kasan_record_aux_stack_noalloc+0xb/0x10 mm/kasan/generic.c:358
insert_work+0x51/0x320 kernel/workqueue.c:1352
__queue_work+0x91f/0xca0 kernel/workqueue.c:1518
queue_work_on+0xe6/0x140 kernel/workqueue.c:1545
queue_work include/linux/workqueue.h:515 [inline]
schedule_work include/linux/workqueue.h:576 [inline]
destroy_super_rcu+0xd1/0xe0 fs/super.c:172
rcu_do_batch+0x488/0xaf0 kernel/rcu/tree.c:2494
rcu_core+0x50a/0xca0 kernel/rcu/tree.c:2735
rcu_core_si+0x9/0x10 kernel/rcu/tree.c:2748
__do_softirq+0x255/0x563 kernel/softirq.c:309

Second to last potentially related work creation:
kasan_save_stack+0x3a/0x60 mm/kasan/common.c:38
__kasan_record_aux_stack+0xd2/0x100 mm/kasan/generic.c:348
kasan_record_aux_stack_noalloc+0xb/0x10 mm/kasan/generic.c:358
__call_rcu kernel/rcu/tree.c:2980 [inline]
call_rcu+0x11a/0x1090 kernel/rcu/tree.c:3054
__put_super+0x254/0x2b0 fs/super.c:299
put_super fs/super.c:313 [inline]
deactivate_locked_super+0xd4/0x100 fs/super.c:346
mount_bdev+0x288/0x380 fs/super.c:1444
f2fs_mount+0x34/0x40 fs/f2fs/super.c:4598
legacy_get_tree+0xed/0x190 fs/fs_context.c:593
vfs_get_tree+0x89/0x260 fs/super.c:1572
do_new_mount+0x25a/0xa30 fs/namespace.c:3006
path_mount+0x581/0xca0 fs/namespace.c:3336
do_mount fs/namespace.c:3349 [inline]
__do_sys_mount fs/namespace.c:3557 [inline]
__se_sys_mount+0x320/0x390 fs/namespace.c:3534
__x64_sys_mount+0xbf/0xd0 fs/namespace.c:3534
do_syscall_64+0x31/0x40 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x61/0xcb

The buggy address belongs to the object at ffff888112ee6000
which belongs to the cache kmalloc-2k of size 2048
The buggy address is located 1136 bytes inside of
2048-byte region [ffff888112ee6000, ffff888112ee6800)
The buggy address belongs to the page:
page:ffffea00044bb800 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x112ee0
head:ffffea00044bb800 order:3 compound_mapcount:0 compound_pincount:0
flags: 0x4000000000010200(slab|head)
raw: 4000000000010200 dead000000000100 dead000000000122 ffff888100042d80
raw: 0000000000000000 0000000000080008 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 3, migratetype Unmovable, gfp_mask 0x1d2a20(GFP_ATOMIC|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC|__GFP_HARDWALL), pid 402, ts 35241989602, free_ts 34229388576
set_page_owner include/linux/page_owner.h:35 [inline]
post_alloc_hook mm/page_alloc.c:2456 [inline]
prep_new_page+0x176/0x190 mm/page_alloc.c:2462
get_page_from_freelist+0x225f/0x23f0 mm/page_alloc.c:4254
__alloc_pages_nodemask+0x29a/0x640 mm/page_alloc.c:5384
alloc_slab_page mm/slub.c:-1 [inline]
allocate_slab mm/slub.c:1813 [inline]
new_slab+0x84/0x3f0 mm/slub.c:1874
new_slab_objects mm/slub.c:2632 [inline]
___slab_alloc+0x2f8/0x4c0 mm/slub.c:2796
__slab_alloc+0x63/0xa0 mm/slub.c:2836
slab_alloc_node mm/slub.c:2918 [inline]
slab_alloc mm/slub.c:2960 [inline]
__kmalloc_track_caller+0x1e4/0x310 mm/slub.c:4541
__kmalloc_reserve net/core/skbuff.c:144 [inline]
__alloc_skb+0xdc/0x520 net/core/skbuff.c:212
alloc_skb include/linux/skbuff.h:1126 [inline]
alloc_skb_with_frags+0xa3/0x560 net/core/skbuff.c:6006
sock_alloc_send_pskb+0x87f/0x9a0 net/core/sock.c:2393
sock_alloc_send_skb+0x32/0x40 net/core/sock.c:2410
mld_newpack+0x1b3/0x9e0 net/ipv6/mcast.c:1604
add_grhead net/ipv6/mcast.c:1707 [inline]
add_grec+0xedf/0x1330 net/ipv6/mcast.c:1838
mld_send_cr net/ipv6/mcast.c:1964 [inline]
mld_ifc_timer_expire+0x797/0xc60 net/ipv6/mcast.c:2471
call_timer_fn+0x38/0x290 kernel/time/timer.c:1450
expire_timers kernel/time/timer.c:1495 [inline]
__run_timers+0x637/0x9a0 kernel/time/timer.c:1789
page last free stack trace:
reset_page_owner include/linux/page_owner.h:28 [inline]
free_pages_prepare mm/page_alloc.c:1349 [inline]
__free_pages_ok+0x80b/0x830 mm/page_alloc.c:1629
free_the_page mm/page_alloc.c:5445 [inline]
__free_pages+0xd8/0x390 mm/page_alloc.c:5454
__free_slab+0xcf/0x190 mm/slub.c:1899
free_slab mm/slub.c:1914 [inline]
discard_slab mm/slub.c:1920 [inline]
unfreeze_partials+0x150/0x180 mm/slub.c:2415
put_cpu_partial+0xc1/0x180 mm/slub.c:2451
__slab_free+0x2c9/0x3a0 mm/slub.c:3100
do_slab_free mm/slub.c:3196 [inline]
___cache_free+0x10e/0x130 mm/slub.c:3215
qlink_free+0x50/0x90 mm/kasan/quarantine.c:157
qlist_free_all+0x5f/0xb0 mm/kasan/quarantine.c:176
kasan_quarantine_reduce+0x14a/0x160 mm/kasan/quarantine.c:283
__kasan_slab_alloc+0x2f/0xe0 mm/kasan/common.c:440
kasan_slab_alloc include/linux/kasan.h:244 [inline]
slab_post_alloc_hook+0x5d/0x2f0 mm/slab.h:580
slab_alloc_node mm/slub.c:2952 [inline]
slab_alloc mm/slub.c:2960 [inline]
__kmalloc+0x17b/0x330 mm/slub.c:4034
kmalloc include/linux/slab.h:560 [inline]
kzalloc include/linux/slab.h:667 [inline]
fib_create_info+0x8eb/0x1ed0 net/ipv4/fib_semantics.c:1477
fib_table_insert+0xc2/0x1d50 net/ipv4/fib_trie.c:1170
fib_magic net/ipv4/fib_frontend.c:1107 [inline]
fib_add_ifaddr+0xbe3/0xf90 net/ipv4/fib_frontend.c:1153

Memory state around the buggy address:
ffff888112ee6300: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
ffff888112ee6380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff888112ee6400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
^
ffff888112ee6480: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
ffff888112ee6500: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages