Groups
Sign in
Groups
syzkaller-bugs
Conversations
About
Send feedback
Help
Sort By Relevance
Sort By Date
1–30 of many
syzbot
3:49 AM
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_release_resources
slab-
use
-
after
-
free
in media_device_unregister+0x154/0x470 Read of size 8 at addr ffff888058df4210 by task kworker/0:1/9 CPU: 0 UID: 0 PID: 9 Comm: kworker/0:1 Not tainted 6.10
unread,
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_release_resources
slab-
use
-
after
-
free
in media_device_unregister+0x154/0x470 Read of size 8 at addr ffff888058df4210 by task kworker/0:1/9 CPU: 0 UID: 0 PID: 9 Comm: kworker/0:1 Not tainted 6.10
3:49 AM
syzbot
,
Edward Adam Davis
7
Jul 30
[syzbot] [usb?] KASAN: slab-use-after-free Read in hdm_disconnect
slab-
use
-
after
-
free
Read in hdm_disconnect usb 1-1: New USB device found, idVendor=0424, idProduct=c001, bcdDevice=1c.8f usb 1-1: New USB device strings: Mfr=1, Product=2,
unread,
[syzbot] [usb?] KASAN: slab-use-after-free Read in hdm_disconnect
slab-
use
-
after
-
free
Read in hdm_disconnect usb 1-1: New USB device found, idVendor=0424, idProduct=c001, bcdDevice=1c.8f usb 1-1: New USB device strings: Mfr=1, Product=2,
Jul 30
syzbot
, …
Edward Adam Davis
5
Jul 26
[syzbot] [wireless?] [usb?] KASAN: use-after-free Read in rtw_load_firmware_cb
:5903
process_one_work
+0x9c5/0x1b40 kernel/workqueue.c:3231 process_scheduled_works kernel/workqueue.c:3312 [inline] worker_thread+0x6c8/0xf20 kernel/workqueue
unread,
[syzbot] [wireless?] [usb?] KASAN: use-after-free Read in rtw_load_firmware_cb
:5903
process_one_work
+0x9c5/0x1b40 kernel/workqueue.c:3231 process_scheduled_works kernel/workqueue.c:3312 [inline] worker_thread+0x6c8/0xf20 kernel/workqueue
Jul 26
Pengfei Xu
Jul 25
[Syzkaller & bisect] There is KASAN: slab-use-after-free Read in __nf_unregister_net_hook in v6.10
slab-
use
-
after
-
free
Read in __nf_unregister_net_hook in v6.10: Found the first bad commit: " f42bcd168d03 bpf: teach verifier actual bounds of bpf_get_smp_processor_id
unread,
[Syzkaller & bisect] There is KASAN: slab-use-after-free Read in __nf_unregister_net_hook in v6.10
slab-
use
-
after
-
free
Read in __nf_unregister_net_hook in v6.10: Found the first bad commit: " f42bcd168d03 bpf: teach verifier actual bounds of bpf_get_smp_processor_id
Jul 25
syzbot
Jul 24
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in mgmt_remove_adv_monitor_sync
slab-
use
-
after
-
free
in mgmt_remove_adv_monitor_sync+0x3a/0xd0 net/bluetooth/mgmt.c:5444 Read of size 8 at addr ffff88802aac0f18 by task kworker/u9:0/54 CPU: 0 PID: 54 Comm
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in mgmt_remove_adv_monitor_sync
slab-
use
-
after
-
free
in mgmt_remove_adv_monitor_sync+0x3a/0xd0 net/bluetooth/mgmt.c:5444 Read of size 8 at addr ffff88802aac0f18 by task kworker/u9:0/54 CPU: 0 PID: 54 Comm
Jul 24
syzbot
Jul 23
[syzbot] [bcachefs?] KASAN: slab-use-after-free Read in percpu_ref_put
slab-
use
-
after
-
free
in __ref_is_percpu include/linux/percpu-refcount.h:174 [inline] BUG: KASAN: slab-
use
-
after
-
free
in percpu_ref_put_many include/linux/percpu-refcount
unread,
[syzbot] [bcachefs?] KASAN: slab-use-after-free Read in percpu_ref_put
slab-
use
-
after
-
free
in __ref_is_percpu include/linux/percpu-refcount.h:174 [inline] BUG: KASAN: slab-
use
-
after
-
free
in percpu_ref_put_many include/linux/percpu-refcount
Jul 23
syzbot
, …
Hillf Danton
17
Jul 18
[syzbot] [fs?] KASAN: slab-use-after-free Read in lockref_get
slab-
use
-
after
-
free
Read in lockref_get wlan1: authentication with 08:02:11:00:00:00 timed out ==================================================================
unread,
[syzbot] [fs?] KASAN: slab-use-after-free Read in lockref_get
slab-
use
-
after
-
free
Read in lockref_get wlan1: authentication with 08:02:11:00:00:00 timed out ==================================================================
Jul 18
syzbot
Jul 15
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in set_powered_sync
slab-
use
-
after
-
free
in set_powered_sync+0xc1/0xd0 net/bluetooth/mgmt.c:1354 Read of size 8 at addr ffff88804642e318 by task kworker/u33:2/5212 CPU: 3 PID: 5212 Comm: kworker
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in set_powered_sync
slab-
use
-
after
-
free
in set_powered_sync+0xc1/0xd0 net/bluetooth/mgmt.c:1354 Read of size 8 at addr ffff88804642e318 by task kworker/u33:2/5212 CPU: 3 PID: 5212 Comm: kworker
Jul 15
syzbot
Jul 4
[syzbot] [lsm?] KASAN: slab-use-after-free Read in smack_socket_sock_rcv_skb
slab-
use
-
after
-
free
in smack_socket_sock_rcv_skb+0xec/0x13a0 security/smack/smack_lsm.c:4142 Read of size 8 at addr ffff888023db9498 by task kworker/u9:7/5088 CPU: 1 PID
unread,
[syzbot] [lsm?] KASAN: slab-use-after-free Read in smack_socket_sock_rcv_skb
slab-
use
-
after
-
free
in smack_socket_sock_rcv_skb+0xec/0x13a0 security/smack/smack_lsm.c:4142 Read of size 8 at addr ffff888023db9498 by task kworker/u9:7/5088 CPU: 1 PID
Jul 4
syzbot
Jul 3
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_recv_acldata
slab-
use
-
after
-
free
in l2cap_recv_reset net/bluetooth/l2cap_core.c:7469 [inline] BUG: KASAN: slab-
use
-
after
-
free
in l2cap_recv_acldata+0x325/0x1550 net/bluetooth
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_recv_acldata
slab-
use
-
after
-
free
in l2cap_recv_reset net/bluetooth/l2cap_core.c:7469 [inline] BUG: KASAN: slab-
use
-
after
-
free
in l2cap_recv_acldata+0x325/0x1550 net/bluetooth
Jul 3
syzbot
, …
Florian Westphal
27
Jul 8
[syzbot] [netfilter?] KASAN: slab-use-after-free Read in nf_tables_trans_destroy_work
slab-
use
-
after
-
free
in nft_ctx_update include/net/netfilter/nf_tables.h:1831 [inline] BUG: KASAN: slab-
use
-
after
-
free
in nft_commit_release net/netfilter/nf_tables_api
unread,
[syzbot] [netfilter?] KASAN: slab-use-after-free Read in nf_tables_trans_destroy_work
slab-
use
-
after
-
free
in nft_ctx_update include/net/netfilter/nf_tables.h:1831 [inline] BUG: KASAN: slab-
use
-
after
-
free
in nft_commit_release net/netfilter/nf_tables_api
Jul 8
syzbot
, …
James Chapman
6
Jul 2
[syzbot] [net?] KASAN: slab-use-after-free Read in l2tp_tunnel_del_work
slab-
use
-
after
-
free
in l2tp_tunnel_del_work+0xe5/0x330 net/l2tp/l2tp_core.c:1334 > Read of size 8 at addr ffff88802361a0b8 by task kworker/u8:1/12 I think this is related
unread,
[syzbot] [net?] KASAN: slab-use-after-free Read in l2tp_tunnel_del_work
slab-
use
-
after
-
free
in l2tp_tunnel_del_work+0xe5/0x330 net/l2tp/l2tp_core.c:1334 > Read of size 8 at addr ffff88802361a0b8 by task kworker/u8:1/12 I think this is related
Jul 2
syzbot
, …
Hillf Danton
27
Jul 10
[syzbot] [net?] KASAN: slab-use-after-free Write in l2tp_session_delete
slab-
use
-
after
-
free
Write in l2tp_session_delete ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in instrument_atomic_read_write
unread,
[syzbot] [net?] KASAN: slab-use-after-free Write in l2tp_session_delete
slab-
use
-
after
-
free
Write in l2tp_session_delete ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in instrument_atomic_read_write
Jul 10
syzbot
Jun 27
[syzbot] [bridge?] KASAN: slab-use-after-free Read in br_multicast_port_group_expired
slab-
use
-
after
-
free
in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861 Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699 CPU:
unread,
[syzbot] [bridge?] KASAN: slab-use-after-free Read in br_multicast_port_group_expired
slab-
use
-
after
-
free
in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861 Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699 CPU:
Jun 27
syzbot
Jun 26
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in hci_chan_sent
slab-
use
-
after
-
free
in hci_chan_sent+0x67d/0xaf0 net/bluetooth/hci_core.c:3548 Read of size 8 at addr ffff88801e8a9018 by task kworker/u9:0/53 CPU: 1 PID: 53 Comm: kworker
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in hci_chan_sent
slab-
use
-
after
-
free
in hci_chan_sent+0x67d/0xaf0 net/bluetooth/hci_core.c:3548 Read of size 8 at addr ffff88801e8a9018 by task kworker/u9:0/53 CPU: 1 PID: 53 Comm: kworker
Jun 26
syzbot
5
Jun 25
[syzbot] [bcachefs?] KASAN: slab-use-after-free Read in bch2_sb_errors_from_cpu
slab-
use
-
after
-
free
in bch2_sb_errors_from_cpu+0x255/0x280 fs/bcachefs/sb-errors.c:122 Read of size 8 at addr ffff88801ac73100 by task kworker/u32:2/45 CPU: 3 PID: 45 Comm
unread,
[syzbot] [bcachefs?] KASAN: slab-use-after-free Read in bch2_sb_errors_from_cpu
slab-
use
-
after
-
free
in bch2_sb_errors_from_cpu+0x255/0x280 fs/bcachefs/sb-errors.c:122 Read of size 8 at addr ffff88801ac73100 by task kworker/u32:2/45 CPU: 3 PID: 45 Comm
Jun 25
shichao lai
Jun 25
KASAN: slab-use-after-free Read in em28xx_init_extension
slab-
use
-
after
-
free
Read in em28xx_init_extension" This bug may be related to the previous bugs but new modules are in the traces, such as security/tomoyo. Unfortunately
unread,
KASAN: slab-use-after-free Read in em28xx_init_extension
slab-
use
-
after
-
free
Read in em28xx_init_extension" This bug may be related to the previous bugs but new modules are in the traces, such as security/tomoyo. Unfortunately
Jun 25
syzbot
Jun 24
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_connect (2)
slab-
use
-
after
-
free
in l2cap_connect.constprop.0+0x10d8/0x1270 net/bluetooth/l2cap_core.c:3949 Read of size 8 at addr ffff88802af53000 by task kworker/u9:4/5114 CPU:
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_connect (2)
slab-
use
-
after
-
free
in l2cap_connect.constprop.0+0x10d8/0x1270 net/bluetooth/l2cap_core.c:3949 Read of size 8 at addr ffff88802af53000 by task kworker/u9:4/5114 CPU:
Jun 24
syzbot
Jun 24
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in __sock_queue_rcv_skb
slab-
use
-
after
-
free
in debug_spin_lock_before kernel/locking/spinlock_debug.c:86 [inline] BUG: KASAN: slab-
use
-
after
-
free
in do_raw_spin_lock+0x271/0x2c0 kernel/
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in __sock_queue_rcv_skb
slab-
use
-
after
-
free
in debug_spin_lock_before kernel/locking/spinlock_debug.c:86 [inline] BUG: KASAN: slab-
use
-
after
-
free
in do_raw_spin_lock+0x271/0x2c0 kernel/
Jun 24
syzbot
, …
Hillf Danton
5
Jun 25
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in sk_skb_reason_drop
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in sk_skb_reason_drop
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
Jun 25
syzbot
,
Hillf Danton
3
Jun 17
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in __lock_sock (2)
slab-
use
-
after
-
free
in __lock_acquire+0x2dd6/0x3b30 kernel/locking/lockdep.c:5005 Read of size 8 at addr ffff88801abd01d8 by task kworker/u33:2/5194 CPU: 1 PID: 5194 Comm
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in __lock_sock (2)
slab-
use
-
after
-
free
in __lock_acquire+0x2dd6/0x3b30 kernel/locking/lockdep.c:5005 Read of size 8 at addr ffff88801abd01d8 by task kworker/u33:2/5194 CPU: 1 PID: 5194 Comm
Jun 17
syzbot
, …
Ryusuke Konishi
22
Jun 23
[syzbot] [mm?] KASAN: slab-use-after-free Read in lru_add_fn
slab-
use
-
after
-
free
Read in lru_add_fn NILFS (loop0): unable to write superblock: err=-5 Buffer I/O error on dev loop0, logical block 1, lost sync page write NILFS (loop0): unable
unread,
[syzbot] [mm?] KASAN: slab-use-after-free Read in lru_add_fn
slab-
use
-
after
-
free
Read in lru_add_fn NILFS (loop0): unable to write superblock: err=-5 Buffer I/O error on dev loop0, logical block 1, lost sync page write NILFS (loop0): unable
Jun 23
syzbot
Jun 11
[syzbot] [hams?] KASAN: slab-use-after-free Read in rose_get_neigh
slab-
use
-
after
-
free
in rose_get_neigh+0x1b6/0x6f0 net/rose/rose_route.c:692 Read of size 1 at addr ffff88802a32b030 by task syz-executor.2/6399 CPU: 0 PID: 6399 Comm: syz
unread,
[syzbot] [hams?] KASAN: slab-use-after-free Read in rose_get_neigh
slab-
use
-
after
-
free
in rose_get_neigh+0x1b6/0x6f0 net/rose/rose_route.c:692 Read of size 1 at addr ffff88802a32b030 by task syz-executor.2/6399 CPU: 0 PID: 6399 Comm: syz
Jun 11
syzbot
, …
Edward Adam Davis
33
Jun 25
[syzbot] [bluetooth?] general protection fault in l2cap_sock_recv_cb
at:
process_one_work
kernel/workqueue.c:3206 [inline] #0: ffff88807c089948 ((wq_completion)hci1#2){+.+.}-{0:0}, at: process_scheduled_works+0x90a/0x1830 kernel/
unread,
[syzbot] [bluetooth?] general protection fault in l2cap_sock_recv_cb
at:
process_one_work
kernel/workqueue.c:3206 [inline] #0: ffff88807c089948 ((wq_completion)hci1#2){+.+.}-{0:0}, at: process_scheduled_works+0x90a/0x1830 kernel/
Jun 25
syzbot
Jun 7
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in hci_req_sync_complete
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in hci_req_sync_complete
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
Jun 7
syzbot
Jun 3
[syzbot] [net?] KASAN: use-after-free Read in rhashtable_lookup_fast (2)
KASAN:
use
-
after
-
free
in rht_key_hashfn include/linux/rhashtable.h:159 [inline] BUG: KASAN:
use
-
after
-
free
in __rhashtable_lookup include/linux/rhashtable.h:604 [inline
unread,
[syzbot] [net?] KASAN: use-after-free Read in rhashtable_lookup_fast (2)
KASAN:
use
-
after
-
free
in rht_key_hashfn include/linux/rhashtable.h:159 [inline] BUG: KASAN:
use
-
after
-
free
in __rhashtable_lookup include/linux/rhashtable.h:604 [inline
Jun 3
syzbot
May 31
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_sock_ready_cb
slab-
use
-
after
-
free
in l2cap_sock_ready_cb+0xd7/0x140 net/bluetooth/l2cap_sock.c:1662 Read of size 8 at addr ffff88806c4de188 by task kworker/1:1/17633 CPU: 1 PID: 17633
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_sock_ready_cb
slab-
use
-
after
-
free
in l2cap_sock_ready_cb+0xd7/0x140 net/bluetooth/l2cap_sock.c:1662 Read of size 8 at addr ffff88806c4de188 by task kworker/1:1/17633 CPU: 1 PID: 17633
May 31
syzbot
, …
Hillf Danton
36
Jun 17
[syzbot] [ntfs3?] KASAN: slab-use-after-free Read in chrdev_open
slab-
use
-
after
-
free
Read in chrdev_open loop0: detected capacity change from 0 to 4096 ================================================================== BUG: KASAN:
unread,
[syzbot] [ntfs3?] KASAN: slab-use-after-free Read in chrdev_open
slab-
use
-
after
-
free
Read in chrdev_open loop0: detected capacity change from 0 to 4096 ================================================================== BUG: KASAN:
Jun 17
syzbot
2
Jun 1
[syzbot] [bpf?] KASAN: slab-use-after-free Read in bpf_link_free (2)
slab-
use
-
after
-
free
in bpf_link_free+0x234/0x2d0 kernel/bpf/syscall.c:3078 Read of size 8 at addr ffff888011469b10 by task syz-executor.1/6398 CPU: 0 PID: 6398 Comm: syz-
unread,
[syzbot] [bpf?] KASAN: slab-use-after-free Read in bpf_link_free (2)
slab-
use
-
after
-
free
in bpf_link_free+0x234/0x2d0 kernel/bpf/syscall.c:3078 Read of size 8 at addr ffff888011469b10 by task syz-executor.1/6398 CPU: 0 PID: 6398 Comm: syz-
Jun 1
syzbot
May 25
[syzbot] [net?] WARNING: refcount bug in __netif_napi_del (3)
underflow;
use
-
after
-
free
. WARNING: CPU: 3 PID: 1086 at lib/refcount.c:28 refcount_warn_saturate+0x14a/0x210 lib/refcount.c:28 Modules linked in: CPU: 3 PID: 1086 Comm: kworker
unread,
[syzbot] [net?] WARNING: refcount bug in __netif_napi_del (3)
underflow;
use
-
after
-
free
. WARNING: CPU: 3 PID: 1086 at lib/refcount.c:28 refcount_warn_saturate+0x14a/0x210 lib/refcount.c:28 Modules linked in: CPU: 3 PID: 1086 Comm: kworker
May 25