Groups
Groups
Sign in
Groups
Groups
syzkaller-bugs
Conversations
About
Send feedback
Help
Sort By Relevance
Sort By Date
1–30 of many
syzbot
3
Jun 29
[syzbot] [usb?] KASAN: slab-use-after-free Read in uea_upload_pre_firmware
slab-
use
-
after
-
free
in __intf_to_usbdev include/linux/usb.h:752 [inline] BUG: KASAN: slab-
use
-
after
-
free
in uea_upload_pre_firmware+0x8d/0x640 drivers/usb/atm/ueagle
unread,
[syzbot] [usb?] KASAN: slab-use-after-free Read in uea_upload_pre_firmware
slab-
use
-
after
-
free
in __intf_to_usbdev include/linux/usb.h:752 [inline] BUG: KASAN: slab-
use
-
after
-
free
in uea_upload_pre_firmware+0x8d/0x640 drivers/usb/atm/ueagle
Jun 29
syzbot ci
, …
syzbot ci
7
Jun 24
[syzbot ci] Re: Data in direntry (dirdata) feature
slab-
use
-
after
-
free
Read in ext4_inlinedir_to_tree * KASAN:
use
-
after
-
free
Read in ext4_inlinedir_to_tree Full report is available here: https://ci.syzbot.org/series/
unread,
[syzbot ci] Re: Data in direntry (dirdata) feature
slab-
use
-
after
-
free
Read in ext4_inlinedir_to_tree * KASAN:
use
-
after
-
free
Read in ext4_inlinedir_to_tree Full report is available here: https://ci.syzbot.org/series/
Jun 24
syzbot
Jun 22
[syzbot] [wpan?] KASAN: slab-use-after-free Read in hwsim_set_promiscuous_mode
slab-
use
-
after
-
free
in hwsim_set_promiscuous_mode+0x2b4/0x2e0 drivers/net/ieee802154/mac802154_hwsim.c:323 Read of size 1 at addr ffff88802adb1800 by task syz.0.303
unread,
[syzbot] [wpan?] KASAN: slab-use-after-free Read in hwsim_set_promiscuous_mode
slab-
use
-
after
-
free
in hwsim_set_promiscuous_mode+0x2b4/0x2e0 drivers/net/ieee802154/mac802154_hwsim.c:323 Read of size 1 at addr ffff88802adb1800 by task syz.0.303
Jun 22
syzbot
Jun 22
[syzbot] [wireless?] KASAN: slab-use-after-free Read in ath9k_hif_request_firmware (2)
slab-
use
-
after
-
free
in ath9k_hif_request_firmware+0x416/0x450 drivers/net/wireless/ath/ath9k/hif_usb.c:1219 Read of size 8 at addr ffff888053c45000 by task kworker/
unread,
[syzbot] [wireless?] KASAN: slab-use-after-free Read in ath9k_hif_request_firmware (2)
slab-
use
-
after
-
free
in ath9k_hif_request_firmware+0x416/0x450 drivers/net/wireless/ath/ath9k/hif_usb.c:1219 Read of size 8 at addr ffff888053c45000 by task kworker/
Jun 22
syzbot
,
Hillf Danton
2
Jun 20
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in bt_accept_dequeue
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] > BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_add_relaxed include
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in bt_accept_dequeue
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] > BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_add_relaxed include
Jun 20
syzbot
Jun 18
[syzbot] [ntfs3?] KASAN: slab-use-after-free Read in ntfs_set_inode (2)
slab-
use
-
after
-
free
in ino_get fs/ntfs3/ntfs.h:192 [inline] BUG: KASAN: slab-
use
-
after
-
free
in ntfs_set_inode+0x70/0x80 fs/ntfs3/inode.c:526 Read of size 4 at addr ffff888011c6ea38
unread,
[syzbot] [ntfs3?] KASAN: slab-use-after-free Read in ntfs_set_inode (2)
slab-
use
-
after
-
free
in ino_get fs/ntfs3/ntfs.h:192 [inline] BUG: KASAN: slab-
use
-
after
-
free
in ntfs_set_inode+0x70/0x80 fs/ntfs3/inode.c:526 Read of size 4 at addr ffff888011c6ea38
Jun 18
syzbot
13
Jun 27
[syzbot] [fs?] KASAN: slab-use-after-free Read in debugfs_u32_get (2)
T36]
process_one_work
+0xa23/0x1940 [ 92.463500][ T36] ? __pfx_process_one_work+0x10/0x10 [ 92.463540][ T36] ? __pfx_cleanup_net+0x10/0x10 [ 92.463574][ T36] worker_thread
unread,
[syzbot] [fs?] KASAN: slab-use-after-free Read in debugfs_u32_get (2)
T36]
process_one_work
+0xa23/0x1940 [ 92.463500][ T36] ? __pfx_process_one_work+0x10/0x10 [ 92.463540][ T36] ? __pfx_cleanup_net+0x10/0x10 [ 92.463574][ T36] worker_thread
Jun 27
syzbot
, …
Kuniyuki Iwashima
5
Jun 16
[syzbot] [net?] KASAN: slab-use-after-free Read in fib_rules_lookup
You can
use
this to reproduce: > > > > > > #!/bin/bash > > > > > > while true; do > > > ip netns add ns1 > > > ip -n ns1 link set dev lo
unread,
[syzbot] [net?] KASAN: slab-use-after-free Read in fib_rules_lookup
You can
use
this to reproduce: > > > > > > #!/bin/bash > > > > > > while true; do > > > ip netns add ns1 > > > ip -n ns1 link set dev lo
Jun 16
syzbot
Jun 16
[syzbot] [kernfs?] KASAN: slab-use-after-free Read in __kernfs_new_node
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:82 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
unread,
[syzbot] [kernfs?] KASAN: slab-use-after-free Read in __kernfs_new_node
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:82 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
Jun 16
syzbot
Jun 10
[syzbot] [fbdev?] KASAN: slab-use-after-free Read in fb_mode_is_equal
slab-
use
-
after
-
free
in fb_mode_is_equal+0x280/0x2f0 drivers/video/fbdev/core/modedb.c:934 Read of size 4 at addr ffff88802666219c by task syz.6.4102/26504 CPU: 0 UID: 0
unread,
[syzbot] [fbdev?] KASAN: slab-use-after-free Read in fb_mode_is_equal
slab-
use
-
after
-
free
in fb_mode_is_equal+0x280/0x2f0 drivers/video/fbdev/core/modedb.c:934 Read of size 4 at addr ffff88802666219c by task syz.6.4102/26504 CPU: 0 UID: 0
Jun 10
syzbot
Jun 10
[syzbot] [net?] WARNING: refcount bug in nsim_fib_event_nb (3)
0;
use
-
after
-
free
. WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#1: kworker/u8:8/1044 Modules linked in: CPU: 1 UID: 0 PID: 1044
unread,
[syzbot] [net?] WARNING: refcount bug in nsim_fib_event_nb (3)
0;
use
-
after
-
free
. WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#1: kworker/u8:8/1044 Modules linked in: CPU: 1 UID: 0 PID: 1044
Jun 10
syzbot
Jun 9
[syzbot] [mm?] KASAN: use-after-free Read in ptdump_pte_entry (2)
KASAN:
use
-
after
-
free
in ptep_get include/linux/pgtable.h:461 [inline] BUG: KASAN:
use
-
after
-
free
in ptdump_pte_entry+0xec/0x100 mm/ptdump.c:124 Read of size 8 at addr ffff88806640f530
unread,
[syzbot] [mm?] KASAN: use-after-free Read in ptdump_pte_entry (2)
KASAN:
use
-
after
-
free
in ptep_get include/linux/pgtable.h:461 [inline] BUG: KASAN:
use
-
after
-
free
in ptdump_pte_entry+0xec/0x100 mm/ptdump.c:124 Read of size 8 at addr ffff88806640f530
Jun 9
syzbot
2
Jun 2
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_unregister_media_device
slab-
use
-
after
-
free
in media_device_unregister drivers/media/mc/mc-device.c:833 [inline] BUG: KASAN: slab-
use
-
after
-
free
in media_device_unregister+0x59d/0x610 drivers
unread,
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_unregister_media_device
slab-
use
-
after
-
free
in media_device_unregister drivers/media/mc/mc-device.c:833 [inline] BUG: KASAN: slab-
use
-
after
-
free
in media_device_unregister+0x59d/0x610 drivers
Jun 2
syzbot
Jun 2
[syzbot] [btrfs?] KASAN: slab-use-after-free Write in btrfs_put_root
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_sub_release include
unread,
[syzbot] [btrfs?] KASAN: slab-use-after-free Write in btrfs_put_root
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_sub_release include
Jun 2
syzbot
,
Jie Wang
3
Jun 25
[syzbot] [jfs?] KASAN: slab-use-after-free Write in lmLogSync
slab-
use
-
after
-
free
in lmLogSync+0x794/0x7b0 fs/jfs/jfs_logmgr.c:1003 Write of size 4 at addr ffff88807d709218 by task jfsCommit/117 CPU: 0 UID: 0 PID: 117 Comm: jfsCommit Tainted
unread,
[syzbot] [jfs?] KASAN: slab-use-after-free Write in lmLogSync
slab-
use
-
after
-
free
in lmLogSync+0x794/0x7b0 fs/jfs/jfs_logmgr.c:1003 Write of size 4 at addr ffff88807d709218 by task jfsCommit/117 CPU: 0 UID: 0 PID: 117 Comm: jfsCommit Tainted
Jun 25
syzbot
Jun 1
[syzbot] [btrfs?] KASAN: slab-use-after-free Read in replace_file_extents
slab-
use
-
after
-
free
in replace_file_extents+0x85f/0x1590 fs/btrfs/relocation.c:941 Read of size 8 at addr ffff888012312010 by task syz.0.0/5346 CPU: 0 UID: 0 PID: 5346 Comm
unread,
[syzbot] [btrfs?] KASAN: slab-use-after-free Read in replace_file_extents
slab-
use
-
after
-
free
in replace_file_extents+0x85f/0x1590 fs/btrfs/relocation.c:941 Read of size 8 at addr ffff888012312010 by task syz.0.0/5346 CPU: 0 UID: 0 PID: 5346 Comm
Jun 1
syzbot
Jun 1
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_v4l2_open
slab-
use
-
after
-
free
in dev_get_drvdata include/linux/device.h:927 [inline] BUG: KASAN: slab-
use
-
after
-
free
in video_get_drvdata include/media/v4l2-dev.h:491 [inline
unread,
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_v4l2_open
slab-
use
-
after
-
free
in dev_get_drvdata include/linux/device.h:927 [inline] BUG: KASAN: slab-
use
-
after
-
free
in video_get_drvdata include/media/v4l2-dev.h:491 [inline
Jun 1
syzbot
Jun 1
[syzbot] [ntfs3?] KASAN: slab-use-after-free Read in ntfs_read_hdr
slab-
use
-
after
-
free
in ntfs_read_hdr+0x938/0xc80 fs/ntfs3/dir.c:368 Read of size 2 at addr ffff888037a69300 by task syz.0.0/5321 CPU: 0 UID: 0 PID: 5321 Comm: syz.0.0 Not tainted
unread,
[syzbot] [ntfs3?] KASAN: slab-use-after-free Read in ntfs_read_hdr
slab-
use
-
after
-
free
in ntfs_read_hdr+0x938/0xc80 fs/ntfs3/dir.c:368 Read of size 2 at addr ffff888037a69300 by task syz.0.0/5321 CPU: 0 UID: 0 PID: 5321 Comm: syz.0.0 Not tainted
Jun 1
syzbot
Jun 1
[syzbot] [serial?] KASAN: slab-use-after-free Read in stop_tty
slab-
use
-
after
-
free
in stop_t[ 93.746644][ T5837] BUG: KASAN: slab-
use
-
after
-
free
in __stop_tty drivers/tty/tty_io.c:742 [inline] BUG: KASAN: slab-
use
-
after
-
free
in stop_t
unread,
[syzbot] [serial?] KASAN: slab-use-after-free Read in stop_tty
slab-
use
-
after
-
free
in stop_t[ 93.746644][ T5837] BUG: KASAN: slab-
use
-
after
-
free
in __stop_tty drivers/tty/tty_io.c:742 [inline] BUG: KASAN: slab-
use
-
after
-
free
in stop_t
Jun 1
syzbot
Jun 1
[syzbot] [kernel?] KASAN: slab-use-after-free Read in netdev_register_kobject (2)
slab-
use
-
after
-
free
in kobject_get+0x136/0x150 lib/kobject.c:639 Read of size 1 at addr ffff88804be10d1c by task syz.2.2484/16757 CPU: 1 UID: 0 PID: 16757 Comm: syz.2.2484 Not
unread,
[syzbot] [kernel?] KASAN: slab-use-after-free Read in netdev_register_kobject (2)
slab-
use
-
after
-
free
in kobject_get+0x136/0x150 lib/kobject.c:639 Read of size 1 at addr ffff88804be10d1c by task syz.2.2484/16757 CPU: 1 UID: 0 PID: 16757 Comm: syz.2.2484 Not
Jun 1
syzbot
May 30
[syzbot] [kernfs?] KASAN: slab-use-after-free Read in kernfs_new_node (2)
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:82 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
unread,
[syzbot] [kernfs?] KASAN: slab-use-after-free Read in kernfs_new_node (2)
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:82 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
May 30
syzbot
May 29
[syzbot] [net?] KASAN: slab-use-after-free Read in ipv6_chk_acast_addr
slab-
use
-
after
-
free
in ipv6_chk_acast_addr+0x2c9/0xb20 net/ipv6/anycast.c:504 Read of size 8 at addr ffff88805f5cd510 by task ktimers/0/16 CPU: 0 UID: 0 PID: 16 Comm: ktimers
unread,
[syzbot] [net?] KASAN: slab-use-after-free Read in ipv6_chk_acast_addr
slab-
use
-
after
-
free
in ipv6_chk_acast_addr+0x2c9/0xb20 net/ipv6/anycast.c:504 Read of size 8 at addr ffff88805f5cd510 by task ktimers/0/16 CPU: 0 UID: 0 PID: 16 Comm: ktimers
May 29
syzbot
May 27
[syzbot] [jfs?] KASAN: slab-use-after-free Read in txLazyUnlock (3)
slab-
use
-
after
-
free
in JFS_SBI fs/jfs/jfs_incore.h:217 [inline] BUG: KASAN: slab-
use
-
after
-
free
in txLazyUnlock+0xf6/0x190 fs/jfs/jfs_txnmgr.c:2786 Read of size 8 at addr
unread,
[syzbot] [jfs?] KASAN: slab-use-after-free Read in txLazyUnlock (3)
slab-
use
-
after
-
free
in JFS_SBI fs/jfs/jfs_incore.h:217 [inline] BUG: KASAN: slab-
use
-
after
-
free
in txLazyUnlock+0xf6/0x190 fs/jfs/jfs_txnmgr.c:2786 Read of size 8 at addr
May 27
syzbot
, …
Michal Pecio
8
May 28
[syzbot] [usb?] KASAN: slab-use-after-free Write in iowarrior_write_callback (2)
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] > BUG: KASAN: slab-
use
-
after
-
free
in atomic_dec include/linux/atomic
unread,
[syzbot] [usb?] KASAN: slab-use-after-free Write in iowarrior_write_callback (2)
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] > BUG: KASAN: slab-
use
-
after
-
free
in atomic_dec include/linux/atomic
May 28
syzbot
,
Philipp Weber
4
May 20
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_dequeue (2)
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:132 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_dequeue (2)
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:132 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
May 20
syzbot
May 15
[syzbot] [xfs?] KASAN: slab-use-after-free Read in xlog_cil_push_work (2)
slab-
use
-
after
-
free
in __list_del_entry_valid_or_report+0xb5/0x190 lib/list_debug.c:65 Read of size 8 at addr ffff8880408ef9a0 by task kworker/u8:9/1184 CPU: 0 UID: 0 PID
unread,
[syzbot] [xfs?] KASAN: slab-use-after-free Read in xlog_cil_push_work (2)
slab-
use
-
after
-
free
in __list_del_entry_valid_or_report+0xb5/0x190 lib/list_debug.c:65 Read of size 8 at addr ffff8880408ef9a0 by task kworker/u8:9/1184 CPU: 0 UID: 0 PID
May 15
syzbot
,
Hojun Choi
2
Jun 29
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_disconn_ind (3)
slab-
use
-
after
-
free
in l2cap_disconn_ind+0xd7/0xf0 net/bluetooth/l2cap_core.c:7430 Read of size 1 at addr ffff88807ee53278 by task kworker/u9:1/4933 CPU: 1 UID: 0 PID: 4933
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_disconn_ind (3)
slab-
use
-
after
-
free
in l2cap_disconn_ind+0xd7/0xf0 net/bluetooth/l2cap_core.c:7430 Read of size 1 at addr ffff88807ee53278 by task kworker/u9:1/4933 CPU: 1 UID: 0 PID: 4933
Jun 29
syzbot
, …
Dave Kleikamp
12
May 6
[syzbot] KASAN: use-after-free Read in jfs_lazycommit
KASAN:
use
-
after
-
free
Read in jfs_lazycommit Author: kapoorarnav43@gmail.com #syz fix From 7e1a0b91e9efa8bec40fc5397ba6c4e683d72df0 Mon Sep 17 00:00:00 2001 From: ArnavKapoor
unread,
[syzbot] KASAN: use-after-free Read in jfs_lazycommit
KASAN:
use
-
after
-
free
Read in jfs_lazycommit Author: kapoorarnav43@gmail.com #syz fix From 7e1a0b91e9efa8bec40fc5397ba6c4e683d72df0 Mon Sep 17 00:00:00 2001 From: ArnavKapoor
May 6
syzbot
4
May 6
Re: [syzbot] [jfs?] KASAN: use-after-free Read in jfs_lazycommit
slab-
use
-
after
-
free
Read in blk_update_request ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irqsave
unread,
Re: [syzbot] [jfs?] KASAN: use-after-free Read in jfs_lazycommit
slab-
use
-
after
-
free
Read in blk_update_request ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irqsave
May 6
syzbot
2
Jun 28
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_pull (2)
slab-
use
-
after
-
free
in skb_pull_inline include/linux/skbuff.h:2853 [inline] BUG: KASAN: slab-
use
-
after
-
free
in skb_pull+0x133/0x1d0 net/core/skbuff.c:2664 Read of size
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_pull (2)
slab-
use
-
after
-
free
in skb_pull_inline include/linux/skbuff.h:2853 [inline] BUG: KASAN: slab-
use
-
after
-
free
in skb_pull+0x133/0x1d0 net/core/skbuff.c:2664 Read of size
Jun 28