Groups
Groups
Sign in
Groups
Groups
syzkaller-bugs
Conversations
About
Send feedback
Help
Sort By Relevance
Sort By Date
1–30 of many
syzbot
, …
Dave Kleikamp
11
11:21 AM
[syzbot] KASAN: use-after-free Read in jfs_lazycommit
KASAN:
use
-
after
-
free
Read in jfs_lazycommit Author: kapoorarnav43@gmail.com #syz fix From 7e1a0b91e9efa8bec40fc5397ba6c4e683d72df0 Mon Sep 17 00:00:00 2001 From: ArnavKapoor
unread,
[syzbot] KASAN: use-after-free Read in jfs_lazycommit
KASAN:
use
-
after
-
free
Read in jfs_lazycommit Author: kapoorarnav43@gmail.com #syz fix From 7e1a0b91e9efa8bec40fc5397ba6c4e683d72df0 Mon Sep 17 00:00:00 2001 From: ArnavKapoor
11:21 AM
syzbot
3
9:26 AM
Re: [syzbot] [jfs?] KASAN: use-after-free Read in jfs_lazycommit
slab-
use
-
after
-
free
Read in blk_update_request ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irqsave
unread,
Re: [syzbot] [jfs?] KASAN: use-after-free Read in jfs_lazycommit
slab-
use
-
after
-
free
Read in blk_update_request ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irqsave
9:26 AM
syzbot
Apr 30
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_pull (2)
slab-
use
-
after
-
free
in skb_pull_inline include/linux/skbuff.h:2853 [inline] BUG: KASAN: slab-
use
-
after
-
free
in skb_pull+0x133/0x1d0 net/core/skbuff.c:2664 Read of size
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_pull (2)
slab-
use
-
after
-
free
in skb_pull_inline include/linux/skbuff.h:2853 [inline] BUG: KASAN: slab-
use
-
after
-
free
in skb_pull+0x133/0x1d0 net/core/skbuff.c:2664 Read of size
Apr 30
syzbot
, …
Hillf Danton
20
Apr 28
[syzbot] [input?] [usb?] KASAN: slab-use-after-free Read in hidraw_report_event
slab-
use
-
after
-
free
Read in usbhid_power =========================================================[ 164.792757][ T6670] ======================================
unread,
[syzbot] [input?] [usb?] KASAN: slab-use-after-free Read in hidraw_report_event
slab-
use
-
after
-
free
Read in usbhid_power =========================================================[ 164.792757][ T6670] ======================================
Apr 28
syzbot ci
, …
NeilBrown
3
Apr 28
[syzbot ci] Re: Prepare to lift lookup out of exclusive lock for directory ops
VFS:
use
wait_var_event for waiting in d_alloc_parallel() * [PATCH v2 05/19] VFS: introduce d_alloc_noblock() * [PATCH v2 06/19] VFS: add d_duplicate() * [PATCH v2 07/19] VFS: Add
unread,
[syzbot ci] Re: Prepare to lift lookup out of exclusive lock for directory ops
VFS:
use
wait_var_event for waiting in d_alloc_parallel() * [PATCH v2 05/19] VFS: introduce d_alloc_noblock() * [PATCH v2 06/19] VFS: add d_duplicate() * [PATCH v2 07/19] VFS: Add
Apr 28
syzbot
14
Apr 25
[syzbot] [mm?] KASAN: use-after-free Read in copy_folio_from_iter_atomic (2)
slab-
use
-
after
-
free
Read in blk_update_request ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __wake_up_common
unread,
[syzbot] [mm?] KASAN: use-after-free Read in copy_folio_from_iter_atomic (2)
slab-
use
-
after
-
free
Read in blk_update_request ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __wake_up_common
Apr 25
syzbot ci
Apr 24
[syzbot ci] Re: netlink: clean up failed initial dump-start state
slab-
use
-
after
-
free
Read in inet_diag_dump_done * KASAN: slab-
use
-
after
-
free
Read in netlink_dump_done * KASAN: slab-
use
-
after
-
free
Read in netlink_rcv_skb * KASAN: slab
unread,
[syzbot ci] Re: netlink: clean up failed initial dump-start state
slab-
use
-
after
-
free
Read in inet_diag_dump_done * KASAN: slab-
use
-
after
-
free
Read in netlink_dump_done * KASAN: slab-
use
-
after
-
free
Read in netlink_rcv_skb * KASAN: slab
Apr 24
syzbot ci
Apr 22
[syzbot ci] Re: ipv6: udp: fix memory leak in udpv6_sendmsg error path
slab-
use
-
after
-
free
Read in ip6_pol_route * KASAN: slab-
use
-
after
-
free
Write in rcuref_put * WARNING in rcuref_put_slowpath Full report is available here: https://ci.syzbot
unread,
[syzbot ci] Re: ipv6: udp: fix memory leak in udpv6_sendmsg error path
slab-
use
-
after
-
free
Read in ip6_pol_route * KASAN: slab-
use
-
after
-
free
Write in rcuref_put * WARNING in rcuref_put_slowpath Full report is available here: https://ci.syzbot
Apr 22
syzbot
Apr 22
[syzbot] [bluetooth] KASAN: slab-use-after-free Read in process_one_work (2)
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:132 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
unread,
[syzbot] [bluetooth] KASAN: slab-use-after-free Read in process_one_work (2)
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:132 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
Apr 22
syzbot
Apr 20
[syzbot] [net?] [usb?] KASAN: slab-use-after-free Read in rtl8150_start_xmit
slab-
use
-
after
-
free
in rtl8150_start_xmit+0x71f/0x760 drivers/net/usb/rtl8150.c:712 Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226 CPU: 0 UID: 0 PID: 5226
unread,
[syzbot] [net?] [usb?] KASAN: slab-use-after-free Read in rtl8150_start_xmit
slab-
use
-
after
-
free
in rtl8150_start_xmit+0x71f/0x760 drivers/net/usb/rtl8150.c:712 Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226 CPU: 0 UID: 0 PID: 5226
Apr 20
syzbot
Apr 20
[syzbot] [wireless?] KASAN: slab-use-after-free Write in rsi_91x_deinit
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_add_relaxed include
unread,
[syzbot] [wireless?] KASAN: slab-use-after-free Write in rsi_91x_deinit
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_add_relaxed include
Apr 20
syzbot ci
,
syzbot ci
2
Apr 22
[syzbot ci] Re: Data in direntry (dirdata) feature
slab-
use
-
after
-
free
Read in __ext4_check_dir_entry * KASAN: slab-
use
-
after
-
free
Read in dx_probe * KASAN:
use
-
after
-
free
Read in __ext4_check_dir_entry Full report is available
unread,
[syzbot ci] Re: Data in direntry (dirdata) feature
slab-
use
-
after
-
free
Read in __ext4_check_dir_entry * KASAN: slab-
use
-
after
-
free
Read in dx_probe * KASAN:
use
-
after
-
free
Read in __ext4_check_dir_entry Full report is available
Apr 22
syzbot
,
Edward Adam Davis
26
Apr 18
[syzbot] [jfs?] KASAN: slab-use-after-free Read in lbmIODone
slab-
use
-
after
-
free
Read in rtlock_slowlock_locked ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irq
unread,
[syzbot] [jfs?] KASAN: slab-use-after-free Read in lbmIODone
slab-
use
-
after
-
free
Read in rtlock_slowlock_locked ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irq
Apr 18
syzbot
2
Apr 17
Re: [syzbot] [jfs?] UBSAN: array-index-out-of-bounds in dbFindLeaf (2)
KASAN:
use
-
after
-
free
Read in copy_folio_from_iter_atomic =========[ 176.559683][ T1419] ================================================================== BUG:
unread,
Re: [syzbot] [jfs?] UBSAN: array-index-out-of-bounds in dbFindLeaf (2)
KASAN:
use
-
after
-
free
Read in copy_folio_from_iter_atomic =========[ 176.559683][ T1419] ================================================================== BUG:
Apr 17
syzbot
, …
Edward Adam Davis
26
Apr 16
[syzbot] [dri?] KASAN: slab-use-after-free Read in drm_gem_object_release_handle
slab-
use
-
after
-
free
Read in drm_gem_object_release_handle ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in
unread,
[syzbot] [dri?] KASAN: slab-use-after-free Read in drm_gem_object_release_handle
slab-
use
-
after
-
free
Read in drm_gem_object_release_handle ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in
Apr 16
syzbot
, …
Tejun Heo
43
Apr 17
[syzbot] [cgroups?] KASAN: slab-use-after-free Read in pressure_write
slab-
use
-
after
-
free
Read in pressure_write ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in pressure_write+
unread,
[syzbot] [cgroups?] KASAN: slab-use-after-free Read in pressure_write
slab-
use
-
after
-
free
Read in pressure_write ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in pressure_write+
Apr 17
syzbot
,
Wentao Guan
2
Apr 10
[syzbot] [serial?] KASAN: slab-use-after-free Read in kbd_event (2)
slab-
use
-
after
-
free
in kbd_keycode drivers/tty/vt/keyboard.c:1435 [inline] BUG: KASA[ 730.192938][ T7920] BUG: KASAN: slab-
use
-
after
-
free
in kbd_event+0x3330/0x40d0
unread,
[syzbot] [serial?] KASAN: slab-use-after-free Read in kbd_event (2)
slab-
use
-
after
-
free
in kbd_keycode drivers/tty/vt/keyboard.c:1435 [inline] BUG: KASA[ 730.192938][ T7920] BUG: KASAN: slab-
use
-
after
-
free
in kbd_event+0x3330/0x40d0
Apr 10
syzbot
Apr 5
[syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_ail_drain
locked for
use
gfs2: fsid=syz:syz.0: jid=0: Looking at journal... gfs2: fsid=syz:syz.0: jid=0: Journal head lookup took 109ms gfs2: fsid=syz:syz.0: jid=0: Done gfs2: fsid=syz
unread,
[syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_ail_drain
locked for
use
gfs2: fsid=syz:syz.0: jid=0: Looking at journal... gfs2: fsid=syz:syz.0: jid=0: Journal head lookup took 109ms gfs2: fsid=syz:syz.0: jid=0: Done gfs2: fsid=syz
Apr 5
syzbot
9
Apr 5
[syzbot] [kernel?] INFO: rcu detected stall in kill
slab-
use
-
after
-
free
Read in usb_anchor_urb ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irqsave
unread,
[syzbot] [kernel?] INFO: rcu detected stall in kill
slab-
use
-
after
-
free
Read in usb_anchor_urb ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in __raw_spin_lock_irqsave
Apr 5
syzbot
Apr 2
[syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel
slab-
use
-
after
-
free
in __vb2_queue_cancel+0xd56/0xdb0 drivers/media/common/videobuf2/videobuf2-core.c:2255 Read of size 4 at addr ffff88803ad98f48 by task v4l_id/15134
unread,
[syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel
slab-
use
-
after
-
free
in __vb2_queue_cancel+0xd56/0xdb0 drivers/media/common/videobuf2/videobuf2-core.c:2255 Read of size 4 at addr ffff88803ad98f48 by task v4l_id/15134
Apr 2
syzbot
5
Apr 2
[syzbot] [net?] [bpf?] KASAN: slab-use-after-free Read in __sk_msg_recvmsg
slab-
use
-
after
-
free
in __sk_msg_recvmsg+0x19b/0xe70 net/core/skmsg.c:431 Read of size 8 at addr ffff88807eeac2b0 by task syz.0.31/6071 CPU: 0 UID: 0 PID: 6071 Comm: syz.0.31
unread,
[syzbot] [net?] [bpf?] KASAN: slab-use-after-free Read in __sk_msg_recvmsg
slab-
use
-
after
-
free
in __sk_msg_recvmsg+0x19b/0xe70 net/core/skmsg.c:431 Read of size 8 at addr ffff88807eeac2b0 by task syz.0.31/6071 CPU: 0 UID: 0 PID: 6071 Comm: syz.0.31
Apr 2
syzbot
Apr 1
[syzbot] [input?] [usb?] KASAN: slab-use-after-free Read in hiddev_disconnect (4)
slab-
use
-
after
-
free
in debug_spin_lock_before kernel/locking/spinlock_debug.c:86 [inline] BUG: KASAN: slab-
use
-
after
-
free
in do_raw_spin_lock+0x23b/0x260 kernel/
unread,
[syzbot] [input?] [usb?] KASAN: slab-use-after-free Read in hiddev_disconnect (4)
slab-
use
-
after
-
free
in debug_spin_lock_before kernel/locking/spinlock_debug.c:86 [inline] BUG: KASAN: slab-
use
-
after
-
free
in do_raw_spin_lock+0x23b/0x260 kernel/
Apr 1
syzbot
Mar 27
[syzbot] [media?] KASAN: slab-use-after-free Read in v4l2_fh_release
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:132 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
unread,
[syzbot] [media?] KASAN: slab-use-after-free Read in v4l2_fh_release
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:132 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
Mar 27
syzbot
4
Mar 25
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in le_read_features_complete
le_read_features_complete but
after
> hci_le_read_remote_features_sync so hci_conn_del -> hci_cmd_sync_dequeue > is not able to prevent it: > > ==========
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in le_read_features_complete
le_read_features_complete but
after
> hci_le_read_remote_features_sync so hci_conn_del -> hci_cmd_sync_dequeue > is not able to prevent it: > > ==========
Mar 25
syzbot ci
Mar 24
[syzbot ci] Re: context_tracking,x86: Defer some IPIs until a user->kernel transition
slab-
use
-
after
-
free
Read in __dynamic_dev_dbg Full report is available here: https://ci.syzbot.org/series/e1f9c661-db83-4882-8439-ab6d1b3ffe07 *** KASAN: slab-out-
unread,
[syzbot ci] Re: context_tracking,x86: Defer some IPIs until a user->kernel transition
slab-
use
-
after
-
free
Read in __dynamic_dev_dbg Full report is available here: https://ci.syzbot.org/series/e1f9c661-db83-4882-8439-ab6d1b3ffe07 *** KASAN: slab-out-
Mar 24
syzbot
,
Edward Adam Davis
12
Mar 20
[syzbot] [media?] [usb?] KASAN: slab-use-after-free Read in v4l2_open
slab-
use
-
after
-
free
Read in v4l2_open ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in v4l2_open+0x395/0x3a0
unread,
[syzbot] [media?] [usb?] KASAN: slab-use-after-free Read in v4l2_open
slab-
use
-
after
-
free
Read in v4l2_open ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in v4l2_open+0x395/0x3a0
Mar 20
syzbot ci
Mar 20
[syzbot ci] Re: ext4: fix use-after-free in update_super_work when racing with umount
: fix
use
-
after
-
free
in update_super_work when racing with umount https://lore.kernel.org/all/20260319073651.79209-1-jiayuan.chen@linux.dev * [PATCH v2] ext4: fix
use
unread,
[syzbot ci] Re: ext4: fix use-after-free in update_super_work when racing with umount
: fix
use
-
after
-
free
in update_super_work when racing with umount https://lore.kernel.org/all/20260319073651.79209-1-jiayuan.chen@linux.dev * [PATCH v2] ext4: fix
use
Mar 20
syzbot
,
Qing Wang
2
Mar 19
[syzbot] [bpf?] [trace?] KASAN: slab-use-after-free Read in bpf_trace_run4 (2)
slab-
use
-
after
-
free
in __bpf_trace_run kernel/trace/bpf_trace.c:2075 [inline] BUG: KASAN: slab-
use
-
after
-
free
in bpf_trace_run4+0xe6/0x850 kernel/trace/bpf_trace
unread,
[syzbot] [bpf?] [trace?] KASAN: slab-use-after-free Read in bpf_trace_run4 (2)
slab-
use
-
after
-
free
in __bpf_trace_run kernel/trace/bpf_trace.c:2075 [inline] BUG: KASAN: slab-
use
-
after
-
free
in bpf_trace_run4+0xe6/0x850 kernel/trace/bpf_trace
Mar 19
syzbot
, …
Hillf Danton
27
Mar 13
[syzbot] [net?] KASAN: slab-use-after-free Read in sock_def_readable (2)
slab-
use
-
after
-
free
Read in sock_def_readable ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in list_empty include
unread,
[syzbot] [net?] KASAN: slab-use-after-free Read in sock_def_readable (2)
slab-
use
-
after
-
free
Read in sock_def_readable ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in list_empty include
Mar 13
syzbot
Mar 5
[syzbot] [rds?] KASAN: slab-use-after-free Read in rds_conn_path_drop
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:82 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
unread,
[syzbot] [rds?] KASAN: slab-use-after-free Read in rds_conn_path_drop
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:82 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
Mar 5