Groups
Groups
Sign in
Groups
Groups
syzkaller-bugs
Conversations
About
Send feedback
Help
Sort By Relevance
Sort By Date
1–30 of many
syzbot
,
Florian Westphal
7
Jan 28
[syzbot] [netfilter?] KASAN: slab-use-after-free Read in nft_array_get_cmp
slab-
use
-
after
-
free
Read in nft_array_get_cmp ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in nft_set_ext include
unread,
[syzbot] [netfilter?] KASAN: slab-use-after-free Read in nft_array_get_cmp
slab-
use
-
after
-
free
Read in nft_array_get_cmp ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in nft_set_ext include
Jan 28
syzbot
Jan 26
[syzbot] [sound?] KASAN: slab-use-after-free Read in snd_pcm_stop
slab-
use
-
after
-
free
in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56 Read of size 1 at addr ffff88803c59a200 by task syz.0.88/6375 CPU: 1 UID: 0 PID: 6375 Comm: syz
unread,
[syzbot] [sound?] KASAN: slab-use-after-free Read in snd_pcm_stop
slab-
use
-
after
-
free
in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56 Read of size 1 at addr ffff88803c59a200 by task syz.0.88/6375 CPU: 1 UID: 0 PID: 6375 Comm: syz
Jan 26
syzbot ci
Jan 26
[syzbot ci] Re: nfc: nci: Fix race between rfkill and nci_unregister_device().
slab-
use
-
after
-
free
Read in nci_unregister_device Full report is available here: https://ci.syzbot.org/series/1b1f8783-f1b1-4eaf-8140-aeb610bb4b90 *** KASAN: slab-
unread,
[syzbot ci] Re: nfc: nci: Fix race between rfkill and nci_unregister_device().
slab-
use
-
after
-
free
Read in nci_unregister_device Full report is available here: https://ci.syzbot.org/series/1b1f8783-f1b1-4eaf-8140-aeb610bb4b90 *** KASAN: slab-
Jan 26
syzbot
,
Hillf Danton
9
Jan 23
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_sock_ready_cb (2)
:1670
process_one_work
+0x9c2/0x1840 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x5da/0xe40 kernel/workqueue
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_sock_ready_cb (2)
:1670
process_one_work
+0x9c2/0x1840 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x5da/0xe40 kernel/workqueue
Jan 23
syzbot
Jan 22
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_unregister_media_device
slab-
use
-
after
-
free
in media_device_unregister drivers/media/mc/mc-device.c:804 [inline] BUG: KASAN: slab-
use
-
after
-
free
in media_device_unregister+0x565/0x5e0 drivers
unread,
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_unregister_media_device
slab-
use
-
after
-
free
in media_device_unregister drivers/media/mc/mc-device.c:804 [inline] BUG: KASAN: slab-
use
-
after
-
free
in media_device_unregister+0x565/0x5e0 drivers
Jan 22
syzbot
Jan 21
[syzbot] [fs?] KASAN: slab-use-after-free Read in proc_invalidate_siblings_dcache (2)
slab-
use
-
after
-
free
in proc_invalidate_siblings_dcache+0x6ae/0x6bc fs/proc/inode.c:114 Read of size 8 at addr ffffaf801aba9a18 by task sshd/3175 CPU: 0 UID: 0 PID: 3175 Comm
unread,
[syzbot] [fs?] KASAN: slab-use-after-free Read in proc_invalidate_siblings_dcache (2)
slab-
use
-
after
-
free
in proc_invalidate_siblings_dcache+0x6ae/0x6bc fs/proc/inode.c:114 Read of size 8 at addr ffffaf801aba9a18 by task sshd/3175 CPU: 0 UID: 0 PID: 3175 Comm
Jan 21
syzbot
Jan 20
[syzbot] [usb?] KASAN: slab-use-after-free Read in event_handler
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
unread,
[syzbot] [usb?] KASAN: slab-use-after-free Read in event_handler
slab-
use
-
after
-
free
in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] BUG: KASAN: slab-
use
-
after
-
free
in _raw_spin_lock_irqsave+0x40/0x60
Jan 20
syzbot
, …
syzbot
16
Jan 19
[syzbot] Monthly xfs report (Oct 2025)
:47
process_one_work
+0x7c0/0x1558 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x958/0xed8 kernel/workqueue.
unread,
[syzbot] Monthly xfs report (Oct 2025)
:47
process_one_work
+0x7c0/0x1558 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x958/0xed8 kernel/workqueue.
Jan 19
syzbot
,
Jeongjun Park
3
Jan 17
[syzbot] [hams?] BUG: unable to handle kernel paging request in sk_skb_reason_drop
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:96 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_sub_release include/
unread,
[syzbot] [hams?] BUG: unable to handle kernel paging request in sk_skb_reason_drop
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:96 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_fetch_sub_release include/
Jan 17
syzbot
Jan 12
[syzbot] [net?] KASAN: slab-use-after-free Read in inet6_addr_del (2)
slab-
use
-
after
-
free
in inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117 Read of size 4 at addr ffff88807b89c86c by task syz.3.1618/9593 CPU: 0 UID: 0 PID:
unread,
[syzbot] [net?] KASAN: slab-use-after-free Read in inet6_addr_del (2)
slab-
use
-
after
-
free
in inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117 Read of size 4 at addr ffff88807b89c86c by task syz.3.1618/9593 CPU: 0 UID: 0 PID:
Jan 12
syzbot
Jan 12
[syzbot] [net?] KASAN: slab-use-after-free Write in rt6_disable_ip
slab-
use
-
after
-
free
in INIT_LIST_HEAD include/linux/list.h:46 [inline] BUG: KASAN: slab-
use
-
after
-
free
in list_del_init include/linux/list.h:296 [inline] BUG: KASAN
unread,
[syzbot] [net?] KASAN: slab-use-after-free Write in rt6_disable_ip
slab-
use
-
after
-
free
in INIT_LIST_HEAD include/linux/list.h:46 [inline] BUG: KASAN: slab-
use
-
after
-
free
in list_del_init include/linux/list.h:296 [inline] BUG: KASAN
Jan 12
syzbot
, …
Laurent Pinchart
14
Jan 11
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_release_resources
slab-
use
-
after
-
free
Read in v4l2_open ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in v4l2_open+0x395/0x3a0
unread,
[syzbot] [media?] KASAN: slab-use-after-free Read in em28xx_release_resources
slab-
use
-
after
-
free
Read in v4l2_open ================================================================== BUG: KASAN: slab-
use
-
after
-
free
in v4l2_open+0x395/0x3a0
Jan 11
syzbot
Jan 8
[syzbot] [net?] KASAN: slab-use-after-free Read in macvlan_forward_source
slab-
use
-
after
-
free
in macvlan_forward_source+0x512/0x630 drivers/net/macvlan.c:436 Read of size 2 at addr ffff888030edadfc by task ksoftirqd/0/15 CPU: 0 UID: 0 PID: 15 Comm
unread,
[syzbot] [net?] KASAN: slab-use-after-free Read in macvlan_forward_source
slab-
use
-
after
-
free
in macvlan_forward_source+0x512/0x630 drivers/net/macvlan.c:436 Read of size 2 at addr ffff888030edadfc by task ksoftirqd/0/15 CPU: 0 UID: 0 PID: 15 Comm
Jan 8
syzbot
,
Chao Yu
11
Jan 7
[syzbot] [f2fs?] KASAN: use-after-free Read in f2fs_write_end_io (2)
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] > BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
unread,
[syzbot] [f2fs?] KASAN: use-after-free Read in f2fs_write_end_io (2)
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] > BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
Jan 7
syzbot
12/23/25
[syzbot] [pm?] KASAN: slab-use-after-free Read in thermal_zone_device_check
slab-
use
-
after
-
free
in __mutex_lock_common kernel/locking/mutex.c:593 [inline] BUG: KASAN: slab-
use
-
after
-
free
in __mutex_lock+0x147/0x1350 kernel/locking/mutex.
unread,
[syzbot] [pm?] KASAN: slab-use-after-free Read in thermal_zone_device_check
slab-
use
-
after
-
free
in __mutex_lock_common kernel/locking/mutex.c:593 [inline] BUG: KASAN: slab-
use
-
after
-
free
in __mutex_lock+0x147/0x1350 kernel/locking/mutex.
12/23/25
syzbot
12/21/25
[syzbot] [usb?] KASAN: slab-use-after-free Read in vhci_tx_loop
slab-
use
-
after
-
free
in vhci_send_cmd_submit drivers/usb/usbip/vhci_tx.c:69 [inline] BUG: KASAN: slab-
use
-
after
-
free
in vhci_tx_loop+0x38e/0x1a80 drivers/usb/usbip
unread,
[syzbot] [usb?] KASAN: slab-use-after-free Read in vhci_tx_loop
slab-
use
-
after
-
free
in vhci_send_cmd_submit drivers/usb/usbip/vhci_tx.c:69 [inline] BUG: KASAN: slab-
use
-
after
-
free
in vhci_tx_loop+0x38e/0x1a80 drivers/usb/usbip
12/21/25
syzbot
2
12/18/25
[syzbot] [io-uring?] KASAN: slab-use-after-free Read in io_poll_remove_entries (2)
slab-
use
-
after
-
free
Read in io_poll_remove_entries (2) Author: axboe@kernel.dk #syz invalid On Fri, Nov 28, 2025 at 2:02 AM syzbot wrote: > > Hello, > > syzbot found
unread,
[syzbot] [io-uring?] KASAN: slab-use-after-free Read in io_poll_remove_entries (2)
slab-
use
-
after
-
free
Read in io_poll_remove_entries (2) Author: axboe@kernel.dk #syz invalid On Fri, Nov 28, 2025 at 2:02 AM syzbot wrote: > > Hello, > > syzbot found
12/18/25
syzbot ci
, …
Caleb Sander Mateos
6
Jan 20
[syzbot ci] Re: io_uring: avoid uring_lock for IORING_SETUP_SINGLE_ISSUER
io_uring:
use
release-acquire ordering for IORING_SETUP_R_DISABLED > * [PATCH v5 2/6] io_uring: clear IORING_SETUP_SINGLE_ISSUER for IORING_SETUP_SQPOLL > * [PATCH
unread,
[syzbot ci] Re: io_uring: avoid uring_lock for IORING_SETUP_SINGLE_ISSUER
io_uring:
use
release-acquire ordering for IORING_SETUP_R_DISABLED > * [PATCH v5 2/6] io_uring: clear IORING_SETUP_SINGLE_ISSUER for IORING_SETUP_SQPOLL > * [PATCH
Jan 20
syzbot
12/12/25
[syzbot] [kernfs?] KASAN: slab-use-after-free Read in kernfs_new_node
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
unread,
[syzbot] [kernfs?] KASAN: slab-use-after-free Read in kernfs_new_node
slab-
use
-
after
-
free
in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_read include/linux/atomic/atomic
12/12/25
syzbot
5
12/11/25
[syzbot] [ocfs2?] KASAN: use-after-free Read in ocfs2_check_dir_entry
KASAN:
use
-
after
-
free
Read in ocfs2_check_dir_entry (kworker/u8:17,5105,0):ocfs2_read_blocks_sync:112 ERROR: status = -12 (kworker/u8:17,5105,0):ocfs2_read_locked_inode
unread,
[syzbot] [ocfs2?] KASAN: use-after-free Read in ocfs2_check_dir_entry
KASAN:
use
-
after
-
free
Read in ocfs2_check_dir_entry (kworker/u8:17,5105,0):ocfs2_read_blocks_sync:112 ERROR: status = -12 (kworker/u8:17,5105,0):ocfs2_read_locked_inode
12/11/25
syzbot
, …
Lizhi Xu
19
12/9/25
[syzbot] [hams?] KASAN: slab-use-after-free Read in ax25_find_cb
slab-
use
-
after
-
free
in ax25_find_cb+0x179/0x3a0 net/ax25/af_ax25.c:236 Read of size 8 at addr ffff888077f9da10 by task syz.2.252/6544 CPU: 1 UID: 0 PID: 6544 Comm: syz.2.252
unread,
[syzbot] [hams?] KASAN: slab-use-after-free Read in ax25_find_cb
slab-
use
-
after
-
free
in ax25_find_cb+0x179/0x3a0 net/ax25/af_ax25.c:236 Read of size 8 at addr ffff888077f9da10 by task syz.2.252/6544 CPU: 1 UID: 0 PID: 6544 Comm: syz.2.252
12/9/25
syzbot
3
12/9/25
[syzbot] [bpf?] KASAN: slab-use-after-free Write in defer_free
slab-
use
-
after
-
free
in defer_free+0x3c/0xbc mm/slub.c:6537 Write at addr f3f000000854f020 by task kworker/u8:6/983 Pointer tag: [f3], memory tag: [fe] CPU: 0 UID: 0 PID: 983
unread,
[syzbot] [bpf?] KASAN: slab-use-after-free Write in defer_free
slab-
use
-
after
-
free
in defer_free+0x3c/0xbc mm/slub.c:6537 Write at addr f3f000000854f020 by task kworker/u8:6/983 Pointer tag: [f3], memory tag: [fe] CPU: 0 UID: 0 PID: 983
12/9/25
syzbot
3
12/22/25
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in le_read_features_complete
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:96 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_dec_and_test include/linux
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in le_read_features_complete
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:96 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_dec_and_test include/linux
12/22/25
syzbot
,
Edward Adam Davis
3
12/3/25
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in hci_conn_drop (3)
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:96 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_dec_and_test include/linux
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Write in hci_conn_drop (3)
slab-
use
-
after
-
free
in instrument_atomic_read_write include/linux/instrumented.h:96 [inline] BUG: KASAN: slab-
use
-
after
-
free
in atomic_dec_and_test include/linux
12/3/25
syzbot
11/28/25
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_pull
slab-
use
-
after
-
free
in skb_pull_inline include/linux/skbuff.h:2839 [inline] BUG: KASAN: slab-
use
-
after
-
free
in skb_pull+0x133/0x1d0 net/core/skbuff.c:2619 Read of size
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in skb_pull
slab-
use
-
after
-
free
in skb_pull_inline include/linux/skbuff.h:2839 [inline] BUG: KASAN: slab-
use
-
after
-
free
in skb_pull+0x133/0x1d0 net/core/skbuff.c:2619 Read of size
11/28/25
syzbot
,
Edward Adam Davis
8
11/25/25
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_sock_new_connection_cb
:4099
process_one_work
kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue
unread,
[syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_sock_new_connection_cb
:4099
process_one_work
kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue
11/25/25
syzbot
11/24/25
[syzbot] [wireless?] KASAN: slab-use-after-free Read in __ieee80211_beacon_add_tim
slab-
use
-
after
-
free
in ieee80211_get_link_sband net/mac80211/ieee80211_i.h:1737 [inline] BUG: KASAN: slab-
use
-
after
-
free
in __ieee80211_beacon_add_tim+0x1d7/0x15a0
unread,
[syzbot] [wireless?] KASAN: slab-use-after-free Read in __ieee80211_beacon_add_tim
slab-
use
-
after
-
free
in ieee80211_get_link_sband net/mac80211/ieee80211_i.h:1737 [inline] BUG: KASAN: slab-
use
-
after
-
free
in __ieee80211_beacon_add_tim+0x1d7/0x15a0
11/24/25
syzbot ci
,
syzbot ci
2
11/21/25
[syzbot ci] Re: bpf: Fix FIONREAD and copied_seq issues
slab-
use
-
after
-
free
Read in tcp_ioctl Full report is available here: https://ci.syzbot.org/series/d61ee16d-47d7-4d43-ae17-0fb7c57066d9 *** KASAN: slab-out-of-bounds
unread,
[syzbot ci] Re: bpf: Fix FIONREAD and copied_seq issues
slab-
use
-
after
-
free
Read in tcp_ioctl Full report is available here: https://ci.syzbot.org/series/d61ee16d-47d7-4d43-ae17-0fb7c57066d9 *** KASAN: slab-out-of-bounds
11/21/25
ALBIN BABU VARGHESE
,
syzbot
11
11/21/25
KASAN: use-after-free Read in ext4_find_extent (4)
KASAN:
use
-
after
-
free
Read in ext4_find_extent ================================================================== BUG: KASAN:
use
-
after
-
free
in ext4_ext_binsearch
unread,
KASAN: use-after-free Read in ext4_find_extent (4)
KASAN:
use
-
after
-
free
Read in ext4_find_extent ================================================================== BUG: KASAN:
use
-
after
-
free
in ext4_ext_binsearch
11/21/25
syzbot
,
Hillf Danton
7
11/18/25
[syzbot] [kernel?] general protection fault in put_ipc_ns
slab-
use
-
after
-
free
in hci_cmd_work+0x5d0/0x7b0 [ 83.977772][ T5149] Read of size 2 at addr ffff88807912b178 by task kworker/u9:1/5149 [ 83.985826][ T5149] [ 83.988159][ T5149
unread,
[syzbot] [kernel?] general protection fault in put_ipc_ns
slab-
use
-
after
-
free
in hci_cmd_work+0x5d0/0x7b0 [ 83.977772][ T5149] Read of size 2 at addr ffff88807912b178 by task kworker/u9:1/5149 [ 83.985826][ T5149] [ 83.988159][ T5149
11/18/25