[v6.6] WARNING in smb2_add_credits

4 views
Skip to first unread message

syzbot

unread,
Jul 28, 2026, 8:45:28 AMJul 28
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: c5596480c50e Linux 6.6.145
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17585632580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0bc3d90c30838b5
dashboard link: https://syzkaller.appspot.com/bug?extid=04d6a0157da850d58691
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/eb5cda0a8020/disk-c5596480.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ca05ff2fc502/vmlinux-c5596480.xz
kernel image: https://storage.googleapis.com/syzbot-assets/6daf3255b985/bzImage-c5596480.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+04d6a0...@syzkaller.appspotmail.com

CIFS: VFS: \\127.0.0.1 Error -32 sending data on socket to server
------------[ cut here ]------------
WARNING: CPU: 0 PID: 15513 at fs/smb/client/smb2ops.c:97 smb2_add_credits+0x1365/0x2600 fs/smb/client/smb2ops.c:97
Modules linked in:
CPU: 0 PID: 15513 Comm: syz.0.2372 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/16/2026
RIP: 0010:smb2_add_credits+0x1365/0x2600 fs/smb/client/smb2ops.c:97
Code: 03 42 80 3c 28 00 74 08 4c 89 e7 e8 55 b4 3c ff 49 8b 34 24 48 c7 c7 20 20 f7 8a e8 75 15 de 07 e9 eb f9 ff ff e8 bb 36 e4 fe <0f> 0b e9 d9 ef ff ff e8 af 36 e4 fe c6 05 0d c3 d3 0b 01 48 c7 c7
RSP: 0018:ffffc9000393f400 EFLAGS: 00010283
RAX: ffffffff82a33e15 RBX: ffff88807cd262c0 RCX: 0000000000080000
RDX: ffffc9000f92a000 RSI: 000000000003f46d RDI: 000000000003f46e
RBP: 0000000000000200 R08: 0000000000000003 R09: 0000000000000004
R10: dffffc0000000000 R11: fffff52000727e70 R12: 1ffff1100f9a4c58
R13: dffffc0000000000 R14: ffff88807cd26000 R15: 0000000000000000
FS: 00007f350c8096c0(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f9b6d224ff8 CR3: 0000000024fef000 CR4: 00000000003506f0
Call Trace:
<TASK>
add_credits fs/smb/client/cifsglob.h:884 [inline]
compound_send_recv+0x1254/0x3040 fs/smb/client/transport.c:1193
cifs_send_recv+0x40/0x50 fs/smb/client/transport.c:1317
SMB2_negotiate+0x16b5/0x4270 fs/smb/client/smb2pdu.c:1144
cifs_negotiate_protocol+0x27a/0x670 fs/smb/client/connect.c:4008
cifs_get_smb_ses+0x8d6/0x1b00 fs/smb/client/connect.c:2434
cifs_mount_get_session+0xef/0x440 fs/smb/client/connect.c:3472
get_session fs/smb/client/dfs.c:62 [inline]
dfs_mount_share+0x1e9/0x7b0 fs/smb/client/dfs.c:285
cifs_mount+0xbc/0x650 fs/smb/client/connect.c:3720
cifs_smb3_do_mount+0x2e5/0x710 fs/smb/client/cifsfs.c:950
smb3_get_tree_common fs/smb/client/fs_context.c:785 [inline]
smb3_get_tree+0x5a5/0xa90 fs/smb/client/fs_context.c:805
vfs_get_tree+0x8c/0x280 fs/super.c:1764
vfs_cmd_create+0xe3/0x230 fs/fsopen.c:236
__do_sys_fsconfig fs/fsopen.c:481 [inline]
__se_sys_fsconfig+0x70a/0x850 fs/fsopen.c:355
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f350b99de99
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f350c809028 EFLAGS: 00000246 ORIG_RAX: 00000000000001af
RAX: ffffffffffffffda RBX: 00007f350bc25fa0 RCX: 00007f350b99de99
RDX: 0000000000000000 RSI: 0000000000000006 RDI: 0000000000000004
RBP: 00007f350ba33eaf R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f350bc26038 R14: 00007f350bc25fa0 R15: 00007ffc1c71ad08
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 1, 2026, 10:51:33 AMAug 1
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: a1153c0deb44 Linux 6.6.147
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=174f0649580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0bc3d90c30838b5
dashboard link: https://syzkaller.appspot.com/bug?extid=04d6a0157da850d58691
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1130ee32580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/9f646bfa1b52/disk-a1153c0d.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a2aec2e8f0fd/vmlinux-a1153c0d.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a7abe1f87405/bzImage-a1153c0d.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+04d6a0...@syzkaller.appspotmail.com

cifs_smb3_do_mount: 14 callbacks suppressed
CIFS: Attempting to mount //127.0.0.1/share
CIFS: VFS: \\127.0.0.1 Error -104 sending data on socket to server
------------[ cut here ]------------
WARNING: CPU: 0 PID: 6330 at fs/smb/client/smb2ops.c:97 smb2_add_credits+0x1365/0x2600 fs/smb/client/smb2ops.c:97
Modules linked in:
CPU: 0 PID: 6330 Comm: syz.1.102 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/16/2026
RIP: 0010:smb2_add_credits+0x1365/0x2600 fs/smb/client/smb2ops.c:97
Code: 03 42 80 3c 28 00 74 08 4c 89 e7 e8 15 b4 3c ff 49 8b 34 24 48 c7 c7 20 20 f7 8a e8 15 0b de 07 e9 eb f9 ff ff e8 ab 36 e4 fe <0f> 0b e9 d9 ef ff ff e8 9f 36 e4 fe c6 05 ad c8 d3 0b 01 48 c7 c7
RSP: 0018:ffffc90004ecf400 EFLAGS: 00010293
RAX: ffffffff82a33875 RBX: ffff88805b5f42c0 RCX: ffff888023a48000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000200 R08: 0000000000000003 R09: 0000000000000004
R10: dffffc0000000000 R11: fffff520009d9e70 R12: 1ffff1100b6be858
R13: dffffc0000000000 R14: ffff88805b5f4000 R15: 0000000000000000
FS: 00007ffaf25076c0(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00002000000000c0 CR3: 0000000079436000 CR4: 00000000003506f0
Call Trace:
<TASK>
add_credits fs/smb/client/cifsglob.h:884 [inline]
compound_send_recv+0x1254/0x3040 fs/smb/client/transport.c:1193
cifs_send_recv+0x40/0x50 fs/smb/client/transport.c:1317
SMB2_negotiate+0x16b5/0x4270 fs/smb/client/smb2pdu.c:1144
cifs_negotiate_protocol+0x445/0x670 fs/smb/client/connect.c:4008
cifs_get_smb_ses+0x8d6/0x1b00 fs/smb/client/connect.c:2434
cifs_mount_get_session+0xef/0x440 fs/smb/client/connect.c:3472
get_session fs/smb/client/dfs.c:62 [inline]
dfs_mount_share+0x1e9/0x7b0 fs/smb/client/dfs.c:285
cifs_mount+0xbc/0x650 fs/smb/client/connect.c:3720
cifs_smb3_do_mount+0x2e5/0x710 fs/smb/client/cifsfs.c:950
smb3_get_tree_common fs/smb/client/fs_context.c:785 [inline]
smb3_get_tree+0x5a5/0xa90 fs/smb/client/fs_context.c:805
vfs_get_tree+0x8c/0x280 fs/super.c:1764
vfs_cmd_create+0xe3/0x230 fs/fsopen.c:236
__do_sys_fsconfig fs/fsopen.c:481 [inline]
__se_sys_fsconfig+0x70a/0x850 fs/fsopen.c:355
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7ffaf159e019
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffaf2507028 EFLAGS: 00000246 ORIG_RAX: 00000000000001af
RAX: ffffffffffffffda RBX: 00007ffaf1825fa0 RCX: 00007ffaf159e019
RDX: 0000000000000000 RSI: 0000000000000006 RDI: 0000000000000004
RBP: 00007ffaf163500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffaf1826038 R14: 00007ffaf1825fa0 R15: 00007ffdfd24f2a8
</TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Aug 10, 2026, 4:53:37 AM (8 days ago) Aug 10
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: aabd761612db Linux 5.15.215
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=15152079580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=27a959413eff403780cc
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f636f56d3662/disk-aabd7616.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f1a46620f40c/vmlinux-aabd7616.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9b78bb48b022/bzImage-aabd7616.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+27a959...@syzkaller.appspotmail.com

CIFS: No dialect specified on mount. Default has changed to a more secure dialect, SMB2.1 or later (e.g. SMB3.1.1), from CIFS (SMB1). To use the less secure SMB1 dialect to access old servers which do not support SMB3.1.1 (or even SMB3 or SMB2.1) specify vers=1.0 on mount.
CIFS: Attempting to mount \\127.0.0.1\test
CIFS: VFS: \\127.0.0.1 Error -32 sending data on socket to server
------------[ cut here ]------------
WARNING: CPU: 1 PID: 7414 at fs/cifs/smb2ops.c:88 smb2_add_credits+0x8df/0x1370 fs/cifs/smb2ops.c:88
Modules linked in:
CPU: 1 PID: 7414 Comm: syz.7.586 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:smb2_add_credits+0x8df/0x1370 fs/cifs/smb2ops.c:88
Code: 02 00 00 03 2a 45 89 ef 41 29 ef 48 8b 44 24 38 42 0f b6 04 20 84 c0 0f 85 e1 02 00 00 44 89 3e e9 61 fb ff ff e8 f1 b0 02 ff <0f> 0b e9 42 f9 ff ff e8 e5 b0 02 ff c6 05 89 08 01 0b 01 48 c7 c7
RSP: 0018:ffffc900015bf3c8 EFLAGS: 00010283
RAX: ffffffff82764bbf RBX: ffff8880667a2224 RCX: 0000000000080000
RDX: ffffc90015af1000 RSI: 0000000000038b19 RDI: 0000000000038b1a
RBP: 1ffff1100ccf4445 R08: 0000000000000003 R09: 0000000000000004
R10: dffffc0000000000 R11: fffff520002b7e68 R12: ffff8880667a222c
R13: 0000000000000200 R14: ffff8880667a2000 R15: 0000000000000000
FS: 00007fd0663586c0(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fc4283cefd0 CR3: 0000000076cff000 CR4: 00000000003506e0
Call Trace:
<TASK>
add_credits fs/cifs/cifsglob.h:745 [inline]
compound_send_recv+0x1054/0x3290 fs/cifs/transport.c:1173
cifs_send_recv+0x3c/0x50 fs/cifs/transport.c:1288
SMB2_negotiate+0x1721/0x4390 fs/cifs/smb2pdu.c:930
smb2_negotiate+0xdf/0x120 fs/cifs/smb2ops.c:395
cifs_negotiate_protocol fs/cifs/connect.c:3811 [inline]
cifs_get_smb_ses+0x890/0x2150 fs/cifs/connect.c:2056
mount_get_conns+0xf8/0xe00 fs/cifs/connect.c:2996
is_dfs_mount fs/cifs/connect.c:3354 [inline]
cifs_mount+0x162/0x1380 fs/cifs/connect.c:3549
cifs_smb3_do_mount+0x366/0x760 fs/cifs/cifsfs.c:895
smb3_get_tree_common fs/cifs/fs_context.c:708 [inline]
smb3_get_tree+0x59a/0xa80 fs/cifs/fs_context.c:726
vfs_get_tree+0x88/0x270 fs/super.c:1530
do_new_mount+0x247/0xa40 fs/namespace.c:3034
do_mount fs/namespace.c:3377 [inline]
__do_sys_mount fs/namespace.c:3585 [inline]
__se_sys_mount+0x2e3/0x3d0 fs/namespace.c:3562
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7fd0681000d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fd066358028 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007fd068387fa0 RCX: 00007fd0681000d9
RDX: 0000200000000240 RSI: 0000200000000200 RDI: 0000000000000000
RBP: 00007fd068197024 R08: 0000200000000300 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fd068388038 R14: 00007fd068387fa0 R15: 00007ffdc80033e8

syzbot

unread,
Aug 10, 2026, 6:17:24 AM (8 days ago) Aug 10
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: aabd761612db Linux 5.15.215
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10812149580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=27a959413eff403780cc
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16332079580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=106762c6580000
CIFS: Attempting to mount \\127.0.0.1\test
CIFS: VFS: \\127.0.0.1 Error -104 sending data on socket to server
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4365 at fs/cifs/smb2ops.c:88 smb2_add_credits+0x8df/0x1370 fs/cifs/smb2ops.c:88
Modules linked in:
CPU: 0 PID: 4365 Comm: syz.1.18 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:smb2_add_credits+0x8df/0x1370 fs/cifs/smb2ops.c:88
Code: 02 00 00 03 2a 45 89 ef 41 29 ef 48 8b 44 24 38 42 0f b6 04 20 84 c0 0f 85 e1 02 00 00 44 89 3e e9 61 fb ff ff e8 f1 b0 02 ff <0f> 0b e9 42 f9 ff ff e8 e5 b0 02 ff c6 05 89 08 01 0b 01 48 c7 c7
RSP: 0018:ffffc900032cf3c8 EFLAGS: 00010293
RAX: ffffffff82764bbf RBX: ffff88807f72a224 RCX: ffff88807ab09dc0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 1ffff1100fee5445 R08: 0000000000000003 R09: 0000000000000004
R10: dffffc0000000000 R11: fffff52000659e68 R12: ffff88807f72a22c
R13: 0000000000000200 R14: ffff88807f72a000 R15: 0000000000000000
FS: 00007f2b349856c0(0000) GS:ffff8880b9000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2b353727c0 CR3: 000000007961c000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
add_credits fs/cifs/cifsglob.h:745 [inline]
compound_send_recv+0x1054/0x3290 fs/cifs/transport.c:1173
cifs_send_recv+0x3c/0x50 fs/cifs/transport.c:1288
SMB2_negotiate+0x1721/0x4390 fs/cifs/smb2pdu.c:930
smb2_negotiate+0xdf/0x120 fs/cifs/smb2ops.c:395
cifs_negotiate_protocol fs/cifs/connect.c:3811 [inline]
cifs_get_smb_ses+0x890/0x2150 fs/cifs/connect.c:2056
mount_get_conns+0xf8/0xe00 fs/cifs/connect.c:2996
is_dfs_mount fs/cifs/connect.c:3354 [inline]
cifs_mount+0x162/0x1380 fs/cifs/connect.c:3549
cifs_smb3_do_mount+0x366/0x760 fs/cifs/cifsfs.c:895
smb3_get_tree_common fs/cifs/fs_context.c:708 [inline]
smb3_get_tree+0x59a/0xa80 fs/cifs/fs_context.c:726
vfs_get_tree+0x88/0x270 fs/super.c:1530
do_new_mount+0x247/0xa40 fs/namespace.c:3034
do_mount fs/namespace.c:3377 [inline]
__do_sys_mount fs/namespace.c:3585 [inline]
__se_sys_mount+0x2e3/0x3d0 fs/namespace.c:3562
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f2b353250d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f2b34985028 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007f2b355acfa0 RCX: 00007f2b353250d9
RDX: 0000200000000240 RSI: 0000200000000200 RDI: 0000000000000000
RBP: 00007f2b353bc024 R08: 0000200000000300 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f2b355ad038 R14: 00007f2b355acfa0 R15: 00007ffee5109bb8
Reply all
Reply to author
Forward
0 new messages