[v6.6] WARNING in nft_pipapo_destroy

0 views
Skip to first unread message

syzbot

unread,
Aug 10, 2026, 3:11:35 PM (5 days ago) Aug 10
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d27334b2888c Linux 6.6.151
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=120ce079580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0bc3d90c30838b5
dashboard link: https://syzkaller.appspot.com/bug?extid=b338ce808595248a409a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/695139abd971/disk-d27334b2.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/b11fc121442a/vmlinux-d27334b2.xz
kernel image: https://storage.googleapis.com/syzbot-assets/e226f54f9286/bzImage-d27334b2.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b338ce...@syzkaller.appspotmail.com

usb 4-1: ath9k_htc: USB layer deinitialized
------------[ cut here ]------------
WARNING: CPU: 0 PID: 8 at net/netfilter/nft_set_pipapo.c:2389 nft_pipapo_destroy+0x84b/0x8b0 net/netfilter/nft_set_pipapo.c:2389
Modules linked in:
CPU: 0 PID: 8 Comm: kworker/0:0 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: events nf_tables_trans_destroy_work
RIP: 0010:nft_pipapo_destroy+0x84b/0x8b0 net/netfilter/nft_set_pipapo.c:2389
Code: 00 00 48 83 c4 50 5b 41 5c 41 5d 41 5e 41 5f 5d c3 e8 89 b4 ab f8 e9 d3 f9 ff ff e8 7f b4 ab f8 e9 6c fe ff ff e8 75 b4 ab f8 <0f> 0b e9 16 f8 ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 0f 8c e3 f9
RSP: 0018:ffffc900000d79d8 EFLAGS: 00010293
RAX: ffffffff88dbbdab RBX: ffff88807dea5cf0 RCX: ffff88801b655a00
RDX: 0000000000000000 RSI: ffff88807dea5c00 RDI: ffff88804f518628
RBP: ffffc900000d7bb0 R08: ffff88801b655a00 R09: 000000000000000f
R10: 0000000000000020 R11: 0000000000000000 R12: ffff88807dea5cc0
R13: dffffc0000000000 R14: ffff88807dea5d10 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000001200 CR3: 000000002c432000 CR4: 00000000003506f0
Call Trace:
<TASK>
nft_set_destroy+0x489/0xa20 net/netfilter/nf_tables_api.c:5363
nft_commit_release net/netfilter/nf_tables_api.c:9544 [inline]
nf_tables_trans_destroy_work+0xb2d/0x11b0 net/netfilter/nf_tables_api.c:9587
process_one_work kernel/workqueue.c:2657 [inline]
process_scheduled_works+0xa60/0x1600 kernel/workqueue.c:2734
worker_thread+0xa5e/0xfe0 kernel/workqueue.c:2815
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 14, 2026, 8:10:38 PM (14 hours ago) Aug 14
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: aabd761612db Linux 5.15.215
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17678279580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=68ef5e861ea09f54325f
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f636f56d3662/disk-aabd7616.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f1a46620f40c/vmlinux-aabd7616.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9b78bb48b022/bzImage-aabd7616.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+68ef5e...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4234 at net/netfilter/nft_set_pipapo.c:2297 nft_pipapo_destroy+0x8b0/0x960 net/netfilter/nft_set_pipapo.c:2297
Modules linked in:
CPU: 1 PID: 4234 Comm: kworker/1:8 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: events nf_tables_trans_destroy_work
RIP: 0010:nft_pipapo_destroy+0x8b0/0x960 net/netfilter/nft_set_pipapo.c:2297
Code: 24 80 3c 18 00 74 08 4c 89 f7 e8 bb d0 81 f9 49 c7 06 00 00 00 00 48 83 c4 40 5b 41 5c 41 5d 41 5e 41 5f 5d c3 e8 60 ad 3c f9 <0f> 0b e9 ad f7 ff ff 48 c7 c1 f0 0f 8b 8d 80 e1 07 80 c1 03 38 c1
RSP: 0018:ffffc900031dfa68 EFLAGS: 00010293
RAX: ffffffff883c4f50 RBX: ffff88801d49a0f0 RCX: ffff888028e41dc0
RDX: 0000000000000000 RSI: ffff88801d49a000 RDI: ffff88801e877328
RBP: ffffc900031dfc30 R08: ffff888028e41dc0 R09: 0000000000000008
R10: 0000000000000018 R11: 0000000000000000 R12: ffff88801d49a0c0
R13: dffffc0000000000 R14: ffff88801d49a110 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff33f3bb158 CR3: 000000002a554000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
nft_set_destroy+0x488/0xa30 net/netfilter/nf_tables_api.c:4972
nft_commit_release net/netfilter/nf_tables_api.c:8872 [inline]
nf_tables_trans_destroy_work+0xc5d/0xf00 net/netfilter/nf_tables_api.c:8912
process_one_work+0x867/0xff0 kernel/workqueue.c:2310
worker_thread+0xad7/0x12a0 kernel/workqueue.c:2457
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287

syzbot

unread,
Aug 14, 2026, 8:11:37 PM (14 hours ago) Aug 14
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: e4f7d8be268e Linux 6.1.182
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1179d279580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=fb0e154ca75b0e246d73
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7cd9b1875376/disk-e4f7d8be.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/4b5d35d18c31/vmlinux-e4f7d8be.xz
kernel image: https://storage.googleapis.com/syzbot-assets/d5ee64c2af77/Image-e4f7d8be.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+fb0e15...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 7 at net/netfilter/nft_set_pipapo.c:2327 nft_pipapo_destroy+0x784/0x7e0 net/netfilter/nft_set_pipapo.c:2327
Modules linked in:
CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
Workqueue: events nf_tables_trans_destroy_work
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : nft_pipapo_destroy+0x784/0x7e0 net/netfilter/nft_set_pipapo.c:2327
lr : nft_pipapo_destroy+0x784/0x7e0 net/netfilter/nft_set_pipapo.c:2327
sp : ffff80001cb17990
x29: ffff80001cb179b0 x28: dfff800000000000 x27: 1fffe000188b9e99
x26: dfff800000000000 x25: ffff0000c45cf4cc x24: ffff0000c45cf400
x23: ffff0000d27bcb18 x22: 000000000000000b x21: ffff800013c7f150
x20: ffff0000d27bcb10 x19: ffff0000c45cf4f0 x18: 1fffe00033e7277e
x17: ffff80001033dd7c x16: ffff8000082dd248 x15: 0000000000000000
x14: 0000000000000018 x13: 0000000000ff0100 x12: ffff800017a84150
x11: ff008000103b4120 x10: 0000000000000000 x9 : ffff8000103b4120
x8 : ffff0000c09a3800 x7 : 0000000000000000 x6 : 000000000000003f
x5 : 0000000000000040 x4 : 0000000000000001 x3 : 0000000000000000
x2 : ffff0000d27bcb10 x1 : ffff0000c45cf400 x0 : ffff0000d27bcb28
Call trace:
nft_pipapo_destroy+0x784/0x7e0 net/netfilter/nft_set_pipapo.c:2327
nft_set_destroy+0x3ac/0x89c net/netfilter/nf_tables_api.c:5066
nft_commit_release net/netfilter/nf_tables_api.c:9107 [inline]
nf_tables_trans_destroy_work+0x980/0xd64 net/netfilter/nf_tables_api.c:9147
process_one_work+0x7e4/0x13bc kernel/workqueue.c:2292
worker_thread+0x8cc/0xfe8 kernel/workqueue.c:2439
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
irq event stamp: 106570
hardirqs last enabled at (106569): [<ffff8000088f5614>] kasan_quarantine_put+0xc4/0x200 mm/kasan/quarantine.c:242
hardirqs last disabled at (106570): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (106462): [<ffff80000a93613c>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (106460): [<ffff80000a936108>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---
Reply all
Reply to author
Forward
0 new messages