uvm_fault: _copyinstr

1 view
Skip to first unread message

syzbot

unread,
May 3, 2025, 5:52:29 AMMay 3
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 0e444de8113c sync
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10efaa70580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=3bcb000ffd1b8ac74c2a

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/1a716a836012/disk-0e444de8.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/abe162202d17/bsd-0e444de8.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/7c49d518f650/kernel-0e444de8.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3bcb00...@syzkaller.appspotmail.com

uvm_fault(0xfffffd806beb13d8, 0x0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at _copyinstr+0x58: lodsb (%rsi)
TID PID UID PRFLAGS PFLAGS CPU COMMAND
* 13602 43624 0 0x2000 0x4000000 0K syz-executor
_copyinstr() at _copyinstr+0x58
sys_unveil(ffff80003c447d58,ffff80002c3e2870,ffff80002c3e27c0) at sys_unveil+0x152 sys/kern/vfs_syscalls.c:982
syscall(ffff80002c3e2870) at syscall+0xb08 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80002c3e2870) at syscall+0xb08 sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x5262dafd870, count: 11
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Nov 1, 2025, 8:34:19 PM (8 days ago) Nov 1
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages