Hello,
syzbot found the following issue on:
HEAD commit: 3dd691bf9970 sys/uvideo: add quriks for Elgato Game Captur..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=11a273df980000
kernel config:
https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link:
https://syzkaller.appspot.com/bug?extid=ad6862768dc0eea6581b
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/cbd07261d2d1/disk-3dd691bf.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/53e5106b2ada/bsd-3dd691bf.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/5158f0d541ec/kernel-3dd691bf.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+ad6862...@syzkaller.appspotmail.com
panic: malloc: allocation too large, type = 31, size = 4294965210
Starting stack trace...
panic(ffffffff8309fd03) at panic+0x1d0 sys/kern/subr_prf.c:229
malloc(fffff7da,1f,1) at malloc+0xcf4 sys/kern/kern_malloc.c:334
sys_semop(ffff8000ffff8f50,ffff80002a4f6d90,ffff80002a4f6ce0) at sys_semop+0x234 sys/kern/sysv_sem.c:564
syscall(ffff80002a4f6d90) at syscall+0xb08 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80002a4f6d90) at syscall+0xb08 sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x5ce62b252e0, count: 252
End of stack trace.
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup