Hello,
syzbot found the following issue on:
HEAD commit: f5098b6bae76 Linux 7.2-rc5
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=1416b88e580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=c05be6c9b0d36cb9
dashboard link:
https://syzkaller.appspot.com/bug?extid=d13ecd60c52f51110a7f
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
CC: [
da...@davemloft.net dsa...@kernel.org edum...@google.com ho...@kernel.org ku...@kernel.org linux-...@vger.kernel.org net...@vger.kernel.org pab...@redhat.com]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image (non-bootable):
https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-f5098b6b.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/0f5a35fe5f21/vmlinux-f5098b6b.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/62259844b3da/bzImage-f5098b6b.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+d13ecd...@syzkaller.appspotmail.com
Oops: general protection fault, probably for non-canonical address 0xee000d100251a81c: 0000 [#1] SMP KASAN NOPTI
KASAN: maybe wild-memory-access in range [0x70008880128d40e0-0x70008880128d40e7]
CPU: 0 UID: 0 PID: 12 Comm: kworker/u4:0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: ipv6_addrconf addrconf_dad_work
RIP: 0010:dev_get_by_index_rcu+0x7d/0x110 net/core/dev.c:988
Code: 00 74 08 4c 89 ff e8 b2 68 93 f8 4d 8b 37 4d 85 f6 74 7c 49 81 c6 a8 fa ff ff 74 73 4d 8d be e0 00 00 00 4c 89 f8 48 c1 e8 03 <42> 0f b6 04 20 84 c0 75 45 41 8b 2f 89 ef 89 de e8 5e 3c 24 f8 39
RSP: 0018:ffffc9000025f2b0 EFLAGS: 00010202
RAX: 0e0011100251a81c RBX: 0000000000000034 RCX: ffff88801cedca80
RDX: 0000000000000000 RSI: 0000000000000034 RDI: ffff888012690000
RBP: 0000000000000034 R08: ffffffff8bb59ef6 R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff8eb59c60 R12: dffffc0000000000
R13: ffffffff8bb59ef6 R14: 70008880128d4000 R15: 70008880128d40e0
FS: 0000000000000000(0000) GS:ffff88808c543000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fecbc458230 CR3: 0000000050207000 CR4: 0000000000352ef0
Call Trace:
<TASK>
l3mdev_update_flow+0xf8/0x610 net/l3mdev/l3mdev.c:278
ip6mr_fib_lookup net/ipv6/ip6mr.c:152 [inline]
mroute6_is_socket+0x1f0/0x370 net/ipv6/ip6mr.c:1697
ip6_finish_output2+0x641/0x13c0 net/ipv6/ip6_output.c:85
__ip6_finish_output net/ipv6/ip6_output.c:-1 [inline]
ip6_finish_output+0x292/0x770 net/ipv6/ip6_output.c:219
NF_HOOK_COND include/linux/netfilter.h:307 [inline]
ip6_output+0x337/0x540 net/ipv6/ip6_output.c:246
dst_output include/net/dst.h:471 [inline]
NF_HOOK+0x177/0x4f0 include/linux/netfilter.h:318
mld_sendpack+0x890/0xe10 net/ipv6/mcast.c:1869
ipv6_mc_dad_complete+0x87/0x410 net/ipv6/mcast.c:2295
addrconf_dad_completed+0x8af/0xe60 net/ipv6/addrconf.c:4375
addrconf_dad_work+0xcf8/0x15c0 net/ipv6/addrconf.c:-1
process_one_work kernel/workqueue.c:3322 [inline]
process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:dev_get_by_index_rcu+0x7d/0x110 net/core/dev.c:988
Code: 00 74 08 4c 89 ff e8 b2 68 93 f8 4d 8b 37 4d 85 f6 74 7c 49 81 c6 a8 fa ff ff 74 73 4d 8d be e0 00 00 00 4c 89 f8 48 c1 e8 03 <42> 0f b6 04 20 84 c0 75 45 41 8b 2f 89 ef 89 de e8 5e 3c 24 f8 39
RSP: 0018:ffffc9000025f2b0 EFLAGS: 00010202
RAX: 0e0011100251a81c RBX: 0000000000000034 RCX: ffff88801cedca80
RDX: 0000000000000000 RSI: 0000000000000034 RDI: ffff888012690000
RBP: 0000000000000034 R08: ffffffff8bb59ef6 R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff8eb59c60 R12: dffffc0000000000
R13: ffffffff8bb59ef6 R14: 70008880128d4000 R15: 70008880128d40e0
FS: 0000000000000000(0000) GS:ffff88808c543000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fecaf929000 CR3: 0000000043964000 CR4: 0000000000352ef0
----------------
Code disassembly (best guess):
0: 00 74 08 4c add %dh,0x4c(%rax,%rcx,1)
4: 89 ff mov %edi,%edi
6: e8 b2 68 93 f8 call 0xf89368bd
b: 4d 8b 37 mov (%r15),%r14
e: 4d 85 f6 test %r14,%r14
11: 74 7c je 0x8f
13: 49 81 c6 a8 fa ff ff add $0xfffffffffffffaa8,%r14
1a: 74 73 je 0x8f
1c: 4d 8d be e0 00 00 00 lea 0xe0(%r14),%r15
23: 4c 89 f8 mov %r15,%rax
26: 48 c1 e8 03 shr $0x3,%rax
* 2a: 42 0f b6 04 20 movzbl (%rax,%r12,1),%eax <-- trapping instruction
2f: 84 c0 test %al,%al
31: 75 45 jne 0x78
33: 41 8b 2f mov (%r15),%ebp
36: 89 ef mov %ebp,%edi
38: 89 de mov %ebx,%esi
3a: e8 5e 3c 24 f8 call 0xf8243c9d
3f: 39 .byte 0x39
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup