[moderation] [fs?] kernel BUG in set_ps_flags

1 view
Skip to first unread message

syzbot

unread,
Mar 15, 2026, 11:30:33 AM (16 hours ago) Mar 15
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: b29fb8829bff Merge tag 'v7.0-rc3-ksmbd-server-fixes' of gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=10336f5a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=163cf0fb07ea84d3
dashboard link: https://syzkaller.appspot.com/bug?extid=752fac0e14c568144eb1
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
CC: [linux-...@vger.kernel.org linux-...@vger.kernel.org]

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d031abe6d097/disk-b29fb882.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/0357a6ee7a21/vmlinux-b29fb882.xz
kernel image: https://storage.googleapis.com/syzbot-assets/e53eec9d067a/bzImage-b29fb882.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+752fac...@syzkaller.appspotmail.com

bdev_release+0x47f/0x6d0 block/bdev.c:1160
blkdev_release+0x15/0x20 block/fops.c:705
__fput+0x3ff/0xb40 fs/file_table.c:469
task_work_run+0x150/0x240 kernel/task_work.c:233
resume_user_mode_work include/linux/resume_user_mode.h:50 [inline]
__exit_to_user_mode_loop kernel/entry/common.c:67 [inline]
exit_to_user_mode_loop+0x100/0x4a0 kernel/entry/common.c:98
__exit_to_user_mode_prepare include/linux/irq-entry-common.h:226 [inline]
syscall_exit_to_user_mode_prepare include/linux/irq-entry-common.h:256 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:325 [inline]
do_syscall_64+0x668/0xf80 arch/x86/entry/syscall_64.c:100
entry_SYSCALL_64_after_hwframe+0x77/0x7f
------------[ cut here ]------------
kernel BUG at ./include/linux/page-flags.h:351!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 17335 Comm: syz.1.1942 Tainted: G L syzkaller #0 PREEMPT(full)
Tainted: [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/27/2026
RIP: 0010:const_folio_flags include/linux/page-flags.h:351 [inline]
RIP: 0010:folio_test_idle include/linux/page-flags.h:673 [inline]
RIP: 0010:set_ps_flags+0x321/0x390 mm/util.c:1219
Code: f6 0f 84 9e fe ff ff e8 fd 6e b9 ff 49 83 ed 01 e9 98 fe ff ff e8 ef 6e b9 ff 48 c7 c6 00 61 be 8b 48 89 df e8 80 82 05 00 90 <0f> 0b e8 e8 f8 24 00 e9 0e fd ff ff e8 0e f9 24 00 e9 78 fd ff ff
RSP: 0018:ffffc9000cd7f900 EFLAGS: 00010246
RAX: 0000000000080000 RBX: ffffea0000e03e00 RCX: ffffc900063da000
RDX: 0000000000080000 RSI: ffffffff825429a8 RDI: ffff888035c2e044
RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000001 R12: ffffc9000cd7f9d0
R13: 0000000000000201 R14: ffffea0000e00034 R15: ffffc9000cd7f9d0
FS: 00007f77fa81f6c0(0000) GS:ffff88812444d000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f8ee6747e20 CR3: 00000000463ba000 CR4: 00000000003526f0
Call Trace:
<TASK>
snapshot_page+0x49a/0x660 mm/util.c:1255
get_kpage_count+0x94/0x240 fs/proc/page.c:50
kpage_read.isra.0+0x1b8/0x2b0 fs/proc/page.c:93
pde_read fs/proc/inode.c:308 [inline]
proc_reg_read+0x120/0x330 fs/proc/inode.c:318
do_loop_readv_writev fs/read_write.c:849 [inline]
do_loop_readv_writev fs/read_write.c:837 [inline]
vfs_readv+0x5d8/0x8d0 fs/read_write.c:1022
do_readv+0x13e/0x340 fs/read_write.c:1082
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f77f999c799
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f77fa81f028 EFLAGS: 00000246 ORIG_RAX: 0000000000000013
RAX: ffffffffffffffda RBX: 00007f77f9c15fa0 RCX: 00007f77f999c799
RDX: 0000000100000007 RSI: 00002000000001c0 RDI: 0000000000000003
RBP: 00007f77f9a32c99 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f77f9c16038 R14: 00007f77f9c15fa0 R15: 00007ffe87f034d8
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:const_folio_flags include/linux/page-flags.h:351 [inline]
RIP: 0010:folio_test_idle include/linux/page-flags.h:673 [inline]
RIP: 0010:set_ps_flags+0x321/0x390 mm/util.c:1219
Code: f6 0f 84 9e fe ff ff e8 fd 6e b9 ff 49 83 ed 01 e9 98 fe ff ff e8 ef 6e b9 ff 48 c7 c6 00 61 be 8b 48 89 df e8 80 82 05 00 90 <0f> 0b e8 e8 f8 24 00 e9 0e fd ff ff e8 0e f9 24 00 e9 78 fd ff ff
RSP: 0018:ffffc9000cd7f900 EFLAGS: 00010246
RAX: 0000000000080000 RBX: ffffea0000e03e00 RCX: ffffc900063da000
RDX: 0000000000080000 RSI: ffffffff825429a8 RDI: ffff888035c2e044
RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000001 R12: ffffc9000cd7f9d0
R13: 0000000000000201 R14: ffffea0000e00034 R15: ffffc9000cd7f9d0
FS: 00007f77fa81f6c0(0000) GS:ffff88812434d000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055558fcd99b8 CR3: 00000000463ba000 CR4: 00000000003526f0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages