Hello,
syzbot found the following issue on:
HEAD commit: ccd1cdca5cd4 Merge tag 'nfsd-6.19-1' of git://git.kernel.o..
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=132470fc580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=1f2b6fe1fdf1a00b
dashboard link:
https://syzkaller.appspot.com/bug?extid=179950e204b042a6679c
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
CC: [
gre...@linuxfoundation.org linux-...@vger.kernel.org linu...@vger.kernel.org]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/7a2605cdbf37/disk-ccd1cdca.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/1a90296b9771/vmlinux-ccd1cdca.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/01272b1902ce/bzImage-ccd1cdca.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+179950...@syzkaller.appspotmail.com
usb 5-1: device descriptor read/64, error -71
usb 5-1: new full-speed USB device number 30 using dummy_hcd
usb 5-1: device descriptor read/64, error -110
usb usb5-port1: attempt power cycle
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000005: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
Workqueue: usb_hub_wq hub_event
RIP: 0010:set_link_state+0xbe4/0x1220 drivers/usb/gadget/udc/dummy_hcd.c:471
Code: 00 fc ff df 80 3c 08 00 74 08 4c 89 f7 e8 64 03 53 fb 4d 8b 26 49 83 c4 28 4c 89 e0 48 c1 e8 03 49 be 00 00 00 00 00 fc ff df <42> 80 3c 30 00 74 08 4c 89 e7 e8 3d 03 53 fb 4d 8b 1c 24 4c 8b 64
RSP: 0018:ffffc900000f7460 EFLAGS: 00010206
RAX: 0000000000000005 RBX: ffff888145310c3c RCX: dffffc0000000000
RDX: ffffc9001a365000 RSI: 000000000007a3ad RDI: 000000000007a3ae
RBP: ffff88805a240f6c R08: ffffffff8edb3477 R09: 1ffffffff1db668e
R10: dffffc0000000000 R11: fffffbfff1db668f R12: 0000000000000028
R13: 1ffff11028a67ea1 R14: dffffc0000000000 R15: 1ffff11028a62187
FS: 0000000000000000(0000) GS:ffff888126cef000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa3d2dde856 CR3: 0000000038270000 CR4: 00000000003526f0
Call Trace:
<TASK>
dummy_hub_control+0xafc/0x1a30 drivers/usb/gadget/udc/dummy_hcd.c:-1
rh_call_control drivers/usb/core/hcd.c:656 [inline]
rh_urb_enqueue drivers/usb/core/hcd.c:821 [inline]
usb_hcd_submit_urb+0xdbe/0x1b60 drivers/usb/core/hcd.c:1542
usb_start_wait_urb+0x115/0x4f0 drivers/usb/core/message.c:59
usb_internal_control_msg drivers/usb/core/message.c:103 [inline]
usb_control_msg+0x232/0x3e0 drivers/usb/core/message.c:154
usb_clear_port_feature drivers/usb/core/hub.c:456 [inline]
usb_hub_set_port_power drivers/usb/core/hub.c:894 [inline]
hub_port_connect drivers/usb/core/hub.c:5607 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5707 [inline]
port_event drivers/usb/core/hub.c:5871 [inline]
hub_event+0x2d55/0x4f30 drivers/usb/core/hub.c:5953
process_one_work kernel/workqueue.c:3257 [inline]
process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340
worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421
kthread+0x711/0x8a0 kernel/kthread.c:463
ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
---[ end trace 0000000000000000 ]---
RIP: 0010:set_link_state+0xbe4/0x1220 drivers/usb/gadget/udc/dummy_hcd.c:471
Code: 00 fc ff df 80 3c 08 00 74 08 4c 89 f7 e8 64 03 53 fb 4d 8b 26 49 83 c4 28 4c 89 e0 48 c1 e8 03 49 be 00 00 00 00 00 fc ff df <42> 80 3c 30 00 74 08 4c 89 e7 e8 3d 03 53 fb 4d 8b 1c 24 4c 8b 64
RSP: 0018:ffffc900000f7460 EFLAGS: 00010206
RAX: 0000000000000005 RBX: ffff888145310c3c RCX: dffffc0000000000
RDX: ffffc9001a365000 RSI: 000000000007a3ad RDI: 000000000007a3ae
RBP: ffff88805a240f6c R08: ffffffff8edb3477 R09: 1ffffffff1db668e
R10: dffffc0000000000 R11: fffffbfff1db668f R12: 0000000000000028
R13: 1ffff11028a67ea1 R14: dffffc0000000000 R15: 1ffff11028a62187
FS: 0000000000000000(0000) GS:ffff888126cef000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa3d2dde856 CR3: 0000000036030000 CR4: 00000000003526f0
----------------
Code disassembly (best guess), 3 bytes skipped:
0: df 80 3c 08 00 74 filds 0x7400083c(%rax)
6: 08 4c 89 f7 or %cl,-0x9(%rcx,%rcx,4)
a: e8 64 03 53 fb call 0xfb530373
f: 4d 8b 26 mov (%r14),%r12
12: 49 83 c4 28 add $0x28,%r12
16: 4c 89 e0 mov %r12,%rax
19: 48 c1 e8 03 shr $0x3,%rax
1d: 49 be 00 00 00 00 00 movabs $0xdffffc0000000000,%r14
24: fc ff df
* 27: 42 80 3c 30 00 cmpb $0x0,(%rax,%r14,1) <-- trapping instruction
2c: 74 08 je 0x36
2e: 4c 89 e7 mov %r12,%rdi
31: e8 3d 03 53 fb call 0xfb530373
36: 4d 8b 1c 24 mov (%r12),%r11
3a: 4c rex.WR
3b: 8b .byte 0x8b
3c: 64 fs
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup