[moderation] [lsm?] BUG: unable to handle kernel paging request in asm_sysvec_apic_timer_interrupt

1 view
Skip to first unread message

syzbot

unread,
Aug 15, 2025, 3:41:33 AM8/15/25
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 8f5ae30d69d7 Linux 6.17-rc1
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1736a9a2580000
kernel config: https://syzkaller.appspot.com/x/.config?x=13f39c6a0380a209
dashboard link: https://syzkaller.appspot.com/bug?extid=59f6fdf25b7c453e691e
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
CC: [ca...@schaufler-ca.com jmo...@namei.org linux-...@vger.kernel.org linux-secu...@vger.kernel.org pa...@paul-moore.com se...@hallyn.com]

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/46150b6d2447/disk-8f5ae30d.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/1c604b2b2258/vmlinux-8f5ae30d.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9c542f0972de/bzImage-8f5ae30d.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+59f6fd...@syzkaller.appspotmail.com

ntfs3(loop2): Different NTFS sector size (1024) and media sector size (512).
ntfs3(loop2): $AttrDef is corrupted.
BUG: unable to handle page fault for address: ffffffff8d037761
#PF: supervisor write access in kernel mode
#PF: error_code(0x0003) - permissions violation
PGD d7ab067 P4D d7ab067 PUD d7ac063 PMD 800000000d0001a1
Oops: Oops: 0003 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 6449 Comm: syz.2.73 Tainted: G W 6.17.0-rc1-syzkaller #0 PREEMPT_{RT,(full)}
Tainted: [W]=WARN
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
RIP: 0010:asm_sysvec_apic_timer_interrupt+0x1b/0x20 arch/x86/include/asm/idtentry.h:702
Code: c4 48 89 e7 e8 26 c5 f5 09 e9 41 06 00 00 90 f3 0f 1e fa 0f 01 ca fc 6a ff e8 f1 04 00 00 48 89 c4 48 89 e7 e8 56 c3 f5 09 e9 <21> 06 00 00 90 f3 0f 1e fa 0f 01 ca fc 6a ff e8 d1 04 00 00 48 89
RSP: 0018:ffffc9000cd1f628 EFLAGS: 00010006
RAX: 395bd97520986900 RBX: 0000000000000000 RCX: 0000000020986900
RDX: 0000000000000000 RSI: ffffffff8d037761 RDI: ffffffff8b620900
RBP: 0000000000000000 R08: ffffffff8f1d3937 R09: 1ffffffff1e3a726
R10: dffffc0000000000 R11: fffffbfff1e3a727 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
FS: 00007f5ae263e6c0(0000) GS:ffff8881269c5000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffff8d037761 CR3: 0000000029406000 CR4: 00000000003526f0
Call Trace:
<TASK>
RIP: 0010:kasan_check_range+0x5/0x2c0 mm/kasan/generic.c:188
Code: 21 8d e8 2e 32 0a ff 90 0f 0b cc cc cc cc cc cc cc cc cc cc cc 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 55 <41> 57 41 56 41 55 41 54 53 b0 01 48 85 f6 0f 84 ba 01 00 00 4c 8d
RSP: 0018:ffffc9000cd1f6d0 EFLAGS: 00000246
RAX: ffffffff84716e72 RBX: 0000000000000028 RCX: ffffffff84716e8a
RDX: 0000000000000001 RSI: 0000000000000028 RDI: ffffc9000cd1f760
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: ffffc9000cd1f740 R11: fffff520019a3ef1 R12: 1ffff920019a3ee4
R13: ffffc9000cd1f740 R14: ffffc9000cd1f760 R15: ffffc9000cd1f760
__asan_memset+0x22/0x50 mm/kasan/shadow.c:84
smk_ad_init security/smack/smack.h:456 [inline]
smack_inode_permission+0x20a/0x320 security/smack/smack_lsm.c:1215
security_inode_permission+0xf8/0x310 security/security.c:2324
may_lookup fs/namei.c:1851 [inline]
link_path_walk+0x851/0xea0 fs/namei.c:2445
path_openat+0x298/0x3840 fs/namei.c:4042
do_filp_open+0x1fa/0x410 fs/namei.c:4073
do_sys_openat2+0x121/0x1c0 fs/open.c:1435
do_sys_open fs/open.c:1450 [inline]
__do_sys_openat fs/open.c:1466 [inline]
__se_sys_openat fs/open.c:1461 [inline]
__x64_sys_openat+0x138/0x170 fs/open.c:1461
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f5ae43dd550
Code: 48 89 44 24 20 75 93 44 89 54 24 0c e8 49 94 02 00 44 8b 54 24 0c 89 da 48 89 ee 41 89 c0 bf 9c ff ff ff b8 01 01 00 00 0f 05 <48> 3d 00 f0 ff ff 77 38 44 89 c7 89 44 24 0c e8 9c 94 02 00 8b 44
RSP: 002b:00007f5ae263ddf0 EFLAGS: 00000293 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 0000000000000002 RCX: 00007f5ae43dd550
RDX: 0000000000000002 RSI: 00007f5ae263deb0 RDI: 00000000ffffff9c
RBP: 00007f5ae263deb0 R08: 0000000000000000 R09: 0000000002004894
R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000016
R13: 00007f5ae263deb0 R14: 000000000001f88f R15: 0000200000000780
</TASK>
Modules linked in:
CR2: ffffffff8d037761
---[ end trace 0000000000000000 ]---
RIP: 0010:asm_sysvec_apic_timer_interrupt+0x1b/0x20 arch/x86/include/asm/idtentry.h:702
Code: c4 48 89 e7 e8 26 c5 f5 09 e9 41 06 00 00 90 f3 0f 1e fa 0f 01 ca fc 6a ff e8 f1 04 00 00 48 89 c4 48 89 e7 e8 56 c3 f5 09 e9 <21> 06 00 00 90 f3 0f 1e fa 0f 01 ca fc 6a ff e8 d1 04 00 00 48 89
RSP: 0018:ffffc9000cd1f628 EFLAGS: 00010006
RAX: 395bd97520986900 RBX: 0000000000000000 RCX: 0000000020986900
RDX: 0000000000000000 RSI: ffffffff8d037761 RDI: ffffffff8b620900
RBP: 0000000000000000 R08: ffffffff8f1d3937 R09: 1ffffffff1e3a726
R10: dffffc0000000000 R11: fffffbfff1e3a727 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
FS: 00007f5ae263e6c0(0000) GS:ffff8881269c5000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffff8d037761 CR3: 0000000029406000 CR4: 00000000003526f0
----------------
Code disassembly (best guess):
0: 21 8d e8 2e 32 0a and %ecx,0xa322ee8(%rbp)
6: ff 90 0f 0b cc cc call *-0x3333f4f1(%rax)
c: cc int3
d: cc int3
e: cc int3
f: cc int3
10: cc int3
11: cc int3
12: cc int3
13: cc int3
14: cc int3
15: 90 nop
16: 90 nop
17: 90 nop
18: 90 nop
19: 90 nop
1a: 90 nop
1b: 90 nop
1c: 90 nop
1d: 90 nop
1e: 90 nop
1f: 90 nop
20: 90 nop
21: 90 nop
22: 90 nop
23: 90 nop
24: 90 nop
25: 66 0f 1f 00 nopw (%rax)
29: 55 push %rbp
* 2a: 41 57 push %r15 <-- trapping instruction
2c: 41 56 push %r14
2e: 41 55 push %r13
30: 41 54 push %r12
32: 53 push %rbx
33: b0 01 mov $0x1,%al
35: 48 85 f6 test %rsi,%rsi
38: 0f 84 ba 01 00 00 je 0x1f8
3e: 4c rex.WR
3f: 8d .byte 0x8d


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Nov 9, 2025, 2:38:20 AM11/9/25
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages