[syzbot] [sound?] BUG: unable to handle kernel NULL pointer dereference in snd_ctl_led_get

syzbot <[email protected]>
Newsgroups gmane.linux.kernel,gmane.linux.sound
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    818bebeb63dd drm/xe: Don't hand out the flat CCS storage a..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=12a3d579580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=ccca94d2c01b9e78
dashboard link: https://syzkaller.appspot.com/bug?extid=b7fe2760ea6f1ee44b4d
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=178bb415580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor instruction fetch in kernel mode
#PF: error_code(0x0010) - not-present page
PGD 0 P4D 0 
Oops: Oops: 0010 [#1] SMP KASAN NOPTI
CPU: 2 UID: 0 PID: 6042 Comm: syz-executor129 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:0x0
Code: Unable to access opcode bytes at 0xffffffffffffffd6.
RSP: 0018:ffffc900034b7948 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff88802e2ff400 RCX: 0000000000000000
RDX: 1ffff11005c5fe8c RSI: ffffffff9bda4620 RDI: ffff88802e2ff400
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: ffffffff9bda4620 R11: 0000000000000000 R12: 0000000000000000
R13: ffffffff90b73bc8 R14: ffff88802e2ff400 R15: ffffffff90b73bc8
FS:  000055555669f400(0000) GS:ffff8880d5da2000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffffffffffd6 CR3: 0000000027234000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 snd_ctl_led_get+0x231/0x430 sound/core/control_led.c:122
 snd_ctl_led_set_state+0x5c1/0x7f0 sound/core/control_led.c:168
 snd_ctl_led_notify+0x15b/0x1e0 sound/core/control_led.c:239
 snd_ctl_led_set_id sound/core/control_led.c:268 [inline]
 set_led_id+0xb0f/0xe80 sound/core/control_led.c:557
 dev_attr_store+0x58/0x80 drivers/base/core.c:2509
 sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
 kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x6af/0x1050 fs/read_write.c:687
 ksys_write+0x12a/0x250 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x123/0x790 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fa7e64de2b7
Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffe15525110 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 000055555669f400 RCX: 00007fa7e64de2b7
RDX: 0000000000000002 RSI: 00007ffe155251a0 RDI: 0000000000000004
RBP: 0000000000000004 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 00007ffe155251a0
R13: 00007fa7e6517024 R14: 00007fa7e6541cc0 R15: 0000000000000002
 </TASK>
Modules linked in:
CR2: 0000000000000000
---[ end trace 0000000000000000 ]---
RIP: 0010:0x0
Code: Unable to access opcode bytes at 0xffffffffffffffd6.
RSP: 0018:ffffc900034b7948 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff88802e2ff400 RCX: 0000000000000000
RDX: 1ffff11005c5fe8c RSI: ffffffff9bda4620 RDI: ffff88802e2ff400
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: ffffffff9bda4620 R11: 0000000000000000 R12: 0000000000000000
R13: ffffffff90b73bc8 R14: ffff88802e2ff400 R15: ffffffff90b73bc8
FS:  000055555669f400(0000) GS:ffff8880d5da2000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffffffffffd6 CR3: 0000000027234000 CR4: 0000000000352ef0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.