Re: [syzbot] [kernel?] KASAN: slab-use-after-free Write in bus_for_each_drv

syzbot <[email protected]>
Newsgroups org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot tried to test the proposed patch but the build/boot failed:

-0x00000000b8600000] (64MB)
[   11.599912][    T1] ACPI: bus type thunderbolt registered
[   11.742383][    T1] RAPL PMU: API unit is 2^-32 Joules, 0 fixed counters, 10737418240 ms ovfl timer
[   11.808342][   T70] kworker/u8:3 (70) used greatest stack depth: 28424 bytes left
[   11.808482][   T71] kworker/u8:5 (71) used greatest stack depth: 27728 bytes left
[   11.908721][    T1] kvm_amd: CPU 1 isn't AMD or Hygon
[   11.908764][    T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
[   11.909880][    T1] clocksource: Switched to clocksource tsc
[   11.959472][   T73] kworker/u8:5 (73) used greatest stack depth: 27312 bytes left
[   12.004111][   T75] kworker/u8:5 (75) used greatest stack depth: 26680 bytes left
[   12.171591][    T1] Initialise system trusted keyrings
[   12.188484][    T1] workingset: timestamp_bits=40 (anon: 35) max_order=21 bucket_order=0 (anon: 0)
[   12.232071][    T1] DLM installed
[   12.270720][    T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[   12.310924][    T1] NFS: Registering the id_resolver key type
[   12.311151][    T1] Key type id_resolver registered
[   12.311167][    T1] Key type id_legacy registered
[   12.311698][    T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[   12.311932][    T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[   12.349827][    T1] smbdirect: subsystem loading...
[   12.473464][    T1] smbdirect: subsystem loaded
[   12.556036][    T1] Key type cifs.spnego registered
[   12.557192][    T1] Key type cifs.idmap registered
[   12.612279][    T1] ntfs3: Enabled Linux POSIX ACLs support
[   12.612296][    T1] ntfs3: Read-only LZX/Xpress compression included
[   12.613918][    T1] jffs2: version 2.2. (NAND) (SUMMARY)  © 2001-2006 Red Hat, Inc.
[   12.707150][    T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[   12.710929][    T1] QNX4 filesystem 0.2.3 registered.
[   12.728727][    T1] qnx6: QNX6 filesystem 1.0.0 registered.
[   12.777345][    T1] fuse: init (API version 7.45)
[   12.813692][    T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[   12.827109][    T1] orangefs_init: module version upstream loaded
[   12.832698][    T1] JFS: nTxBlock = 8192, nTxLock = 65536
[   12.902685][    T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[   12.939665][    T1] 9p: Installing v9fs 9p2000 file system support
[   12.942832][    T1] NILFS version 2 loaded
[   12.942854][    T1] befs: version: 0.9.3
[   12.946918][    T1] ocfs2: Registered cluster interface o2cb
[   12.958238][    T1] ocfs2: Registered cluster interface user
[   12.979796][    T1] OCFS2 User DLM kernel interface loaded
[   13.137006][    T1] gfs2: GFS2 installed
[   13.186192][    T1] ceph: loaded (mds proto 32)
[   13.239816][    T1] NET: Registered PF_ALG protocol family
[   13.241279][    T1] async_tx: api initialized (async)
[   13.241362][    T1] Key type asymmetric registered
[   13.241613][    T1] Asymmetric key parser 'x509' registered
[   13.241642][    T1] Asymmetric key parser 'pkcs8' registered
[   13.241663][    T1] Key type pkcs7_test registered
[   13.244006][    T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[   13.247405][    T1] io scheduler mq-deadline registered
[   13.247428][    T1] io scheduler kyber registered
[   13.251382][    T1] io scheduler bfq registered
[   13.274291][    T1] raid6: skipped pq benchmark and selected avx2x4
[   13.482571][    T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[   13.514265][    T1] ACPI: button: Power Button [PWRF]
[   13.537302][    T1] input: Sleep Button as /devices/platform/LNXSLPBN:00/input/input1
[   13.568912][    T1] ACPI: button: Sleep Button [SLPF]
[   13.662280][    T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[   13.795622][   T10] ACPI: \_SB_.LNKC: Enabled at IRQ 11
[   13.796273][   T10] virtio-pci 0000:00:03.0: virtio_pci: leaving for legacy driver
[   13.911245][   T10] ACPI: \_SB_.LNKD: Enabled at IRQ 10
[   13.911473][   T10] virtio-pci 0000:00:04.0: virtio_pci: leaving for legacy driver
[   14.036923][   T10] ACPI: \_SB_.LNKB: Enabled at IRQ 10
[   14.037334][   T10] virtio-pci 0000:00:06.0: virtio_pci: leaving for legacy driver
[   14.134871][   T10] virtio-pci 0000:00:07.0: virtio_pci: leaving for legacy driver
[   14.455961][  T276] kworker/u8:3 (276) used greatest stack depth: 26536 bytes left
[   16.547826][    T1] N_HDLC line discipline registered with maxframe=4096
[   16.550769][    T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[   16.605843][    T1] 00:02: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[   16.671871][    T1] 00:03: ttyS1 at I/O 0x2f8 (irq = 3, base_baud = 115200) is a 16550A
[   16.730076][    T1] 00:04: ttyS2 at I/O 0x3e8 (irq = 6, base_baud = 115200) is a 16550A
[   16.805136][    T1] 00:05: ttyS3 at I/O 0x2e8 (irq = 7, base_baud = 115200) is a 16550A
[   16.949551][    T1] Non-volatile memory driver v1.3
[   17.132363][    T1] usbcore: registered new interface driver xillyusb
[   17.183391][    T1] ACPI: bus type drm_connector registered
[   17.243108][    T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[   17.314892][    T1] ------------[ cut here ]------------
[   17.314909][    T1] [PLANE:35:plane-0] pixel format with alpha exposed but blend mode not setup
[   17.314933][    T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6d/0x1e60, CPU#0: swapper/0/1
[   17.315009][    T1] Modules linked in:
[   17.315074][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)} 
[   17.315098][    T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
[   17.315123][    T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[   17.315929][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 5a d7 af fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 56 4a 44 fc 49 bd 00 00 00 00 00 fc ff df
[   17.315949][    T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[   17.315969][    T1] RAX: 1ffff11004bcd808 RBX: dffffc0000000000 RCX: ffff88801c6b5dc0
[   17.315986][    T1] RDX: ffff888025a56980 RSI: 0000000000000023 RDI: ffffffff8fbcf300
[   17.316002][    T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[   17.316015][    T1] R10: dffffc0000000000 R11: fffffbfff1f63828 R12: dffffc0000000000
[   17.316031][    T1] R13: ffffffff8fbcf300 R14: ffff888025e6c040 R15: ffff888025e6c030
[   17.316047][    T1] FS:  0000000000000000(0000) GS:ffff888125be6000(0000) knlGS:0000000000000000
[   17.316065][    T1] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   17.316079][    T1] CR2: ffff88823ffff000 CR3: 000000000dfb0000 CR4: 00000000003526f0
[   17.316098][    T1] Call Trace:
[   17.316108][    T1]  <TASK>
[   17.316128][    T1]  ? debugfs_create_file_full+0x3f/0x60
[   17.316273][    T1]  drm_dev_register+0x7f/0xd80
[   17.316310][    T1]  vkms_create+0x40d/0x4f0
[   17.316337][    T1]  ? __pfx_vkms_init+0x10/0x10
[   17.316373][    T1]  vkms_init+0x57/0x80
[   17.316402][    T1]  do_one_initcall+0x250/0x870
[   17.316445][    T1]  ? __pfx_vkms_init+0x10/0x10
[   17.316473][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   17.316511][    T1]  ? kvm_clock_get_cycles+0x49/0x60
[   17.316543][    T1]  ? __pfx___schedule+0x10/0x10
[   17.316576][    T1]  ? clockevents_program_event+0x491/0x630
[   17.316607][    T1]  ? __hrtimer_rearm_deferred+0x99/0x4d0
[   17.318440][    T1]  ? irqentry_exit+0x218/0x910
[   17.318510][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   17.318545][    T1]  ? irqentry_exit+0x218/0x910
[   17.318575][    T1]  ? trace_irq_disable+0x3b/0x140
[   17.318624][    T1]  ? next_arg+0x4a0/0x5e0
[   17.318660][    T1]  ? parameq+0x14d/0x170
[   17.318690][    T1]  ? parse_args+0x9c3/0xad0
[   17.318747][    T1]  ? rcu_is_watching+0x16/0xb0
[   17.318786][    T1]  do_initcall_level+0x10a/0x1a0
[   17.318830][    T1]  ? kernel_init+0x22/0x1d0
[   17.318867][    T1]  do_initcalls+0x59/0xa0
[   17.318908][    T1]  kernel_init_freeable+0x29d/0x3e0
[   17.318947][    T1]  ? __pfx_kernel_init+0x10/0x10
[   17.318987][    T1]  kernel_init+0x22/0x1d0
[   17.319029][    T1]  ? __pfx_kernel_init+0x10/0x10
[   17.319065][    T1]  ret_from_fork+0x514/0xb70
[   17.319106][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   17.321040][    T1]  ? __switch_to+0xc89/0x1420
[   17.321120][    T1]  ? __pfx_kernel_init+0x10/0x10
[   17.321163][    T1]  ret_from_fork_asm+0x1a/0x30
[   17.321202][    T1]  </TASK>
[   17.321228][    T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[   17.321250][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)} 
[   17.321274][    T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
[   17.321288][    T1] Call Trace:
[   17.321298][    T1]  <TASK>
[   17.321307][    T1]  vpanic+0x56d/0xa60
[   17.321329][    T1]  ? __pfx__printk+0x10/0x10
[   17.321354][    T1]  ? __pfx_vpanic+0x10/0x10
[   17.321372][    T1]  ? is_bpf_text_address+0x292/0x2b0
[   17.321401][    T1]  ? is_bpf_text_address+0x26/0x2b0
[   17.321437][    T1]  panic+0xc5/0xd0
[   17.321457][    T1]  ? __pfx_panic+0x10/0x10
[   17.321487][    T1]  ? ret_from_fork_asm+0x1a/0x30
[   17.321513][    T1]  __warn+0x315/0x4c0
[   17.321532][    T1]  ? drm_mode_config_validate+0x1c6d/0x1e60
[   17.321568][    T1]  ? drm_mode_config_validate+0x1c6d/0x1e60
[   17.321596][    T1]  __report_bug+0x276/0x570
[   17.321625][    T1]  ? drm_mode_config_validate+0x1c6d/0x1e60
[   17.321656][    T1]  ? __pfx___report_bug+0x10/0x10
[   17.322207][    T1]  ? _raw_spin_unlock_irqrestore+0x30/0x80
[   17.322248][    T1]  ? rt_mutex_slowunlock+0x4ee/0xa30
[   17.322275][    T1]  report_bug_entry+0x19b/0x290
[   17.322306][    T1]  ? drm_mode_config_validate+0x1cae/0x1e60
[   17.322338][    T1]  ? drm_mode_config_validate+0x1cb3/0x1e60
[   17.322982][    T1]  handle_bug+0xce/0x200
[   17.323038][    T1]  exc_invalid_op+0x1a/0x50
[   17.323075][    T1]  asm_exc_invalid_op+0x1a/0x20
[   17.323101][    T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[   17.323142][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 5a d7 af fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 56 4a 44 fc 49 bd 00 00 00 00 00 fc ff df
[   17.323163][    T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[   17.323186][    T1] RAX: 1ffff11004bcd808 RBX: dffffc0000000000 RCX: ffff88801c6b5dc0
[   17.323205][    T1] RDX: ffff888025a56980 RSI: 0000000000000023 RDI: ffffffff8fbcf300
[   17.323222][    T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[   17.323237][    T1] R10: dffffc0000000000 R11: fffffbfff1f63828 R12: dffffc0000000000
[   17.323388][    T1] R13: ffffffff8fbcf300 R14: ffff888025e6c040 R15: ffff888025e6c030
[   17.323437][    T1]  ? debugfs_create_file_full+0x3f/0x60
[   17.323476][    T1]  drm_dev_register+0x7f/0xd80
[   17.323517][    T1]  vkms_create+0x40d/0x4f0
[   17.323548][    T1]  ? __pfx_vkms_init+0x10/0x10
[   17.323582][    T1]  vkms_init+0x57/0x80
[   17.323617][    T1]  do_one_initcall+0x250/0x870
[   17.323655][    T1]  ? __pfx_vkms_init+0x10/0x10
[   17.323687][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   17.323731][    T1]  ? kvm_clock_get_cycles+0x49/0x60
[   17.324961][    T1]  ? __pfx___schedule+0x10/0x10
[   17.325015][    T1]  ? clockevents_program_event+0x491/0x630
[   17.325058][    T1]  ? __hrtimer_rearm_deferred+0x99/0x4d0
[   17.325107][    T1]  ? irqentry_exit+0x218/0x910
[   17.325950][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   17.325977][    T1]  ? irqentry_exit+0x218/0x910
[   17.325999][    T1]  ? trace_irq_disable+0x3b/0x140
[   17.326037][    T1]  ? next_arg+0x4a0/0x5e0
[   17.326399][    T1]  ? parameq+0x14d/0x170
[   17.326436][    T1]  ? parse_args+0x9c3/0xad0
[   17.326488][    T1]  ? rcu_is_watching+0x16/0xb0
[   17.326530][    T1]  do_initcall_level+0x10a/0x1a0
[   17.326576][    T1]  ? kernel_init+0x22/0x1d0
[   17.326615][    T1]  do_initcalls+0x59/0xa0
[   17.326656][    T1]  kernel_init_freeable+0x29d/0x3e0
[   17.326695][    T1]  ? __pfx_kernel_init+0x10/0x10
[   17.326972][    T1]  kernel_init+0x22/0x1d0
[   17.327019][    T1]  ? __pfx_kernel_init+0x10/0x10
[   17.327052][    T1]  ret_from_fork+0x514/0xb70
[   17.327090][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   17.327123][    T1]  ? __switch_to+0xc89/0x1420
[   17.327166][    T1]  ? __pfx_kernel_init+0x10/0x10
[   17.327206][    T1]  ret_from_fork_asm+0x1a/0x30
[   17.327246][    T1]  </TASK>
[   17.327972][    T1] Kernel Offset: disabled


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build3418809368=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs-2/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at d4abbeacd53
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d4abbeacd53add822a563e66a8ca9e64929b96ab -X github.com/google/syzkaller/prog.gitRevisionDate=20260804-103143"  ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d4abbeacd53add822a563e66a8ca9e64929b96ab -X github.com/google/syzkaller/prog.gitRevisionDate=20260804-103143"  ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d4abbeacd53add822a563e66a8ca9e64929b96ab -X github.com/google/syzkaller/prog.gitRevisionDate=20260804-103143"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"d4abbeacd53add822a563e66a8ca9e64929b96ab\"
/usr/bin/ld: /tmp/ccSFcTDt.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=12f43549580000


Tested on:

commit:         4352b8ae Merge tag 'i3c/for-7.3' of git://git.kernel.o..
git tree:       upstream
kernel config:  https://syzkaller.appspot.com/x/.config?x=c01bf1b5895f71b2
dashboard link: https://syzkaller.appspot.com/bug?extid=9cb1ac7fce4944ba9165
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch:          https://syzkaller.appspot.com/x/patch.diff?x=10c13179580000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.