[syzbot] [media?] general protection fault in usbtv_querycap

syzbot <[email protected]>
Newsgroups org.kernel.vger.linux-media,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    3eb40771c00a Merge tag 'soc-fixes-7.2-3' of git://git.kern..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=11b7ba79580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=2ca5f2f2c4197664
dashboard link: https://syzkaller.appspot.com/bug?extid=37a57a84893052ab6071
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=15009949580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000050-0x0000000000000057]
CPU: 1 UID: 0 PID: 5878 Comm: syz-executor121 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:usb_make_path include/linux/usb.h:985 [inline]
RIP: 0010:usbtv_querycap+0x9c/0x100 drivers/media/usb/usbtv/usbtv-video.c:612
Code: d9 f9 49 83 c6 08 4c 89 f0 48 c1 e8 03 42 80 3c 20 00 74 08 4c 89 f7 e8 42 3b d9 f9 4d 8b 36 4d 8d 7e 50 4c 89 f8 48 c1 e8 03 <42> 80 3c 20 00 74 08 4c 89 ff e8 25 3b d9 f9 48 83 c3 30 4d 8b 3f
RSP: 0018:ffffc90003757b10 EFLAGS: 00010206
RAX: 000000000000000a RBX: ffffc90003757d60 RCX: 0000000074627375
RDX: 0000000000000006 RSI: ffffffff8cd143a0 RDI: ffffc90003757d70
RBP: 1ffff920006eafb6 R08: 0000000000767462 R09: 1ffff920006eafae
R10: dffffc0000000000 R11: fffff520006eafaf R12: dffffc0000000000
R13: ffff888035e170d8 R14: 0000000000000000 R15: 0000000000000050
FS:  00007f7ef67fc6c0(0000) GS:ffff888125049000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055c7f8b42d51 CR3: 0000000071dc6000 CR4: 00000000003526f0
Call Trace:
 <TASK>
 v4l_querycap+0x236/0x470 drivers/media/v4l2-core/v4l2-ioctl.c:1106
 __video_do_ioctl+0x8af/0xc70 drivers/media/v4l2-core/v4l2-ioctl.c:3133
 video_usercopy+0x860/0x1430 drivers/media/v4l2-core/v4l2-ioctl.c:3475
 v4l2_ioctl+0x18d/0x1e0 drivers/media/v4l2-core/v4l2-dev.c:366
 vfs_ioctl fs/ioctl.c:51 [inline]
 __do_sys_ioctl fs/ioctl.c:597 [inline]
 __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:583
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f7efcf7300b
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1c 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007f7ef67fc120 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000080685600 RCX: 00007f7efcf7300b
RDX: 00007f7ef67fc190 RSI: 0000000080685600 RDI: 0000000000000006
RBP: 0000000000000021 R08: 0000000000000002 R09: 0000000000000000
R10: 00007f7efcfe37e0 R11: 0000000000000246 R12: ffffffffffffffd0
R13: 0000000000000000 R14: 00007ffc6b9d1890 R15: 00007ffc6b9d1978
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:usb_make_path include/linux/usb.h:985 [inline]
RIP: 0010:usbtv_querycap+0x9c/0x100 drivers/media/usb/usbtv/usbtv-video.c:612
Code: d9 f9 49 83 c6 08 4c 89 f0 48 c1 e8 03 42 80 3c 20 00 74 08 4c 89 f7 e8 42 3b d9 f9 4d 8b 36 4d 8d 7e 50 4c 89 f8 48 c1 e8 03 <42> 80 3c 20 00 74 08 4c 89 ff e8 25 3b d9 f9 48 83 c3 30 4d 8b 3f
RSP: 0018:ffffc90003757b10 EFLAGS: 00010206
RAX: 000000000000000a RBX: ffffc90003757d60 RCX: 0000000074627375
RDX: 0000000000000006 RSI: ffffffff8cd143a0 RDI: ffffc90003757d70
RBP: 1ffff920006eafb6 R08: 0000000000767462 R09: 1ffff920006eafae
R10: dffffc0000000000 R11: fffff520006eafaf R12: dffffc0000000000
R13: ffff888035e170d8 R14: 0000000000000000 R15: 0000000000000050
FS:  00007f7ef67fc6c0(0000) GS:ffff888125049000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055c7f8b42d51 CR3: 0000000071dc6000 CR4: 00000000003526f0
----------------
Code disassembly (best guess):
   0:	d9 f9                	fyl2xp1
   2:	49 83 c6 08          	add    $0x8,%r14
   6:	4c 89 f0             	mov    %r14,%rax
   9:	48 c1 e8 03          	shr    $0x3,%rax
   d:	42 80 3c 20 00       	cmpb   $0x0,(%rax,%r12,1)
  12:	74 08                	je     0x1c
  14:	4c 89 f7             	mov    %r14,%rdi
  17:	e8 42 3b d9 f9       	call   0xf9d93b5e
  1c:	4d 8b 36             	mov    (%r14),%r14
  1f:	4d 8d 7e 50          	lea    0x50(%r14),%r15
  23:	4c 89 f8             	mov    %r15,%rax
  26:	48 c1 e8 03          	shr    $0x3,%rax
* 2a:	42 80 3c 20 00       	cmpb   $0x0,(%rax,%r12,1) <-- trapping instruction
  2f:	74 08                	je     0x39
  31:	4c 89 ff             	mov    %r15,%rdi
  34:	e8 25 3b d9 f9       	call   0xf9d93b5e
  39:	48 83 c3 30          	add    $0x30,%rbx
  3d:	4d 8b 3f             	mov    (%r15),%r15


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.