[syzbot] [sctp?] KMSAN: uninit-value in __sctp_v6_cmp_addr (2)

syzbot <[email protected]>
Newsgroups org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    69fd6b99b8f8 Merge tag 'perf_urgent_for_v6.17_rc3' of git:..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=10adec42580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=6ccfdce02093e91f
dashboard link: https://syzkaller.appspot.com/bug?extid=e69f06a0f30116c68056
compiler:       Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=130d8462580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=10bfb862580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/ce22f4296138/disk-69fd6b99.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/36a2af954ef6/vmlinux-69fd6b99.xz
kernel image: https://storage.googleapis.com/syzbot-assets/594a8181f23a/bzImage-69fd6b99.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

=====================================================
BUG: KMSAN: uninit-value in __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649
 __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649
 sctp_inet6_cmp_addr+0x4f2/0x510 net/sctp/ipv6.c:983
 sctp_bind_addr_conflict+0x22a/0x3b0 net/sctp/bind_addr.c:390
 sctp_get_port_local+0x21eb/0x2440 net/sctp/socket.c:8452
 sctp_get_port net/sctp/socket.c:8523 [inline]
 sctp_listen_start net/sctp/socket.c:8567 [inline]
 sctp_inet_listen+0x710/0xfd0 net/sctp/socket.c:8636
 __sys_listen_socket net/socket.c:1912 [inline]
 __sys_listen net/socket.c:1927 [inline]
 __do_sys_listen net/socket.c:1932 [inline]
 __se_sys_listen net/socket.c:1930 [inline]
 __x64_sys_listen+0x343/0x4c0 net/socket.c:1930
 x64_sys_call+0x271d/0x3e20 arch/x86/include/generated/asm/syscalls_64.h:51
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Local variable t.i created at:
 __do_sys_futex kernel/futex/syscalls.c:165 [inline]
 __se_sys_futex+0x4d/0x740 kernel/futex/syscalls.c:160
 __x64_sys_futex+0x114/0x1a0 kernel/futex/syscalls.c:160

CPU: 1 UID: 0 PID: 6089 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(none) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
=====================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.