* [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
@ 2025-02-25 7:06 syzbot
2025-02-25 11:43 ` syzbot
` (4 more replies)
0 siblings, 5 replies; 9+ messages in thread
From: syzbot @ 2025-02-25 7:06 UTC (permalink / raw)
To: deller, dri-devel, linux-fbdev, linux-kernel, simona, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: d082ecbc71e9 Linux 6.14-rc4
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=100c97a4580000
kernel config: https://syzkaller.appspot.com/x/.config?x=b1635bf4c5557b92
dashboard link: https://syzkaller.appspot.com/bug?extid=0c815b25cdb3678e7083
compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/323a5d590eec/disk-d082ecbc.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f7c4b6e33fd9/vmlinux-d082ecbc.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c518bbd55334/bzImage-d082ecbc.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0c815b25cdb3678e7083@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: slab-out-of-bounds in scr_memcpyw include/linux/vt_buffer.h:38 [inline]
BUG: KASAN: slab-out-of-bounds in fbcon_prepare_logo+0xa15/0xc80 drivers/video/fbdev/core/fbcon.c:614
Read of size 256 at addr ffff888033e96f60 by task syz.0.317/7285
CPU: 1 UID: 0 PID: 7285 Comm: syz.0.317 Not tainted 6.14.0-rc4-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:408 [inline]
print_report+0xc3/0x670 mm/kasan/report.c:521
kasan_report+0xd9/0x110 mm/kasan/report.c:634
check_region_inline mm/kasan/generic.c:183 [inline]
kasan_check_range+0xef/0x1a0 mm/kasan/generic.c:189
__asan_memcpy+0x23/0x60 mm/kasan/shadow.c:105
scr_memcpyw include/linux/vt_buffer.h:38 [inline]
fbcon_prepare_logo+0xa15/0xc80 drivers/video/fbdev/core/fbcon.c:614
fbcon_init+0xd41/0x1890 drivers/video/fbdev/core/fbcon.c:1146
visual_init+0x31d/0x620 drivers/tty/vt/vt.c:1011
do_bind_con_driver.isra.0+0x57a/0xbf0 drivers/tty/vt/vt.c:3831
vt_bind drivers/tty/vt/vt.c:3987 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4059
dev_attr_store+0x55/0x80 drivers/base/core.c:2439
sysfs_kf_write+0x117/0x170 fs/sysfs/file.c:139
kernfs_fop_write_iter+0x33d/0x500 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:586 [inline]
vfs_write+0x5ae/0x1150 fs/read_write.c:679
ksys_write+0x12b/0x250 fs/read_write.c:731
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f44b6f8d169
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f44b7dc3038 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f44b71a5fa0 RCX: 00007f44b6f8d169
RDX: 0000000000000002 RSI: 0000000000000000 RDI: 0000000000000003
RBP: 00007f44b700e2a0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007f44b71a5fa0 R15: 00007ffee813d3a8
</TASK>
The buggy address belongs to the physical page:
page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888033e94340 pfn:0x33e94
head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000040 0000000000000000 dead000000000122 0000000000000000
raw: ffff888033e94340 0000000000000000 00000001ffffffff 0000000000000000
head: 00fff00000000040 0000000000000000 dead000000000122 0000000000000000
head: ffff888033e94340 0000000000000000 00000001ffffffff 0000000000000000
head: 00fff00000000002 ffffea0000cfa501 ffffffffffffffff 0000000000000000
head: 0000000000000004 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 2, migratetype Unmovable, gfp_mask 0x140dc0(GFP_USER|__GFP_COMP|__GFP_ZERO), pid 7285, tgid 7284 (syz.0.317), ts 193263994848, free_ts 193235941647
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x181/0x1b0 mm/page_alloc.c:1551
prep_new_page mm/page_alloc.c:1559 [inline]
get_page_from_freelist+0xfce/0x2f80 mm/page_alloc.c:3477
__alloc_frozen_pages_noprof+0x221/0x2470 mm/page_alloc.c:4739
__alloc_pages_noprof+0xb/0x1b0 mm/page_alloc.c:4773
__alloc_pages_node_noprof include/linux/gfp.h:265 [inline]
alloc_pages_node_noprof include/linux/gfp.h:292 [inline]
___kmalloc_large_node+0x84/0x1b0 mm/slub.c:4239
__kmalloc_large_node_noprof+0x1c/0x70 mm/slub.c:4266
__do_kmalloc_node mm/slub.c:4282 [inline]
__kmalloc_noprof.cold+0xc/0x61 mm/slub.c:4306
kmalloc_noprof include/linux/slab.h:905 [inline]
kzalloc_noprof include/linux/slab.h:1037 [inline]
vc_do_resize+0x1e3/0x10f0 drivers/tty/vt/vt.c:1174
vc_resize include/linux/vt_kern.h:49 [inline]
fbcon_init+0xd1d/0x1890 drivers/video/fbdev/core/fbcon.c:1143
visual_init+0x31d/0x620 drivers/tty/vt/vt.c:1011
do_bind_con_driver.isra.0+0x57a/0xbf0 drivers/tty/vt/vt.c:3831
vt_bind drivers/tty/vt/vt.c:3987 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4059
dev_attr_store+0x55/0x80 drivers/base/core.c:2439
sysfs_kf_write+0x117/0x170 fs/sysfs/file.c:139
kernfs_fop_write_iter+0x33d/0x500 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:586 [inline]
vfs_write+0x5ae/0x1150 fs/read_write.c:679
page last free pid 7285 tgid 7284 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
free_pages_prepare mm/page_alloc.c:1127 [inline]
free_frozen_pages+0x6db/0xfb0 mm/page_alloc.c:2660
__folio_put+0x32a/0x450 mm/swap.c:112
vc_do_resize+0xe31/0x10f0 drivers/tty/vt/vt.c:1194
vc_resize include/linux/vt_kern.h:49 [inline]
fbcon_startup+0x406/0xb70 drivers/video/fbdev/core/fbcon.c:997
do_bind_con_driver.isra.0+0x207/0xbf0 drivers/tty/vt/vt.c:3794
vt_bind drivers/tty/vt/vt.c:3987 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4059
dev_attr_store+0x55/0x80 drivers/base/core.c:2439
sysfs_kf_write+0x117/0x170 fs/sysfs/file.c:139
kernfs_fop_write_iter+0x33d/0x500 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:586 [inline]
vfs_write+0x5ae/0x1150 fs/read_write.c:679
ksys_write+0x12b/0x250 fs/read_write.c:731
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff888033e96f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
ffff888033e96f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>ffff888033e97000: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
^
ffff888033e97080: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
ffff888033e97100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
==================================================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
2025-02-25 7:06 [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo syzbot
@ 2025-02-25 11:43 ` syzbot
2025-07-30 20:34 ` syzbot
` (3 subsequent siblings)
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2025-02-25 11:43 UTC (permalink / raw)
To: deller, dri-devel, linux-fbdev, linux-kernel, simona, syzkaller-bugs
syzbot has found a reproducer for the following issue on:
HEAD commit: d082ecbc71e9 Linux 6.14-rc4
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=14f56db0580000
kernel config: https://syzkaller.appspot.com/x/.config?x=b1635bf4c5557b92
dashboard link: https://syzkaller.appspot.com/bug?extid=0c815b25cdb3678e7083
compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=172e77f8580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/323a5d590eec/disk-d082ecbc.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f7c4b6e33fd9/vmlinux-d082ecbc.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c518bbd55334/bzImage-d082ecbc.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0c815b25cdb3678e7083@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: slab-out-of-bounds in scr_memcpyw include/linux/vt_buffer.h:38 [inline]
BUG: KASAN: slab-out-of-bounds in fbcon_prepare_logo+0xa15/0xc80 drivers/video/fbdev/core/fbcon.c:614
Read of size 256 at addr ffff888032edef60 by task syz.2.2428/8600
CPU: 0 UID: 0 PID: 8600 Comm: syz.2.2428 Not tainted 6.14.0-rc4-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:408 [inline]
print_report+0xc3/0x670 mm/kasan/report.c:521
kasan_report+0xd9/0x110 mm/kasan/report.c:634
check_region_inline mm/kasan/generic.c:183 [inline]
kasan_check_range+0xef/0x1a0 mm/kasan/generic.c:189
__asan_memcpy+0x23/0x60 mm/kasan/shadow.c:105
scr_memcpyw include/linux/vt_buffer.h:38 [inline]
fbcon_prepare_logo+0xa15/0xc80 drivers/video/fbdev/core/fbcon.c:614
fbcon_init+0xd41/0x1890 drivers/video/fbdev/core/fbcon.c:1146
visual_init+0x31d/0x620 drivers/tty/vt/vt.c:1011
do_bind_con_driver.isra.0+0x57a/0xbf0 drivers/tty/vt/vt.c:3831
vt_bind drivers/tty/vt/vt.c:3987 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4059
dev_attr_store+0x55/0x80 drivers/base/core.c:2439
sysfs_kf_write+0x117/0x170 fs/sysfs/file.c:139
kernfs_fop_write_iter+0x33d/0x500 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:586 [inline]
vfs_write+0x5ae/0x1150 fs/read_write.c:679
ksys_write+0x12b/0x250 fs/read_write.c:731
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fb44418d169
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffe52f027e8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007fb4443a5fa0 RCX: 00007fb44418d169
RDX: 0000000000000002 RSI: 0000000000000000 RDI: 0000000000000003
RBP: 00007fb44420e2a0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fb4443a5fa0 R14: 00007fb4443a5fa0 R15: 0000000000000003
</TASK>
The buggy address belongs to the physical page:
page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x32edc
head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000040 0000000000000000 dead000000000122 0000000000000000
raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
head: 00fff00000000040 0000000000000000 dead000000000122 0000000000000000
head: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
head: 00fff00000000002 ffffea0000cbb701 ffffffffffffffff 0000000000000000
head: 0000000000000004 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 2, migratetype Unmovable, gfp_mask 0x140dc0(GFP_USER|__GFP_COMP|__GFP_ZERO), pid 8600, tgid 8600 (syz.2.2428), ts 463971995066, free_ts 463963903452
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x181/0x1b0 mm/page_alloc.c:1551
prep_new_page mm/page_alloc.c:1559 [inline]
get_page_from_freelist+0xfce/0x2f80 mm/page_alloc.c:3477
__alloc_frozen_pages_noprof+0x221/0x2470 mm/page_alloc.c:4739
__alloc_pages_noprof+0xb/0x1b0 mm/page_alloc.c:4773
__alloc_pages_node_noprof include/linux/gfp.h:265 [inline]
alloc_pages_node_noprof include/linux/gfp.h:292 [inline]
___kmalloc_large_node+0x84/0x1b0 mm/slub.c:4239
__kmalloc_large_node_noprof+0x1c/0x70 mm/slub.c:4266
__do_kmalloc_node mm/slub.c:4282 [inline]
__kmalloc_noprof.cold+0xc/0x61 mm/slub.c:4306
kmalloc_noprof include/linux/slab.h:905 [inline]
kzalloc_noprof include/linux/slab.h:1037 [inline]
vc_do_resize+0x1e3/0x10f0 drivers/tty/vt/vt.c:1174
vc_resize include/linux/vt_kern.h:49 [inline]
fbcon_init+0xd1d/0x1890 drivers/video/fbdev/core/fbcon.c:1143
visual_init+0x31d/0x620 drivers/tty/vt/vt.c:1011
do_bind_con_driver.isra.0+0x57a/0xbf0 drivers/tty/vt/vt.c:3831
vt_bind drivers/tty/vt/vt.c:3987 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4059
dev_attr_store+0x55/0x80 drivers/base/core.c:2439
sysfs_kf_write+0x117/0x170 fs/sysfs/file.c:139
kernfs_fop_write_iter+0x33d/0x500 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:586 [inline]
vfs_write+0x5ae/0x1150 fs/read_write.c:679
page last free pid 8600 tgid 8600 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
free_pages_prepare mm/page_alloc.c:1127 [inline]
free_frozen_pages+0x6db/0xfb0 mm/page_alloc.c:2660
__folio_put+0x32a/0x450 mm/swap.c:112
vc_do_resize+0xe31/0x10f0 drivers/tty/vt/vt.c:1194
vc_resize include/linux/vt_kern.h:49 [inline]
fbcon_startup+0x406/0xb70 drivers/video/fbdev/core/fbcon.c:997
do_bind_con_driver.isra.0+0x207/0xbf0 drivers/tty/vt/vt.c:3794
vt_bind drivers/tty/vt/vt.c:3987 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4059
dev_attr_store+0x55/0x80 drivers/base/core.c:2439
sysfs_kf_write+0x117/0x170 fs/sysfs/file.c:139
kernfs_fop_write_iter+0x33d/0x500 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:586 [inline]
vfs_write+0x5ae/0x1150 fs/read_write.c:679
ksys_write+0x12b/0x250 fs/read_write.c:731
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff888032edef00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
ffff888032edef80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>ffff888032edf000: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
^
ffff888032edf080: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
ffff888032edf100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
==================================================================
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
2025-02-25 7:06 [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo syzbot
2025-02-25 11:43 ` syzbot
@ 2025-07-30 20:34 ` syzbot
2025-08-03 22:24 ` Forwarded: " syzbot
` (2 subsequent siblings)
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2025-07-30 20:34 UTC (permalink / raw)
To: deller, dri-devel, linux-fbdev, linux-kernel, simona, syzkaller-bugs
syzbot has found a reproducer for the following issue on:
HEAD commit: 4b290aae788e Merge tag 'sysctl-6.17-rc1' of git://git.kern..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=10ff8834580000
kernel config: https://syzkaller.appspot.com/x/.config?x=eb654b6c0c63cccc
dashboard link: https://syzkaller.appspot.com/bug?extid=0c815b25cdb3678e7083
compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=134389bc580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17a82ca2580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/6d83c5020884/disk-4b290aae.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/91441dce0745/vmlinux-4b290aae.xz
kernel image: https://storage.googleapis.com/syzbot-assets/55d2e063b8a3/bzImage-4b290aae.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0c815b25cdb3678e7083@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: slab-out-of-bounds in scr_memcpyw include/linux/vt_buffer.h:38 [inline]
BUG: KASAN: slab-out-of-bounds in fbcon_prepare_logo+0xa03/0xc70 drivers/video/fbdev/core/fbcon.c:618
Read of size 256 at addr ffff8880331da860 by task syz.0.17/5996
CPU: 0 UID: 0 PID: 5996 Comm: syz.0.17 Not tainted 6.16.0-syzkaller-04405-g4b290aae788e #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xcd/0x630 mm/kasan/report.c:482
kasan_report+0xe0/0x110 mm/kasan/report.c:595
check_region_inline mm/kasan/generic.c:183 [inline]
kasan_check_range+0x100/0x1b0 mm/kasan/generic.c:189
__asan_memcpy+0x23/0x60 mm/kasan/shadow.c:105
scr_memcpyw include/linux/vt_buffer.h:38 [inline]
fbcon_prepare_logo+0xa03/0xc70 drivers/video/fbdev/core/fbcon.c:618
fbcon_init+0xd77/0x1900 drivers/video/fbdev/core/fbcon.c:1150
visual_init+0x31d/0x620 drivers/tty/vt/vt.c:1019
do_bind_con_driver.isra.0+0x57a/0xbf0 drivers/tty/vt/vt.c:3915
vt_bind drivers/tty/vt/vt.c:4071 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4143
dev_attr_store+0x55/0x80 drivers/base/core.c:2437
sysfs_kf_write+0xef/0x150 fs/sysfs/file.c:145
kernfs_fop_write_iter+0x354/0x510 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:593 [inline]
vfs_write+0x6c4/0x1150 fs/read_write.c:686
ksys_write+0x12a/0x250 fs/read_write.c:738
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x490 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f580578e9a9
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffce73cfbb8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f58059b5fa0 RCX: 00007f580578e9a9
RDX: 0000000000000081 RSI: 00002000000001c0 RDI: 0000000000000004
RBP: 00007f5805810d69 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f58059b5fa0 R14: 00007f58059b5fa0 R15: 0000000000000003
</TASK>
The buggy address belongs to the object at ffff8880331da000
which belongs to the cache kmalloc-2k of size 2048
The buggy address is located 96 bytes to the right of
allocated 2048-byte region [ffff8880331da000, ffff8880331da800)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x331d8
head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff)
page_type: f5(slab)
raw: 00fff00000000040 ffff88801b842000 dead000000000122 0000000000000000
raw: 0000000000000000 0000000080080008 00000000f5000000 0000000000000000
head: 00fff00000000040 ffff88801b842000 dead000000000122 0000000000000000
head: 0000000000000000 0000000080080008 00000000f5000000 0000000000000000
head: 00fff00000000003 ffffea0000cc7601 00000000ffffffff 00000000ffffffff
head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 3, migratetype Unmovable, gfp_mask 0x1d20c0(__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC|__GFP_HARDWALL), pid 5996, tgid 5996 (syz.0.17), ts 103546222970, free_ts 103072976762
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x1c0/0x230 mm/page_alloc.c:1704
prep_new_page mm/page_alloc.c:1712 [inline]
get_page_from_freelist+0x1321/0x3890 mm/page_alloc.c:3669
__alloc_frozen_pages_noprof+0x261/0x23f0 mm/page_alloc.c:4959
alloc_pages_mpol+0x1fb/0x550 mm/mempolicy.c:2419
alloc_slab_page mm/slub.c:2451 [inline]
allocate_slab mm/slub.c:2619 [inline]
new_slab+0x23b/0x330 mm/slub.c:2673
___slab_alloc+0xd9c/0x1940 mm/slub.c:3859
__slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3949
__slab_alloc_node mm/slub.c:4024 [inline]
slab_alloc_node mm/slub.c:4185 [inline]
__do_kmalloc_node mm/slub.c:4327 [inline]
__kmalloc_noprof+0x2f2/0x510 mm/slub.c:4340
kmalloc_noprof include/linux/slab.h:909 [inline]
kzalloc_noprof include/linux/slab.h:1039 [inline]
vc_do_resize+0x1de/0x10e0 drivers/tty/vt/vt.c:1182
vc_resize include/linux/vt_kern.h:49 [inline]
fbcon_startup+0x427/0xba0 drivers/video/fbdev/core/fbcon.c:1001
do_bind_con_driver.isra.0+0x20a/0xbf0 drivers/tty/vt/vt.c:3878
vt_bind drivers/tty/vt/vt.c:4071 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4143
dev_attr_store+0x55/0x80 drivers/base/core.c:2437
sysfs_kf_write+0xef/0x150 fs/sysfs/file.c:145
kernfs_fop_write_iter+0x354/0x510 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:593 [inline]
vfs_write+0x6c4/0x1150 fs/read_write.c:686
page last free pid 5947 tgid 5947 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
free_pages_prepare mm/page_alloc.c:1248 [inline]
__free_frozen_pages+0x7fe/0x1180 mm/page_alloc.c:2706
qlink_free mm/kasan/quarantine.c:163 [inline]
qlist_free_all+0x4d/0x120 mm/kasan/quarantine.c:179
kasan_quarantine_reduce+0x195/0x1e0 mm/kasan/quarantine.c:286
__kasan_slab_alloc+0x69/0x90 mm/kasan/common.c:329
kasan_slab_alloc include/linux/kasan.h:250 [inline]
slab_post_alloc_hook mm/slub.c:4148 [inline]
slab_alloc_node mm/slub.c:4197 [inline]
__do_kmalloc_node mm/slub.c:4327 [inline]
__kmalloc_noprof+0x1d4/0x510 mm/slub.c:4340
kmalloc_noprof include/linux/slab.h:909 [inline]
kzalloc_noprof include/linux/slab.h:1039 [inline]
fib6_info_alloc+0x40/0x160 net/ipv6/ip6_fib.c:155
ip6_route_info_create+0x14c/0x870 net/ipv6/route.c:3811
ip6_route_add.part.0+0x22/0x1d0 net/ipv6/route.c:3940
ip6_route_add+0x45/0x60 net/ipv6/route.c:3937
addrconf_prefix_route+0x2fd/0x510 net/ipv6/addrconf.c:2487
inet6_addr_add+0x589/0x960 net/ipv6/addrconf.c:3052
inet6_rtm_newaddr+0x1619/0x1c70 net/ipv6/addrconf.c:5058
rtnetlink_rcv_msg+0x95e/0xe90 net/core/rtnetlink.c:6944
netlink_rcv_skb+0x158/0x420 net/netlink/af_netlink.c:2552
netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
netlink_unicast+0x58a/0x850 net/netlink/af_netlink.c:1346
netlink_sendmsg+0x8d1/0xdd0 net/netlink/af_netlink.c:1896
Memory state around the buggy address:
ffff8880331da700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
ffff8880331da780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
>ffff8880331da800: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
^
ffff8880331da880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
ffff8880331da900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
==================================================================
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Forwarded: KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
2025-02-25 7:06 [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo syzbot
2025-02-25 11:43 ` syzbot
2025-07-30 20:34 ` syzbot
@ 2025-08-03 22:24 ` syzbot
2025-08-04 13:47 ` syzbot
2026-08-22 10:40 ` Forwarded: [PATCH] fbcon: Fix KASAN " syzbot
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2025-08-03 22:24 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
Author: sravankumarlpu@gmail.com
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
4b290aae788e06561754b28c6842e4080957d3f7
^ permalink raw reply [flat|nested] 9+ messages in thread
* Forwarded: KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
2025-02-25 7:06 [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo syzbot
` (2 preceding siblings ...)
2025-08-03 22:24 ` Forwarded: " syzbot
@ 2025-08-04 13:47 ` syzbot
2026-08-22 10:40 ` Forwarded: [PATCH] fbcon: Fix KASAN " syzbot
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2025-08-04 13:47 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
Author: sravankumarlpu@gmail.com
#syz test:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
4b290aae788e06561754b28c6842e4080957d3f7
^ permalink raw reply [flat|nested] 9+ messages in thread
* Forwarded: [PATCH] fbcon: Fix KASAN slab-out-of-bounds Read in fbcon_prepare_logo
2025-02-25 7:06 [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo syzbot
` (3 preceding siblings ...)
2025-08-04 13:47 ` syzbot
@ 2026-08-22 10:40 ` syzbot
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-08-22 10:40 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] fbcon: Fix KASAN slab-out-of-bounds Read in fbcon_prepare_logo
Author: deller@kernel.org
#syz test
Ensure the logo will not exceed the screen size, which then should
fix a reported KASAN: slab-out-of-bounds Read in fbcon_prepare_logo.
Reported-by: syzbot+0c815b25cdb3678e7083@syzkaller.appspotmail.com
Link: https://syzkaller.appspot.com/bug?extid=0c815b25cdb3678e7083
Signed-off-by: Helge Deller <deller@gmx.de>
diff --git a/drivers/video/fbdev/core/fbcon.c b/drivers/video/fbdev/core/fbcon.c
index 23b3c536d53d..01715873ea49 100644
--- a/drivers/video/fbdev/core/fbcon.c
+++ b/drivers/video/fbdev/core/fbcon.c
@@ -660,6 +660,13 @@ static void fbcon_prepare_logo(struct vc_data *vc, struct fb_info *info,
erase &= ~0x400;
logo_height = fb_prepare_logo(info, par->rotate);
logo_lines = DIV_ROUND_UP(logo_height, vc->vc_font.height);
+ logo_lines = min(logo_lines, rows);
+ logo_lines = min(logo_lines, new_rows - 1);
+ if (logo_lines <= 0) {
+ logo_lines = 0;
+ logo_shown = FBCON_LOGO_DONTSHOW;
+ return;
+ }
q = (unsigned short *) (vc->vc_origin +
vc->vc_size_row * rows);
step = logo_lines * cols;
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
[not found] <aol8iTdogX4i055n@carbonx1>
@ 2026-08-22 11:04 ` syzbot
0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-08-22 11:04 UTC (permalink / raw)
To: deller, deller, linux-kernel, syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
m: mask: 0xffffff max_cycles: 0xffffff, max_idle_ns: 2085701024 ns
[ 6.879936][ T1] NET: Registered PF_INET protocol family
[ 6.888856][ T1] IP idents hash table entries: 131072 (order: 8, 1048576 bytes, vmalloc)
[ 6.916004][ T1] tcp_listen_portaddr_hash hash table entries: 4096 (order: 7, 294912 bytes, vmalloc)
[ 6.927673][ T1] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, vmalloc)
[ 6.939720][ T1] TCP established hash table entries: 65536 (order: 7, 524288 bytes, vmalloc)
[ 6.963382][ T1] TCP bind hash table entries: 65536 (order: 12, 9437184 bytes, vmalloc hugepage)
[ 6.984847][ T1] TCP: Hash tables configured (established 65536 bind 65536)
[ 6.996181][ T1] MPTCP token hash table entries: 8192 (order: 8, 720896 bytes, vmalloc)
[ 7.007388][ T1] UDP hash table entries: 4096 (order: 8, 1048576 bytes, vmalloc)
[ 7.018480][ T1] NET: Registered PF_UNIX/PF_LOCAL protocol family
[ 7.033043][ T1] RPC: Registered named UNIX socket transport module.
[ 7.041029][ T1] RPC: Registered udp transport module.
[ 7.047194][ T1] RPC: Registered tcp transport module.
[ 7.053345][ T1] RPC: Registered tcp-with-tls transport module.
[ 7.061092][ T1] RPC: Registered tcp NFSv4.1 backchannel transport module.
[ 7.077293][ T1] NET: Registered PF_XDP protocol family
[ 7.084555][ T1] pci_bus 0000:00: resource 4 [io 0x0000-0x0cf7 window]
[ 7.093175][ T1] pci_bus 0000:00: resource 5 [io 0x0d00-0x0fff window]
[ 7.102036][ T1] pci_bus 0000:00: resource 6 [io 0xc000-0xffff window]
[ 7.109968][ T1] pci_bus 0000:00: resource 7 [io 0xa000-0xbfff window]
[ 7.117419][ T1] pci_bus 0000:00: resource 8 [mem 0x000a0000-0x000bffff window]
[ 7.126097][ T1] pci_bus 0000:00: resource 9 [mem 0xc0000000-0xfebfefff window]
[ 7.138760][ T1] pci 0000:00:00.0: Limiting direct PCI/PCI transfers
[ 7.148541][ T1] PCI: CLS 0 bytes, default 64
[ 7.155068][ T1] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
[ 7.163648][ T1] software IO TLB: mapped [mem 0x00000000b4400000-0x00000000b8400000] (64MB)
[ 7.179099][ T1] ACPI: bus type thunderbolt registered
[ 7.206819][ T59] kworker/u8:3 (59) used greatest stack depth: 28312 bytes left
[ 7.217723][ T60] kworker/u8:3 (60) used greatest stack depth: 27864 bytes left
[ 7.218365][ T1] RAPL PMU: API unit is 2^-32 Joules, 0 fixed counters, 10737418240 ms ovfl timer
[ 7.274157][ T1] kvm_amd: CPU 0 isn't AMD or Hygon
[ 7.281406][ T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
[ 7.295305][ T1] clocksource: Switched to clocksource tsc
[ 7.324198][ T67] kworker/u8:3 (67) used greatest stack depth: 27640 bytes left
[ 7.367239][ T1] Initialise system trusted keyrings
[ 7.379339][ T1] workingset: timestamp_bits=40 (anon: 35) max_order=21 bucket_order=0 (anon: 0)
[ 7.400907][ T1] DLM installed
[ 7.415403][ T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 7.436873][ T1] NFS: Registering the id_resolver key type
[ 7.445672][ T1] Key type id_resolver registered
[ 7.454593][ T1] Key type id_legacy registered
[ 7.461477][ T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[ 7.473026][ T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[ 7.498411][ T1] smbdirect: subsystem loading...
[ 7.521052][ T1] smbdirect: subsystem loaded
[ 7.549191][ T1] Key type cifs.spnego registered
[ 7.556231][ T1] Key type cifs.idmap registered
[ 7.570058][ T1] ntfs3: Enabled Linux POSIX ACLs support
[ 7.576365][ T1] ntfs3: Read-only LZX/Xpress compression included
[ 7.585189][ T1] jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
[ 7.597775][ T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[ 7.605637][ T1] QNX4 filesystem 0.2.3 registered.
[ 7.613980][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 7.625824][ T1] fuse: init (API version 7.45)
[ 7.639652][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 7.654508][ T1] orangefs_init: module version upstream loaded
[ 7.671168][ T1] JFS: nTxBlock = 8192, nTxLock = 65536
[ 7.707677][ T1] SGI XFS with ACLs, security attributes, realtime, quota, no debug enabled
[ 7.740342][ T1] 9p: Installing v9fs 9p2000 file system support
[ 7.750197][ T1] NILFS version 2 loaded
[ 7.762930][ T1] befs: version: 0.9.3
[ 7.775363][ T1] ocfs2: Registered cluster interface o2cb
[ 7.790702][ T1] ocfs2: Registered cluster interface user
[ 7.802858][ T1] OCFS2 User DLM kernel interface loaded
[ 7.858898][ T1] gfs2: GFS2 installed
[ 7.890449][ T1] ceph: loaded (mds proto 32)
[ 7.928515][ T1] cryptd: max_cpu_qlen set to 1000
[ 8.022954][ T1] NET: Registered PF_ALG protocol family
[ 8.034264][ T1] async_tx: api initialized (async)
[ 8.044395][ T1] Key type asymmetric registered
[ 8.053579][ T1] Asymmetric key parser 'x509' registered
[ 8.070465][ T1] Asymmetric key parser 'pkcs8' registered
[ 8.083813][ T1] Key type pkcs7_test registered
[ 8.094104][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 8.112958][ T1] io scheduler mq-deadline registered
[ 8.121114][ T1] io scheduler kyber registered
[ 8.130620][ T1] io scheduler bfq registered
[ 8.143874][ T134] kworker/u8:3 (134) used greatest stack depth: 27576 bytes left
[ 8.181566][ T150] kworker/u8:4 (150) used greatest stack depth: 27512 bytes left
[ 8.199268][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 8.222725][ T1] ACPI: button: Power Button [PWRF]
[ 8.246747][ T1] input: Sleep Button as /devices/platform/LNXSLPBN:00/input/input1
[ 8.272025][ T1] ACPI: button: Sleep Button [SLPF]
[ 8.312574][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 8.384985][ T10] ACPI: \_SB_.LNKC: Enabled at IRQ 11
[ 8.394668][ T10] virtio-pci 0000:00:03.0: virtio_pci: leaving for legacy driver
[ 8.466063][ T10] ACPI: \_SB_.LNKD: Enabled at IRQ 10
[ 8.473348][ T10] virtio-pci 0000:00:04.0: virtio_pci: leaving for legacy driver
[ 8.542587][ T10] ACPI: \_SB_.LNKB: Enabled at IRQ 10
[ 8.552444][ T10] virtio-pci 0000:00:06.0: virtio_pci: leaving for legacy driver
[ 8.611589][ T10] virtio-pci 0000:00:07.0: virtio_pci: leaving for legacy driver
[ 9.238437][ T488] kworker/u8:6 (488) used greatest stack depth: 26904 bytes left
[ 9.614789][ T1] N_HDLC line discipline registered with maxframe=4096
[ 9.626210][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 9.650014][ T1] 00:02: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 9.683528][ T1] 00:03: ttyS1 at I/O 0x2f8 (irq = 3, base_baud = 115200) is a 16550A
[ 9.717283][ T1] 00:04: ttyS2 at I/O 0x3e8 (irq = 6, base_baud = 115200) is a 16550A
[ 9.748101][ T1] 00:05: ttyS3 at I/O 0x2e8 (irq = 7, base_baud = 115200) is a 16550A
[ 9.803137][ T1] Non-volatile memory driver v1.3
[ 9.872050][ T1] usbcore: registered new interface driver xillyusb
[ 9.882756][ T1] ACPI: bus type drm_connector registered
[ 9.903775][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 9.918970][ T1] ------------[ cut here ]------------
[ 9.924668][ T1] [PLANE:35:plane-0] pixel format with alpha exposed but blend mode not setup
[ 9.924702][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:872 at drm_mode_config_validate+0xfb4/0x1be0, CPU#0: swapper/0/1
[ 9.950604][ T1] Modules linked in:
[ 9.956032][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 9.968456][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
[ 9.980319][ T1] RIP: 0010:drm_mode_config_validate+0xfbb/0x1be0
[ 9.987862][ T1] Code: 00 49 8b 57 18 48 89 f8 48 c1 e8 03 0f b6 04 28 84 c0 74 08 3c 03 0f 8e 00 0b 00 00 48 8d 3d fc 4e 2f 0b 41 8b b7 c8 00 00 00 <67> 48 0f b9 3a e9 fa fd ff ff 48 8b 5c 24 20 e8 41 e3 60 fc 48 8d
[ 10.011007][ T1] RSP: 0000:ffffc90000067c18 EFLAGS: 00010246
[ 10.017721][ T1] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[ 10.026974][ T1] RDX: ffff888025f58ea0 RSI: 0000000000000023 RDI: ffffffff90d71bb0
[ 10.035665][ T1] RBP: dffffc0000000000 R08: 0000000000000001 R09: 0000000000000000
[ 10.045086][ T1] R10: 0000000000000001 R11: 0000000000000000 R12: ffffed1004c93c23
[ 10.054115][ T1] R13: ffffed1004c93c24 R14: 0000000000000001 R15: ffff88802649e028
[ 10.062412][ T1] FS: 0000000000000000(0000) GS:ffff88812440a000(0000) knlGS:0000000000000000
[ 10.077158][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 10.084105][ T1] CR2: ffff88823ffff000 CR3: 000000000e586000 CR4: 00000000003526f0
[ 10.093478][ T1] Call Trace:
[ 10.097566][ T1] <TASK>
[ 10.101718][ T1] drm_dev_register+0x56e/0x7b0
[ 10.107158][ T1] vkms_create+0x491/0x5b0
[ 10.111916][ T1] ? __pfx_vkms_init+0x10/0x10
[ 10.117488][ T1] vkms_init+0x98/0xe0
[ 10.122162][ T1] do_one_initcall+0x11c/0x6f0
[ 10.127726][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 10.134615][ T1] ? kernel_init_freeable+0x4ca/0x7b0
[ 10.141204][ T1] kernel_init_freeable+0x6ea/0x7b0
[ 10.151156][ T1] ? __pfx_kernel_init+0x10/0x10
[ 10.162306][ T1] kernel_init+0x21/0x1e0
[ 10.168336][ T1] ? __pfx_kernel_init+0x10/0x10
[ 10.177012][ T1] ret_from_fork+0x730/0xd60
[ 10.182722][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 10.194824][ T1] ? __switch_to+0x800/0x10f0
[ 10.200466][ T1] ? __switch_to_asm+0x39/0x70
[ 10.206138][ T1] ? __pfx_kernel_init+0x10/0x10
[ 10.212710][ T1] ret_from_fork_asm+0x1a/0x30
[ 10.218506][ T1] </TASK>
[ 10.222298][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 10.228437][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 10.228437][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
[ 10.228437][ T1] Call Trace:
[ 10.228437][ T1] <TASK>
[ 10.228437][ T1] dump_stack_lvl+0x100/0x190
[ 10.228437][ T1] vpanic+0x553/0x970
[ 10.228437][ T1] ? __pfx_vpanic+0x10/0x10
[ 10.274204][ T1] panic+0xd1/0xe0
[ 10.274204][ T1] ? __pfx_panic+0x10/0x10
[ 10.274204][ T1] check_panic_on_warn.cold+0x19/0x34
[ 10.274204][ T1] ? drm_mode_config_validate+0xfb4/0x1be0
[ 10.274204][ T1] __warn.cold+0x191/0x318
[ 10.274204][ T1] __report_bug+0x30f/0x440
[ 10.274204][ T1] ? drm_mode_config_validate+0xfb4/0x1be0
[ 10.274204][ T1] ? __pfx___report_bug+0x10/0x10
[ 10.274204][ T1] ? __lock_acquire+0x4c5/0x1ec0
[ 10.274204][ T1] report_bug_entry+0xe2/0x290
[ 10.274204][ T1] ? drm_mode_config_validate+0xfbb/0x1be0
[ 10.274204][ T1] handle_bug+0x1cd/0x2a0
[ 10.274204][ T1] exc_invalid_op+0x17/0x50
[ 10.274204][ T1] asm_exc_invalid_op+0x1a/0x20
[ 10.274204][ T1] RIP: 0010:drm_mode_config_validate+0xfbb/0x1be0
[ 10.274204][ T1] Code: 00 49 8b 57 18 48 89 f8 48 c1 e8 03 0f b6 04 28 84 c0 74 08 3c 03 0f 8e 00 0b 00 00 48 8d 3d fc 4e 2f 0b 41 8b b7 c8 00 00 00 <67> 48 0f b9 3a e9 fa fd ff ff 48 8b 5c 24 20 e8 41 e3 60 fc 48 8d
[ 10.374312][ T1] RSP: 0000:ffffc90000067c18 EFLAGS: 00010246
[ 10.374312][ T1] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[ 10.374312][ T1] RDX: ffff888025f58ea0 RSI: 0000000000000023 RDI: ffffffff90d71bb0
[ 10.374312][ T1] RBP: dffffc0000000000 R08: 0000000000000001 R09: 0000000000000000
[ 10.374312][ T1] R10: 0000000000000001 R11: 0000000000000000 R12: ffffed1004c93c23
[ 10.374312][ T1] R13: ffffed1004c93c24 R14: 0000000000000001 R15: ffff88802649e028
[ 10.374312][ T1] ? drm_mode_config_validate+0xf76/0x1be0
[ 10.374312][ T1] drm_dev_register+0x56e/0x7b0
[ 10.374312][ T1] vkms_create+0x491/0x5b0
[ 10.374312][ T1] ? __pfx_vkms_init+0x10/0x10
[ 10.374312][ T1] vkms_init+0x98/0xe0
[ 10.374312][ T1] do_one_initcall+0x11c/0x6f0
[ 10.374312][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 10.474281][ T1] ? kernel_init_freeable+0x4ca/0x7b0
[ 10.474281][ T1] kernel_init_freeable+0x6ea/0x7b0
[ 10.474281][ T1] ? __pfx_kernel_init+0x10/0x10
[ 10.474281][ T1] kernel_init+0x21/0x1e0
[ 10.474281][ T1] ? __pfx_kernel_init+0x10/0x10
[ 10.474281][ T1] ret_from_fork+0x730/0xd60
[ 10.474281][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 10.474281][ T1] ? __switch_to+0x800/0x10f0
[ 10.474281][ T1] ? __switch_to_asm+0x39/0x70
[ 10.474281][ T1] ? __pfx_kernel_init+0x10/0x10
[ 10.474281][ T1] ret_from_fork_asm+0x1a/0x30
[ 10.474281][ T1] </TASK>
[ 10.474281][ T1] Kernel Offset: disabled
[ 10.474281][ T1] Rebooting in 86400 seconds..
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2227337947=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at f8f2b4da0e6
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=f8f2b4da0e6eaaf0aeed6f6d613d86d599aafcd3 -X github.com/google/syzkaller/prog.gitRevisionDate=20250729-133428" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"f8f2b4da0e6eaaf0aeed6f6d613d86d599aafcd3\"
/usr/bin/ld: /tmp/ccoS8z5G.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=12708625580000
Tested on:
commit: 26260251 Merge tag 'livepatching-for-7.3' of git://git..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=7e3366b2d3e49f2d
dashboard link: https://syzkaller.appspot.com/bug?extid=0c815b25cdb3678e7083
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch: https://syzkaller.appspot.com/x/patch.diff?x=10a8a179580000
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
[not found] <CAJuRXzCYr1t_hQ0t-B-OXVc-+Lg1f73PN5BMJEk-mzpB6FUpxA@mail.gmail.com>
@ 2025-08-04 14:02 ` syzbot
0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2025-08-04 14:02 UTC (permalink / raw)
To: linux-kernel, sravankumarlpu, syzkaller-bugs
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
==================================================================
BUG: KASAN: slab-out-of-bounds in scr_memcpyw include/linux/vt_buffer.h:38 [inline]
BUG: KASAN: slab-out-of-bounds in fbcon_prepare_logo+0xa03/0xc70 drivers/video/fbdev/core/fbcon.c:618
Read of size 256 at addr ffff888144ebb860 by task syz.0.17/6639
CPU: 0 UID: 0 PID: 6639 Comm: syz.0.17 Not tainted 6.16.0-syzkaller-04405-g4b290aae788e #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xcd/0x630 mm/kasan/report.c:482
kasan_report+0xe0/0x110 mm/kasan/report.c:595
check_region_inline mm/kasan/generic.c:183 [inline]
kasan_check_range+0x100/0x1b0 mm/kasan/generic.c:189
__asan_memcpy+0x23/0x60 mm/kasan/shadow.c:105
scr_memcpyw include/linux/vt_buffer.h:38 [inline]
fbcon_prepare_logo+0xa03/0xc70 drivers/video/fbdev/core/fbcon.c:618
fbcon_init+0xd77/0x1900 drivers/video/fbdev/core/fbcon.c:1150
visual_init+0x31d/0x620 drivers/tty/vt/vt.c:1019
do_bind_con_driver.isra.0+0x57a/0xbf0 drivers/tty/vt/vt.c:3915
vt_bind drivers/tty/vt/vt.c:4071 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4143
dev_attr_store+0x55/0x80 drivers/base/core.c:2437
sysfs_kf_write+0xef/0x150 fs/sysfs/file.c:145
kernfs_fop_write_iter+0x354/0x510 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:593 [inline]
vfs_write+0x6c4/0x1150 fs/read_write.c:686
ksys_write+0x12a/0x250 fs/read_write.c:738
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x490 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f36be18e9a9
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f36bef23038 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f36be3b5fa0 RCX: 00007f36be18e9a9
RDX: 0000000000000081 RSI: 00002000000001c0 RDI: 0000000000000004
RBP: 00007f36be210d69 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007f36be3b5fa0 R15: 00007ffe05ac9a98
</TASK>
Allocated by task 1100:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
poison_kmalloc_redzone mm/kasan/common.c:377 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:394
kasan_kmalloc include/linux/kasan.h:260 [inline]
__do_kmalloc_node mm/slub.c:4328 [inline]
__kmalloc_node_track_caller_noprof+0x221/0x510 mm/slub.c:4347
kmalloc_reserve+0xef/0x2c0 net/core/skbuff.c:601
__alloc_skb+0x166/0x380 net/core/skbuff.c:670
alloc_skb include/linux/skbuff.h:1336 [inline]
mld_newpack.isra.0+0x18e/0xa20 net/ipv6/mcast.c:1788
add_grhead+0x299/0x340 net/ipv6/mcast.c:1899
add_grec+0x112a/0x1680 net/ipv6/mcast.c:2037
mld_send_initial_cr.part.0+0xe2/0x260 net/ipv6/mcast.c:2282
mld_send_initial_cr include/linux/refcount.h:291 [inline]
ipv6_mc_dad_complete+0x22c/0x2b0 net/ipv6/mcast.c:2293
addrconf_dad_completed+0xd8a/0x10d0 net/ipv6/addrconf.c:4339
addrconf_dad_work+0x84d/0x14e0 net/ipv6/addrconf.c:4267
process_one_work+0x9cc/0x1b70 kernel/workqueue.c:3238
process_scheduled_works kernel/workqueue.c:3321 [inline]
worker_thread+0x6c8/0xf10 kernel/workqueue.c:3402
kthread+0x3c2/0x780 kernel/kthread.c:464
ret_from_fork+0x5d4/0x6f0 arch/x86/kernel/process.c:148
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
Freed by task 1100:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:576
poison_slab_object mm/kasan/common.c:247 [inline]
__kasan_slab_free+0x51/0x70 mm/kasan/common.c:264
kasan_slab_free include/linux/kasan.h:233 [inline]
slab_free_hook mm/slub.c:2381 [inline]
slab_free mm/slub.c:4643 [inline]
kfree+0x2b4/0x4d0 mm/slub.c:4842
skb_kfree_head net/core/skbuff.c:1048 [inline]
skb_free_head+0x114/0x210 net/core/skbuff.c:1060
skb_release_data+0x776/0x9c0 net/core/skbuff.c:1087
skb_release_all net/core/skbuff.c:1152 [inline]
__kfree_skb net/core/skbuff.c:1166 [inline]
sk_skb_reason_drop+0x129/0x1a0 net/core/skbuff.c:1204
kfree_skb_reason include/linux/skbuff.h:1275 [inline]
kfree_skb include/linux/skbuff.h:1284 [inline]
ip_tunnel_xmit+0x8e0/0x37b0 net/ipv4/ip_tunnel.c:869
__gre_xmit+0x8bb/0xc00 net/ipv4/ip_gre.c:488
gre_tap_xmit+0x3b3/0x630 net/ipv4/ip_gre.c:776
__netdev_start_xmit include/linux/netdevice.h:5215 [inline]
netdev_start_xmit include/linux/netdevice.h:5224 [inline]
xmit_one net/core/dev.c:3830 [inline]
dev_hard_start_xmit+0x97/0x740 net/core/dev.c:3846
sch_direct_xmit+0x1b2/0xcf0 net/sched/sch_generic.c:344
__dev_xmit_skb net/core/dev.c:4102 [inline]
__dev_queue_xmit+0x13c7/0x43e0 net/core/dev.c:4679
dev_queue_xmit include/linux/netdevice.h:3355 [inline]
neigh_hh_output include/net/neighbour.h:523 [inline]
neigh_output include/net/neighbour.h:537 [inline]
ip6_finish_output2+0xe98/0x2020 net/ipv6/ip6_output.c:141
__ip6_finish_output+0x3cd/0xff0 net/ipv6/ip6_output.c:215
ip6_finish_output net/ipv6/ip6_output.c:226 [inline]
NF_HOOK_COND include/linux/netfilter.h:306 [inline]
ip6_output+0x1f9/0x540 net/ipv6/ip6_output.c:247
dst_output include/net/dst.h:459 [inline]
NF_HOOK include/linux/netfilter.h:317 [inline]
NF_HOOK include/linux/netfilter.h:311 [inline]
mld_sendpack+0x9e9/0x1220 net/ipv6/mcast.c:1868
mld_send_initial_cr.part.0+0x1a1/0x260 net/ipv6/mcast.c:2285
mld_send_initial_cr include/linux/refcount.h:291 [inline]
ipv6_mc_dad_complete+0x22c/0x2b0 net/ipv6/mcast.c:2293
addrconf_dad_completed+0xd8a/0x10d0 net/ipv6/addrconf.c:4339
addrconf_dad_work+0x84d/0x14e0 net/ipv6/addrconf.c:4267
process_one_work+0x9cc/0x1b70 kernel/workqueue.c:3238
process_scheduled_works kernel/workqueue.c:3321 [inline]
worker_thread+0x6c8/0xf10 kernel/workqueue.c:3402
kthread+0x3c2/0x780 kernel/kthread.c:464
ret_from_fork+0x5d4/0x6f0 arch/x86/kernel/process.c:148
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
The buggy address belongs to the object at ffff888144ebb000
which belongs to the cache kmalloc-2k of size 2048
The buggy address is located 96 bytes to the right of
allocated 2048-byte region [ffff888144ebb000, ffff888144ebb800)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x144eb8
head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
anon flags: 0x57ff00000000040(head|node=1|zone=2|lastcpupid=0x7ff)
page_type: f5(slab)
raw: 057ff00000000040 ffff88801b842000 0000000000000000 dead000000000001
raw: 0000000000000000 0000000080080008 00000000f5000000 0000000000000000
head: 057ff00000000040 ffff88801b842000 0000000000000000 dead000000000001
head: 0000000000000000 0000000080080008 00000000f5000000 0000000000000000
head: 057ff00000000003 ffffea000513ae01 00000000ffffffff 00000000ffffffff
head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 3, migratetype Unmovable, gfp_mask 0xd20c0(__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 1, tgid 1 (swapper/0), ts 3818223817, free_ts 0
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x1c0/0x230 mm/page_alloc.c:1704
prep_new_page mm/page_alloc.c:1712 [inline]
get_page_from_freelist+0x1321/0x3890 mm/page_alloc.c:3669
__alloc_frozen_pages_noprof+0x261/0x23f0 mm/page_alloc.c:4959
alloc_pages_mpol+0x1fb/0x550 mm/mempolicy.c:2419
alloc_slab_page mm/slub.c:2451 [inline]
allocate_slab mm/slub.c:2619 [inline]
new_slab+0x23b/0x330 mm/slub.c:2673
___slab_alloc+0xd9c/0x1940 mm/slub.c:3859
__slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3949
__slab_alloc_node mm/slub.c:4024 [inline]
slab_alloc_node mm/slub.c:4185 [inline]
__kmalloc_cache_noprof+0xfb/0x3e0 mm/slub.c:4354
kmalloc_noprof include/linux/slab.h:905 [inline]
kzalloc_noprof include/linux/slab.h:1039 [inline]
acpi_ds_create_walk_state+0x78/0x250 drivers/acpi/acpica/dswstate.c:518
acpi_ps_execute_method+0x253/0xb30 drivers/acpi/acpica/psxface.c:134
acpi_ns_evaluate+0x76c/0xca0 drivers/acpi/acpica/nseval.c:205
acpi_ut_evaluate_object+0xda/0x4a0 drivers/acpi/acpica/uteval.c:60
acpi_ut_execute_STA+0x87/0x1a0 drivers/acpi/acpica/uteval.c:223
acpi_ns_get_device_callback+0x23c/0x500 drivers/acpi/acpica/nsxfeval.c:723
acpi_ns_walk_namespace+0x405/0x5b0 drivers/acpi/acpica/nswalk.c:233
acpi_get_devices+0x137/0x160 drivers/acpi/acpica/nsxfeval.c:805
page_owner free stack trace missing
Memory state around the buggy address:
ffff888144ebb700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
ffff888144ebb780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff888144ebb800: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
^
ffff888144ebb880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
ffff888144ebb900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
==================================================================
Tested on:
commit: 4b290aae Merge tag 'sysctl-6.17-rc1' of git://git.kern..
git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=10eb4042580000
kernel config: https://syzkaller.appspot.com/x/.config?x=eb654b6c0c63cccc
dashboard link: https://syzkaller.appspot.com/bug?extid=0c815b25cdb3678e7083
compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
Note: no patches were applied.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
[not found] <CAJuRXzBmd-mViNReK64CozvMeUfF2AWtdNiDAz=hL0-AcGD7fw@mail.gmail.com>
@ 2025-08-03 22:39 ` syzbot
0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2025-08-03 22:39 UTC (permalink / raw)
To: linux-kernel, sravankumarlpu, syzkaller-bugs
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
KASAN: slab-out-of-bounds Read in fbcon_prepare_logo
==================================================================
BUG: KASAN: slab-out-of-bounds in scr_memcpyw include/linux/vt_buffer.h:38 [inline]
BUG: KASAN: slab-out-of-bounds in fbcon_prepare_logo+0xa03/0xc70 drivers/video/fbdev/core/fbcon.c:618
Read of size 256 at addr ffff88802ad9b860 by task syz.0.17/6602
CPU: 0 UID: 0 PID: 6602 Comm: syz.0.17 Not tainted 6.16.0-syzkaller-04405-g4b290aae788e-dirty #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xcd/0x630 mm/kasan/report.c:482
kasan_report+0xe0/0x110 mm/kasan/report.c:595
check_region_inline mm/kasan/generic.c:183 [inline]
kasan_check_range+0x100/0x1b0 mm/kasan/generic.c:189
__asan_memcpy+0x23/0x60 mm/kasan/shadow.c:105
scr_memcpyw include/linux/vt_buffer.h:38 [inline]
fbcon_prepare_logo+0xa03/0xc70 drivers/video/fbdev/core/fbcon.c:618
fbcon_init+0x118d/0x1920 drivers/video/fbdev/core/fbcon.c:1150
visual_init+0x320/0x620 drivers/tty/vt/vt.c:1019
do_bind_con_driver.isra.0+0x57a/0xbf0 drivers/tty/vt/vt.c:3915
vt_bind drivers/tty/vt/vt.c:4071 [inline]
store_bind+0x61d/0x760 drivers/tty/vt/vt.c:4143
dev_attr_store+0x58/0x80 drivers/base/core.c:2437
sysfs_kf_write+0xef/0x150 fs/sysfs/file.c:145
kernfs_fop_write_iter+0x354/0x510 fs/kernfs/file.c:334
new_sync_write fs/read_write.c:593 [inline]
vfs_write+0x6c4/0x1150 fs/read_write.c:686
ksys_write+0x12a/0x250 fs/read_write.c:738
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x490 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f988878e9a9
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f9889579038 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f98889b5fa0 RCX: 00007f988878e9a9
RDX: 0000000000000081 RSI: 00002000000001c0 RDI: 0000000000000004
RBP: 00007f9888810d69 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007f98889b5fa0 R15: 00007ffc350333d8
</TASK>
Allocated by task 6325:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
poison_kmalloc_redzone mm/kasan/common.c:377 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:394
kasan_kmalloc include/linux/kasan.h:260 [inline]
__do_kmalloc_node mm/slub.c:4328 [inline]
__kmalloc_noprof+0x223/0x510 mm/slub.c:4340
kmalloc_noprof include/linux/slab.h:909 [inline]
sk_prot_alloc+0x1a8/0x2a0 net/core/sock.c:2247
sk_alloc+0x36/0xc20 net/core/sock.c:2303
__netlink_create+0x5e/0x2c0 net/netlink/af_netlink.c:628
__netlink_kernel_create+0xed/0x750 net/netlink/af_netlink.c:2020
netlink_kernel_create include/linux/netlink.h:62 [inline]
nl_fib_lookup_init net/ipv4/fib_frontend.c:1438 [inline]
fib_net_init net/ipv4/fib_frontend.c:1644 [inline]
fib_net_init+0x26d/0x3f0 net/ipv4/fib_frontend.c:1629
ops_init+0x1df/0x5f0 net/core/net_namespace.c:138
setup_net+0x1ff/0x510 net/core/net_namespace.c:442
copy_net_ns+0x2a6/0x5f0 net/core/net_namespace.c:574
create_new_namespaces+0x3ea/0xa90 kernel/nsproxy.c:110
unshare_nsproxy_namespaces+0xc0/0x1f0 kernel/nsproxy.c:218
ksys_unshare+0x45b/0xa40 kernel/fork.c:3124
__do_sys_unshare kernel/fork.c:3195 [inline]
__se_sys_unshare kernel/fork.c:3193 [inline]
__x64_sys_unshare+0x31/0x40 kernel/fork.c:3193
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x490 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 6332:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:576
poison_slab_object mm/kasan/common.c:247 [inline]
__kasan_slab_free+0x51/0x70 mm/kasan/common.c:264
kasan_slab_free include/linux/kasan.h:233 [inline]
slab_free_hook mm/slub.c:2381 [inline]
slab_free mm/slub.c:4643 [inline]
kfree+0x2b4/0x4d0 mm/slub.c:4842
sk_prot_free net/core/sock.c:2286 [inline]
__sk_destruct+0x740/0x980 net/core/sock.c:2381
sk_destruct+0xc2/0xf0 net/core/sock.c:2409
__sk_free+0xf4/0x3e0 net/core/sock.c:2420
sk_free+0x6a/0x90 net/core/sock.c:2431
deferred_put_nlk_sk+0xc9/0x110 net/netlink/af_netlink.c:716
rcu_do_batch kernel/rcu/tree.c:2576 [inline]
rcu_core+0x79c/0x14e0 kernel/rcu/tree.c:2832
handle_softirqs+0x219/0x8e0 kernel/softirq.c:579
__do_softirq kernel/softirq.c:613 [inline]
invoke_softirq kernel/softirq.c:453 [inline]
__irq_exit_rcu+0x109/0x170 kernel/softirq.c:680
irq_exit_rcu+0x9/0x30 kernel/softirq.c:696
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1050 [inline]
sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1050
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702
Last potentially related work creation:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_record_aux_stack+0xa7/0xc0 mm/kasan/generic.c:548
__call_rcu_common.constprop.0+0xa5/0xa10 kernel/rcu/tree.c:3094
netlink_release+0x12f4/0x2020 net/netlink/af_netlink.c:798
__sock_release net/socket.c:647 [inline]
sock_release+0x8e/0x1d0 net/socket.c:675
netlink_kernel_release+0x4e/0x60 net/netlink/af_netlink.c:2080
nl_fib_lookup_exit net/ipv4/fib_frontend.c:1447 [inline]
fib_net_exit+0x40/0x80 net/ipv4/fib_frontend.c:1668
ops_exit_list net/core/net_namespace.c:200 [inline]
ops_undo_list+0x2eb/0xab0 net/core/net_namespace.c:253
cleanup_net+0x408/0x890 net/core/net_namespace.c:686
process_one_work+0x9cc/0x1b70 kernel/workqueue.c:3238
process_scheduled_works kernel/workqueue.c:3321 [inline]
worker_thread+0x6c8/0xf10 kernel/workqueue.c:3402
kthread+0x3c2/0x780 kernel/kthread.c:464
ret_from_fork+0x5d4/0x6f0 arch/x86/kernel/process.c:148
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
The buggy address belongs to the object at ffff88802ad9b000
which belongs to the cache kmalloc-2k of size 2048
The buggy address is located 96 bytes to the right of
allocated 2048-byte region [ffff88802ad9b000, ffff88802ad9b800)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x2ad98
head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
anon flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff)
page_type: f5(slab)
raw: 00fff00000000040 ffff88801b842000 0000000000000000 dead000000000001
raw: 0000000000000000 0000000080080008 00000000f5000000 0000000000000000
head: 00fff00000000040 ffff88801b842000 0000000000000000 dead000000000001
head: 0000000000000000 0000000080080008 00000000f5000000 0000000000000000
head: 00fff00000000003 ffffea0000ab6601 00000000ffffffff 00000000ffffffff
head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 3, migratetype Unmovable, gfp_mask 0xd20c0(__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5925, tgid 5925 (syz-executor), ts 92458486289, free_ts 63680726622
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x1c0/0x230 mm/page_alloc.c:1704
prep_new_page mm/page_alloc.c:1712 [inline]
get_page_from_freelist+0x1321/0x3890 mm/page_alloc.c:3669
__alloc_frozen_pages_noprof+0x261/0x23f0 mm/page_alloc.c:4959
alloc_pages_mpol+0x1fb/0x550 mm/mempolicy.c:2419
alloc_slab_page mm/slub.c:2451 [inline]
allocate_slab mm/slub.c:2619 [inline]
new_slab+0x23b/0x330 mm/slub.c:2673
___slab_alloc+0xd9c/0x1940 mm/slub.c:3859
__slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3949
__slab_alloc_node mm/slub.c:4024 [inline]
slab_alloc_node mm/slub.c:4185 [inline]
__do_kmalloc_node mm/slub.c:4327 [inline]
__kmalloc_noprof+0x2f2/0x510 mm/slub.c:4340
kmalloc_noprof include/linux/slab.h:909 [inline]
kzalloc_noprof include/linux/slab.h:1039 [inline]
ops_init+0x77/0x5f0 net/core/net_namespace.c:128
setup_net+0x1ff/0x510 net/core/net_namespace.c:442
copy_net_ns+0x2a6/0x5f0 net/core/net_namespace.c:574
create_new_namespaces+0x3ea/0xa90 kernel/nsproxy.c:110
unshare_nsproxy_namespaces+0xc0/0x1f0 kernel/nsproxy.c:218
ksys_unshare+0x45b/0xa40 kernel/fork.c:3124
__do_sys_unshare kernel/fork.c:3195 [inline]
__se_sys_unshare kernel/fork.c:3193 [inline]
__x64_sys_unshare+0x31/0x40 kernel/fork.c:3193
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x490 arch/x86/entry/syscall_64.c:94
page last free pid 5666 tgid 5666 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
free_pages_prepare mm/page_alloc.c:1248 [inline]
__free_frozen_pages+0x7fe/0x1180 mm/page_alloc.c:2706
qlink_free mm/kasan/quarantine.c:163 [inline]
qlist_free_all+0x4d/0x120 mm/kasan/quarantine.c:179
kasan_quarantine_reduce+0x195/0x1e0 mm/kasan/quarantine.c:286
__kasan_slab_alloc+0x69/0x90 mm/kasan/common.c:329
kasan_slab_alloc include/linux/kasan.h:250 [inline]
slab_post_alloc_hook mm/slub.c:4148 [inline]
slab_alloc_node mm/slub.c:4197 [inline]
kmem_cache_alloc_noprof+0x1cb/0x3b0 mm/slub.c:4204
getname_flags.part.0+0x4c/0x550 fs/namei.c:146
getname_flags+0x93/0xf0 include/linux/audit.h:322
user_path_at+0x24/0x60 fs/namei.c:3126
do_faccessat+0x139/0xba0 fs/open.c:493
__do_sys_access fs/open.c:552 [inline]
__se_sys_access fs/open.c:550 [inline]
__x64_sys_access+0x5b/0x80 fs/open.c:550
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x490 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff88802ad9b700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
ffff88802ad9b780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff88802ad9b800: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
^
ffff88802ad9b880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
ffff88802ad9b900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
==================================================================
Tested on:
commit: 4b290aae Merge tag 'sysctl-6.17-rc1' of git://git.kern..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=120c8042580000
kernel config: https://syzkaller.appspot.com/x/.config?x=eb654b6c0c63cccc
dashboard link: https://syzkaller.appspot.com/bug?extid=0c815b25cdb3678e7083
compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=16548042580000
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-08-22 11:04 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-02-25 7:06 [syzbot] [fbdev?] KASAN: slab-out-of-bounds Read in fbcon_prepare_logo syzbot
2025-02-25 11:43 ` syzbot
2025-07-30 20:34 ` syzbot
2025-08-03 22:24 ` Forwarded: " syzbot
2025-08-04 13:47 ` syzbot
2026-08-22 10:40 ` Forwarded: [PATCH] fbcon: Fix KASAN " syzbot
[not found] <CAJuRXzBmd-mViNReK64CozvMeUfF2AWtdNiDAz=hL0-AcGD7fw@mail.gmail.com>
2025-08-03 22:39 ` [syzbot] [fbdev?] KASAN: " syzbot
[not found] <CAJuRXzCYr1t_hQ0t-B-OXVc-+Lg1f73PN5BMJEk-mzpB6FUpxA@mail.gmail.com>
2025-08-04 14:02 ` syzbot
[not found] <aol8iTdogX4i055n@carbonx1>
2026-08-22 11:04 ` syzbot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®