From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ot1-f71.google.com (mail-ot1-f71.google.com [209.85.210.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B9CC030FC3B for ; Fri, 23 Jan 2026 11:02:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.71 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769166124; cv=none; b=mq40/nmAtvc5bDcHOXoGrHDqMuEzvgp/ajOGdIVv2d5EmEUJrWIbdEWrA9QYxx5e9Q6ScO8inj6/okFK5uGSAV9hpt4JjufnNNL1oUlipb+meLNOn6H/bIrnJpes6yca1uvKLdOiKNVf/H525U6f092CPCLcygbmCuG/VxuRGkk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769166124; c=relaxed/simple; bh=aqpfybsco6CAtmwQS0xe3D7GmioVXch95R5lxWXzOOU=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=gc3xV8WDuH+5M9AfmoVe3jPv9thFHcUlR3Tv+JMI40blecY0Z+H2CindVLa+xFxokDbRAxiOLEirDIS95JKWtkA/i13MgRIt2GV35kxTU2rIG7Kp7fG1GwPFQHSm8y+XlOU7xXVk2NcqDQh6WPLN6nn0tuD036tgIJKtdlZZR4U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.210.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-ot1-f71.google.com with SMTP id 46e09a7af769-7cfd3cbaeedso4467116a34.1 for ; Fri, 23 Jan 2026 03:02:02 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769166121; x=1769770921; h=to:from:subject:message-id:in-reply-to:date:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=/cA9oCuwz3PlYCmuCF0cuJhIRnEiwyV/5yJPyBG9pDE=; b=n62IHvTigGQcLOybbXYA7MG6ILMAe68/4cGwZnbFh3lxqfrHh6hOyQhWq0H9PN7Wxm KkLg5btDLswGfJvMewfpkiPmnXkDWT4Ct9OeoZ7hTbdSZKxg443VkJdDUvCfypFF2kIe RSBAEFxjLPgNYO8724mSC7TwR9f+rPGEPiVSAtmJlmry+a76zQpdL/4LBrgweOfB4SeG HaxIPShQ3LWT2XurlOubbPwqsI1yk2B8ExFD6PG0Z4Vkup25bpVEvAh0XA8dYf4s8qIK TXUuGe1WErs/Pu7coW+Ci7LSjk0PpfW6cjX4HgmI7scOVKOO8/AUm3iUkyw8bjMecMms /h5w== X-Forwarded-Encrypted: i=1; AJvYcCUEDQZ3tEGqvO7eHjHeX6MFcculkr19HXrw8eisYGGutiO4L02jesKjajBclDf7eVArDZk15EluBuyzKz8=@vger.kernel.org X-Gm-Message-State: AOJu0YzTE06Vp/Aj6vTTd4HtZ1TBnZOWArL2+qpIzdVbxu9T76KyhFCV NgFzgWWrGgw5bC1LxCFxSt8FiirENARv9kZQxrnwtTaQeCYkE/xMcJawYki3vi8XWlo4CYpKHLp 8DTJWgchVBMWAr6eX7LVyG3P1MQRlPwDVoV+uJIXApJyXdiHrKxiEJVJ9qls= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:626:b0:65f:75e4:3478 with SMTP id 006d021491bc7-662cabb4983mr1301558eaf.76.1769166121665; Fri, 23 Jan 2026 03:02:01 -0800 (PST) Date: Fri, 23 Jan 2026 03:02:01 -0800 In-Reply-To: <20260123102623.2318-1-hdanton@sina.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <69735529.050a0220.1ad174.0339.GAE@google.com> Subject: Re: [syzbot] [bluetooth?] KASAN: slab-use-after-free Read in l2cap_sock_ready_cb (2) From: syzbot To: hdanton@sina.com, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: general protection fault in lock_sock_nested Oops: general protection fault, probably for non-canonical address 0xdffffc000000004c: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000260-0x0000000000000267] CPU: 1 UID: 0 PID: 6843 Comm: kworker/1:8 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/13/2026 Workqueue: events l2cap_info_timeout RIP: 0010:kasan_byte_accessible+0x15/0x30 mm/kasan/generic.c:210 Code: 00 00 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 40 d6 48 b8 00 00 00 00 00 fc ff df 48 c1 ef 03 48 01 c7 <0f> b6 07 3c 07 0f 96 c0 e9 ce 86 08 09 66 66 2e 0f 1f 84 00 00 00 RSP: 0018:ffffc90004717978 EFLAGS: 00010282 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffffffff89422bb1 RDI: dffffc000000004c RBP: 0000000000000260 R08: 0000000000000001 R09: 0000000000000000 R10: 00000000ffffff80 R11: 0000000000000000 R12: ffffffff89422bb1 R13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8881246dc000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f80dadab940 CR3: 000000007cc38000 CR4: 00000000003526f0 Call Trace: __kasan_check_byte+0x13/0x50 mm/kasan/common.c:573 kasan_check_byte include/linux/kasan.h:402 [inline] lock_acquire kernel/locking/lockdep.c:5842 [inline] lock_acquire+0xf5/0x330 kernel/locking/lockdep.c:5825 lock_sock_nested+0x41/0xf0 net/core/sock.c:3780 lock_sock include/net/sock.h:1700 [inline] l2cap_sock_ready_cb+0x43/0x1a0 net/bluetooth/l2cap_sock.c:1679 l2cap_chan_ready net/bluetooth/l2cap_core.c:1247 [inline] l2cap_conn_start+0x123/0xb20 net/bluetooth/l2cap_core.c:1513 l2cap_info_timeout+0x81/0xa0 net/bluetooth/l2cap_core.c:1670 process_one_work+0x9c2/0x1840 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x5da/0xe40 kernel/workqueue.c:3421 kthread+0x3b3/0x730 kernel/kthread.c:463 ret_from_fork+0x754/0xaf0 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:kasan_byte_accessible+0x15/0x30 mm/kasan/generic.c:210 Code: 00 00 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 40 d6 48 b8 00 00 00 00 00 fc ff df 48 c1 ef 03 48 01 c7 <0f> b6 07 3c 07 0f 96 c0 e9 ce 86 08 09 66 66 2e 0f 1f 84 00 00 00 RSP: 0018:ffffc90004717978 EFLAGS: 00010282 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffffffff89422bb1 RDI: dffffc000000004c RBP: 0000000000000260 R08: 0000000000000001 R09: 0000000000000000 R10: 00000000ffffff80 R11: 0000000000000000 R12: ffffffff89422bb1 R13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8881246dc000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f005ec17dac CR3: 0000000026311000 CR4: 00000000003526f0 ---------------- Code disassembly (best guess): 0: 00 00 add %al,(%rax) 2: 0f 1f 00 nopl (%rax) 5: 90 nop 6: 90 nop 7: 90 nop 8: 90 nop 9: 90 nop a: 90 nop b: 90 nop c: 90 nop d: 90 nop e: 90 nop f: 90 nop 10: 90 nop 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 0f 1f 40 d6 nopl -0x2a(%rax) 19: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax 20: fc ff df 23: 48 c1 ef 03 shr $0x3,%rdi 27: 48 01 c7 add %rax,%rdi * 2a: 0f b6 07 movzbl (%rdi),%eax <-- trapping instruction 2d: 3c 07 cmp $0x7,%al 2f: 0f 96 c0 setbe %al 32: e9 ce 86 08 09 jmp 0x9088705 37: 66 data16 38: 66 data16 39: 2e cs 3a: 0f .byte 0xf 3b: 1f (bad) 3c: 84 00 test %al,(%rax) Tested on: commit: c072629f Merge tag 'v6.19-p4' of git://git.kernel.org/.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=15b35f9a580000 kernel config: https://syzkaller.appspot.com/x/.config?x=f1fac0919970b671 dashboard link: https://syzkaller.appspot.com/bug?extid=9265e754091c2d27ea29 compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44 patch: https://syzkaller.appspot.com/x/patch.diff?x=10a38452580000