From: syzbot <syzbot+dd0f06181ab66b93dc00@syzkaller.appspotmail.com>
To: dmantipov@yandex.ru, hverkuil@kernel.org,
linux-kernel@vger.kernel.org, linux-media@vger.kernel.org,
lvc-project@linuxtesting.org, m.szyprowski@samsung.com,
mchehab@kernel.org, syzkaller-bugs@googlegroups.com,
tfiga@chromium.org
Subject: Re: [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2)
Date: Sun, 30 Aug 2026 04:40:33 -0700 [thread overview]
Message-ID: <6a9416b1.a8e469d2.cbf3.5607.GAE@google.com> (raw)
In-Reply-To: <6a8725d5.4d75e56a.c9a88.0043.GAE@google.com>
syzbot has found a reproducer for the following issue on:
HEAD commit: 08dbfad3f504 Merge tag 'for-linus' of git://git.kernel.org..
git tree: upstream
console+strace: https://syzkaller.appspot.com/x/log.txt?x=11740349580000
kernel config: https://syzkaller.appspot.com/x/.config?x=19560cab9a915237
dashboard link: https://syzkaller.appspot.com/bug?extid=dd0f06181ab66b93dc00
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10c45d79580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10eeee25580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/5896a88f5701/disk-08dbfad3.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/af401a4b0127/vmlinux-08dbfad3.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c322757c580c/bzImage-08dbfad3.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dd0f06181ab66b93dc00@syzkaller.appspotmail.com
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 1 UID: 0 PID: 25 Comm: kworker/1:0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/05/2026
Workqueue: events request_module_async
RIP: 0010:__wake_up_common+0x9b/0x1f0 kernel/sched/wait.c:105
Code: 02 00 0f 85 5b 01 00 00 48 8b 5b 40 48 8d 43 e8 4c 39 fb 0f 84 b3 00 00 00 48 ba 00 00 00 00 00 fc ff df 48 89 d9 48 c1 e9 03 <80> 3c 11 00 0f 85 18 01 00 00 48 bd 00 00 00 00 00 fc ff df 4c 8b
RSP: 0018:ffffc900001f79a0 EFLAGS: 00010056
RAX: ffffffffffffffe8 RBX: 0000000000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000003 RDI: ffff8880298b5790
RBP: ffff8880298b5790 R08: 0000000000000000 R09: fffff5200003ef2b
R10: 0000000000000003 R11: 00000000000075fb R12: 0000000000000003
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880298b57d0
FS: 0000000000000000(0000) GS:ffff888123c61000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000557902ace698 CR3: 0000000034273000 CR4: 0000000000350ef0
Call Trace:
<TASK>
__wake_up_common_lock kernel/sched/wait.c:126 [inline]
__wake_up+0x31/0x60 kernel/sched/wait.c:147
__vb2_queue_cancel+0x348/0xe90 drivers/media/common/videobuf2/videobuf2-core.c:2244
vb2_core_queue_release+0x27/0x190 drivers/media/common/videobuf2/videobuf2-core.c:2677
vb2_queue_release drivers/media/common/videobuf2/videobuf2-v4l2.c:943 [inline]
vb2_video_unregister_device drivers/media/common/videobuf2/videobuf2-v4l2.c:1279 [inline]
vb2_video_unregister_device+0x152/0x2e0 drivers/media/common/videobuf2/videobuf2-v4l2.c:1254
em28xx_v4l2_init.cold+0xe1a/0x3a18 drivers/media/usb/em28xx/em28xx-video.c:3097
em28xx_init_extension+0x13a/0x200 drivers/media/usb/em28xx/em28xx-core.c:1248
request_module_async+0x1e/0x30 drivers/media/usb/em28xx/em28xx-cards.c:3685
process_one_work+0xac7/0x1b10 kernel/workqueue.c:3387
process_scheduled_works kernel/workqueue.c:3470 [inline]
worker_thread+0x5ef/0xe50 kernel/workqueue.c:3551
kthread+0x373/0x450 kernel/kthread.c:436
ret_from_fork+0x730/0xd60 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__wake_up_common+0x9b/0x1f0 kernel/sched/wait.c:105
Code: 02 00 0f 85 5b 01 00 00 48 8b 5b 40 48 8d 43 e8 4c 39 fb 0f 84 b3 00 00 00 48 ba 00 00 00 00 00 fc ff df 48 89 d9 48 c1 e9 03 <80> 3c 11 00 0f 85 18 01 00 00 48 bd 00 00 00 00 00 fc ff df 4c 8b
RSP: 0018:ffffc900001f79a0 EFLAGS: 00010056
RAX: ffffffffffffffe8 RBX: 0000000000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000003 RDI: ffff8880298b5790
RBP: ffff8880298b5790 R08: 0000000000000000 R09: fffff5200003ef2b
R10: 0000000000000003 R11: 00000000000075fb R12: 0000000000000003
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880298b57d0
FS: 0000000000000000(0000) GS:ffff888123c61000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000557902ace698 CR3: 0000000034273000 CR4: 0000000000350ef0
----------------
Code disassembly (best guess):
0: 02 00 add (%rax),%al
2: 0f 85 5b 01 00 00 jne 0x163
8: 48 8b 5b 40 mov 0x40(%rbx),%rbx
c: 48 8d 43 e8 lea -0x18(%rbx),%rax
10: 4c 39 fb cmp %r15,%rbx
13: 0f 84 b3 00 00 00 je 0xcc
19: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx
20: fc ff df
23: 48 89 d9 mov %rbx,%rcx
26: 48 c1 e9 03 shr $0x3,%rcx
* 2a: 80 3c 11 00 cmpb $0x0,(%rcx,%rdx,1) <-- trapping instruction
2e: 0f 85 18 01 00 00 jne 0x14c
34: 48 bd 00 00 00 00 00 movabs $0xdffffc0000000000,%rbp
3b: fc ff df
3e: 4c rex.WR
3f: 8b .byte 0x8b
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
next prev parent reply other threads:[~2026-08-30 11:40 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-20 16:05 syzbot
2026-08-25 10:05 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91 syzbot
2026-08-25 11:04 ` syzbot
2026-08-30 11:40 ` syzbot [this message]
[not found] <7f5e0678-0ca7-4682-9b53-3c0d9ad5db8a@yandex.ru>
2026-08-25 10:52 ` [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
[not found] <07d01650-bdd5-42f4-96c9-eb2d7f8cfbb2@yandex.ru>
2026-08-25 11:49 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a9416b1.a8e469d2.cbf3.5607.GAE@google.com \
--to=syzbot+dd0f06181ab66b93dc00@syzkaller.appspotmail.com \
--cc=dmantipov@yandex.ru \
--cc=hverkuil@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=lvc-project@linuxtesting.org \
--cc=m.szyprowski@samsung.com \
--cc=mchehab@kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
--cc=tfiga@chromium.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®