* [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2)
@ 2026-08-20 16:05 syzbot
2026-08-25 10:05 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91 syzbot
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: syzbot @ 2026-08-20 16:05 UTC (permalink / raw)
To: linux-kernel, linux-media, m.szyprowski, mchehab, syzkaller-bugs, tfiga
Hello,
syzbot found the following issue on:
HEAD commit: f4cdf7ca9a1f Merge tag 'media/v7.3-1' of git://git.kernel...
git tree: upstream
console+strace: https://syzkaller.appspot.com/x/log.txt?x=10a10e79580000
kernel config: https://syzkaller.appspot.com/x/.config?x=e4b57019f58edf16
dashboard link: https://syzkaller.appspot.com/bug?extid=dd0f06181ab66b93dc00
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14a10e79580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/865d16295f11/disk-f4cdf7ca.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/71f476ad78fc/vmlinux-f4cdf7ca.xz
kernel image: https://storage.googleapis.com/syzbot-assets/e19d5dbdc9b7/bzImage-f4cdf7ca.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dd0f06181ab66b93dc00@syzkaller.appspotmail.com
ret_from_fork+0x730/0xd60 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 1 UID: 0 PID: 30 Comm: kworker/1:2 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/16/2026
Workqueue: events request_module_async
RIP: 0010:__wake_up_common+0x9b/0x1f0 kernel/sched/wait.c:104
Code: 02 00 0f 85 5b 01 00 00 48 8b 5b 40 48 8d 43 e8 4c 39 fb 0f 84 b3 00 00 00 48 ba 00 00 00 00 00 fc ff df 48 89 d9 48 c1 e9 03 <80> 3c 11 00 0f 85 18 01 00 00 48 bd 00 00 00 00 00 fc ff df 4c 8b
RSP: 0018:ffffc90000a679c0 EFLAGS: 00010056
RAX: ffffffffffffffe8 RBX: 0000000000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000003 RDI: ffff8880283e5790
RBP: ffff8880283e5790 R08: 0000000000000000 R09: fffff5200014cf2f
R10: 0000000000000003 R11: 00000000000075ab R12: 0000000000000003
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880283e57d0
FS: 0000000000000000(0000) GS:ffff888123ccc000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f764d56ae9c CR3: 000000002a6c6000 CR4: 0000000000350ef0
Call Trace:
<TASK>
__wake_up_common_lock kernel/sched/wait.c:125 [inline]
__wake_up+0x31/0x60 kernel/sched/wait.c:146
__vb2_queue_cancel+0x348/0xe90 drivers/media/common/videobuf2/videobuf2-core.c:2244
vb2_core_queue_release+0x27/0x190 drivers/media/common/videobuf2/videobuf2-core.c:2677
vb2_queue_release drivers/media/common/videobuf2/videobuf2-v4l2.c:943 [inline]
vb2_video_unregister_device drivers/media/common/videobuf2/videobuf2-v4l2.c:1279 [inline]
vb2_video_unregister_device+0x152/0x2e0 drivers/media/common/videobuf2/videobuf2-v4l2.c:1254
em28xx_v4l2_init.cold+0xe1a/0x3a18 drivers/media/usb/em28xx/em28xx-video.c:3097
em28xx_init_extension+0x13a/0x200 drivers/media/usb/em28xx/em28xx-core.c:1248
request_module_async+0x1e/0x30 drivers/media/usb/em28xx/em28xx-cards.c:3685
process_one_work+0xa23/0x1940 kernel/workqueue.c:3322
process_scheduled_works kernel/workqueue.c:3405 [inline]
worker_thread+0x5ef/0xe50 kernel/workqueue.c:3486
kthread+0x373/0x450 kernel/kthread.c:436
ret_from_fork+0x730/0xd60 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__wake_up_common+0x9b/0x1f0 kernel/sched/wait.c:104
Code: 02 00 0f 85 5b 01 00 00 48 8b 5b 40 48 8d 43 e8 4c 39 fb 0f 84 b3 00 00 00 48 ba 00 00 00 00 00 fc ff df 48 89 d9 48 c1 e9 03 <80> 3c 11 00 0f 85 18 01 00 00 48 bd 00 00 00 00 00 fc ff df 4c 8b
RSP: 0018:ffffc90000a679c0 EFLAGS: 00010056
RAX: ffffffffffffffe8 RBX: 0000000000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000003 RDI: ffff8880283e5790
RBP: ffff8880283e5790 R08: 0000000000000000 R09: fffff5200014cf2f
R10: 0000000000000003 R11: 00000000000075ab R12: 0000000000000003
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880283e57d0
FS: 0000000000000000(0000) GS:ffff888123ccc000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f764d56ae9c CR3: 000000002a6c6000 CR4: 0000000000350ef0
----------------
Code disassembly (best guess):
0: 02 00 add (%rax),%al
2: 0f 85 5b 01 00 00 jne 0x163
8: 48 8b 5b 40 mov 0x40(%rbx),%rbx
c: 48 8d 43 e8 lea -0x18(%rbx),%rax
10: 4c 39 fb cmp %r15,%rbx
13: 0f 84 b3 00 00 00 je 0xcc
19: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx
20: fc ff df
23: 48 89 d9 mov %rbx,%rcx
26: 48 c1 e9 03 shr $0x3,%rcx
* 2a: 80 3c 11 00 cmpb $0x0,(%rcx,%rdx,1) <-- trapping instruction
2e: 0f 85 18 01 00 00 jne 0x14c
34: 48 bd 00 00 00 00 00 movabs $0xdffffc0000000000,%rbp
3b: fc ff df
3e: 4c rex.WR
3f: 8b .byte 0x8b
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 6+ messages in thread* Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91
2026-08-20 16:05 [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
@ 2026-08-25 10:05 ` syzbot
2026-08-25 11:04 ` syzbot
2026-08-30 11:40 ` [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
2 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-08-25 10:05 UTC (permalink / raw)
To: linux-kernel, syzkaller-bugs
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91
Author: dmantipov@yandex.ru
#syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91
^ permalink raw reply [flat|nested] 6+ messages in thread
* Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91
2026-08-20 16:05 [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
2026-08-25 10:05 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91 syzbot
@ 2026-08-25 11:04 ` syzbot
2026-08-30 11:40 ` [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
2 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-08-25 11:04 UTC (permalink / raw)
To: linux-kernel, syzkaller-bugs
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91
Author: dmantipov@yandex.ru
#syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2)
2026-08-20 16:05 [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
2026-08-25 10:05 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91 syzbot
2026-08-25 11:04 ` syzbot
@ 2026-08-30 11:40 ` syzbot
2 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-08-30 11:40 UTC (permalink / raw)
To: dmantipov, hverkuil, linux-kernel, linux-media, lvc-project,
m.szyprowski, mchehab, syzkaller-bugs, tfiga
syzbot has found a reproducer for the following issue on:
HEAD commit: 08dbfad3f504 Merge tag 'for-linus' of git://git.kernel.org..
git tree: upstream
console+strace: https://syzkaller.appspot.com/x/log.txt?x=11740349580000
kernel config: https://syzkaller.appspot.com/x/.config?x=19560cab9a915237
dashboard link: https://syzkaller.appspot.com/bug?extid=dd0f06181ab66b93dc00
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10c45d79580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10eeee25580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/5896a88f5701/disk-08dbfad3.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/af401a4b0127/vmlinux-08dbfad3.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c322757c580c/bzImage-08dbfad3.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dd0f06181ab66b93dc00@syzkaller.appspotmail.com
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 1 UID: 0 PID: 25 Comm: kworker/1:0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/05/2026
Workqueue: events request_module_async
RIP: 0010:__wake_up_common+0x9b/0x1f0 kernel/sched/wait.c:105
Code: 02 00 0f 85 5b 01 00 00 48 8b 5b 40 48 8d 43 e8 4c 39 fb 0f 84 b3 00 00 00 48 ba 00 00 00 00 00 fc ff df 48 89 d9 48 c1 e9 03 <80> 3c 11 00 0f 85 18 01 00 00 48 bd 00 00 00 00 00 fc ff df 4c 8b
RSP: 0018:ffffc900001f79a0 EFLAGS: 00010056
RAX: ffffffffffffffe8 RBX: 0000000000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000003 RDI: ffff8880298b5790
RBP: ffff8880298b5790 R08: 0000000000000000 R09: fffff5200003ef2b
R10: 0000000000000003 R11: 00000000000075fb R12: 0000000000000003
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880298b57d0
FS: 0000000000000000(0000) GS:ffff888123c61000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000557902ace698 CR3: 0000000034273000 CR4: 0000000000350ef0
Call Trace:
<TASK>
__wake_up_common_lock kernel/sched/wait.c:126 [inline]
__wake_up+0x31/0x60 kernel/sched/wait.c:147
__vb2_queue_cancel+0x348/0xe90 drivers/media/common/videobuf2/videobuf2-core.c:2244
vb2_core_queue_release+0x27/0x190 drivers/media/common/videobuf2/videobuf2-core.c:2677
vb2_queue_release drivers/media/common/videobuf2/videobuf2-v4l2.c:943 [inline]
vb2_video_unregister_device drivers/media/common/videobuf2/videobuf2-v4l2.c:1279 [inline]
vb2_video_unregister_device+0x152/0x2e0 drivers/media/common/videobuf2/videobuf2-v4l2.c:1254
em28xx_v4l2_init.cold+0xe1a/0x3a18 drivers/media/usb/em28xx/em28xx-video.c:3097
em28xx_init_extension+0x13a/0x200 drivers/media/usb/em28xx/em28xx-core.c:1248
request_module_async+0x1e/0x30 drivers/media/usb/em28xx/em28xx-cards.c:3685
process_one_work+0xac7/0x1b10 kernel/workqueue.c:3387
process_scheduled_works kernel/workqueue.c:3470 [inline]
worker_thread+0x5ef/0xe50 kernel/workqueue.c:3551
kthread+0x373/0x450 kernel/kthread.c:436
ret_from_fork+0x730/0xd60 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__wake_up_common+0x9b/0x1f0 kernel/sched/wait.c:105
Code: 02 00 0f 85 5b 01 00 00 48 8b 5b 40 48 8d 43 e8 4c 39 fb 0f 84 b3 00 00 00 48 ba 00 00 00 00 00 fc ff df 48 89 d9 48 c1 e9 03 <80> 3c 11 00 0f 85 18 01 00 00 48 bd 00 00 00 00 00 fc ff df 4c 8b
RSP: 0018:ffffc900001f79a0 EFLAGS: 00010056
RAX: ffffffffffffffe8 RBX: 0000000000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000003 RDI: ffff8880298b5790
RBP: ffff8880298b5790 R08: 0000000000000000 R09: fffff5200003ef2b
R10: 0000000000000003 R11: 00000000000075fb R12: 0000000000000003
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880298b57d0
FS: 0000000000000000(0000) GS:ffff888123c61000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000557902ace698 CR3: 0000000034273000 CR4: 0000000000350ef0
----------------
Code disassembly (best guess):
0: 02 00 add (%rax),%al
2: 0f 85 5b 01 00 00 jne 0x163
8: 48 8b 5b 40 mov 0x40(%rbx),%rbx
c: 48 8d 43 e8 lea -0x18(%rbx),%rax
10: 4c 39 fb cmp %r15,%rbx
13: 0f 84 b3 00 00 00 je 0xcc
19: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx
20: fc ff df
23: 48 89 d9 mov %rbx,%rcx
26: 48 c1 e9 03 shr $0x3,%rcx
* 2a: 80 3c 11 00 cmpb $0x0,(%rcx,%rdx,1) <-- trapping instruction
2e: 0f 85 18 01 00 00 jne 0x14c
34: 48 bd 00 00 00 00 00 movabs $0xdffffc0000000000,%rbp
3b: fc ff df
3e: 4c rex.WR
3f: 8b .byte 0x8b
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 6+ messages in thread
[parent not found: <7f5e0678-0ca7-4682-9b53-3c0d9ad5db8a@yandex.ru>]
[parent not found: <07d01650-bdd5-42f4-96c9-eb2d7f8cfbb2@yandex.ru>]
end of thread, other threads:[~2026-08-30 11:40 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-20 16:05 [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
2026-08-25 10:05 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 66498c75b4f8017f62d720d9b59675bdf3abce91 syzbot
2026-08-25 11:04 ` syzbot
2026-08-30 11:40 ` [syzbot] [media?] KASAN: slab-use-after-free Read in __vb2_queue_cancel (2) syzbot
[not found] <7f5e0678-0ca7-4682-9b53-3c0d9ad5db8a@yandex.ru>
2026-08-25 10:52 ` syzbot
[not found] <07d01650-bdd5-42f4-96c9-eb2d7f8cfbb2@yandex.ru>
2026-08-25 11:49 ` syzbot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®