From mboxrd@z Thu Jan 1 00:00:00 1970 From: syzbot Date: Tue, 03 Dec 2019 22:25:08 +0000 Subject: KASAN: slab-out-of-bounds Read in fbcon_get_font Message-Id: <0000000000002cfc3a0598d42b70@google.com> List-Id: MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable To: b.zolnierkie@samsung.com, daniel.thompson@linaro.org, daniel.vetter@ffwll.ch, dri-devel@lists.freedesktop.org, ghalat@redhat.com, linux-fbdev@vger.kernel.org, linux-kernel@vger.kernel.org, maarten.lankhorst@linux.intel.com, sam@ravnborg.org, syzkaller-bugs@googlegroups.com Hello, syzbot found the following crash on: HEAD commit: 76bb8b05 Merge tag 'kbuild-v5.5' of git://git.kernel.org/p.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=10bfe282e00000 kernel config: https://syzkaller.appspot.com/x/.config?x=DD226651cb0f364b dashboard link: https://syzkaller.appspot.com/bug?extidD55ca3b3291de891abc compiler: gcc (GCC) 9.0.0 20181231 (experimental) syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11181edae00000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=105cbb7ae00000 IMPORTANT: if you fix the bug, please add the following tag to the commit: Reported-by: syzbot+4455ca3b3291de891abc@syzkaller.appspotmail.com =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D BUG: KASAN: slab-out-of-bounds in memcpy include/linux/string.h:380 [inline] BUG: KASAN: slab-out-of-bounds in fbcon_get_font+0x2b2/0x5e0 =20 drivers/video/fbdev/core/fbcon.c:2465 Read of size 16 at addr ffff888094b0aa10 by task syz-executor414/9999 CPU: 0 PID: 9999 Comm: syz-executor414 Not tainted 5.4.0-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS =20 Google 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:77 [inline] dump_stack+0x197/0x210 lib/dump_stack.c:118 print_address_description.constprop.0.cold+0xd4/0x30b mm/kasan/report.c:3= 74 __kasan_report.cold+0x1b/0x41 mm/kasan/report.c:506 kasan_report+0x12/0x20 mm/kasan/common.c:638 check_memory_region_inline mm/kasan/generic.c:185 [inline] check_memory_region+0x134/0x1a0 mm/kasan/generic.c:192 memcpy+0x24/0x50 mm/kasan/common.c:124 memcpy include/linux/string.h:380 [inline] fbcon_get_font+0x2b2/0x5e0 drivers/video/fbdev/core/fbcon.c:2465 con_font_get drivers/tty/vt/vt.c:4446 [inline] con_font_op+0x20b/0x1250 drivers/tty/vt/vt.c:4605 vt_ioctl+0x181a/0x26d0 drivers/tty/vt/vt_ioctl.c:965 tty_ioctl+0xa37/0x14f0 drivers/tty/tty_io.c:2658 vfs_ioctl fs/ioctl.c:47 [inline] file_ioctl fs/ioctl.c:545 [inline] do_vfs_ioctl+0x977/0x14e0 fs/ioctl.c:732 ksys_ioctl+0xab/0xd0 fs/ioctl.c:749 __do_sys_ioctl fs/ioctl.c:756 [inline] __se_sys_ioctl fs/ioctl.c:754 [inline] __x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:754 do_syscall_64+0xfa/0x790 arch/x86/entry/common.c:294 entry_SYSCALL_64_after_hwframe+0x49/0xbe RIP: 0033:0x4444d9 Code: 18 89 d0 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 48 89 f8 48 89 f7 = =20 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff = ff 0f 83 7b d8 fb ff c3 66 2e 0f 1f 84 00 00 00 00 RSP: 002b:00007fff6f4393b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007fff6f4393c0 RCX: 00000000004444d9 RDX: 0000000020000440 RSI: 0000000000004b72 RDI: 0000000000000005 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000400da0 R10: 00007fff6f438f00 R11: 0000000000000246 R12: 00000000004021e0 R13: 0000000000402270 R14: 0000000000000000 R15: 0000000000000000 Allocated by task 9999: save_stack+0x23/0x90 mm/kasan/common.c:71 set_track mm/kasan/common.c:79 [inline] __kasan_kmalloc mm/kasan/common.c:512 [inline] __kasan_kmalloc.constprop.0+0xcf/0xe0 mm/kasan/common.c:485 kasan_kmalloc+0x9/0x10 mm/kasan/common.c:526 __do_kmalloc mm/slab.c:3656 [inline] __kmalloc+0x163/0x770 mm/slab.c:3665 kmalloc include/linux/slab.h:561 [inline] fbcon_set_font+0x32d/0x860 drivers/video/fbdev/core/fbcon.c:2663 con_font_set drivers/tty/vt/vt.c:4538 [inline] con_font_op+0xe18/0x1250 drivers/tty/vt/vt.c:4603 vt_ioctl+0xd2e/0x26d0 drivers/tty/vt/vt_ioctl.c:913 tty_ioctl+0xa37/0x14f0 drivers/tty/tty_io.c:2658 vfs_ioctl fs/ioctl.c:47 [inline] file_ioctl fs/ioctl.c:545 [inline] do_vfs_ioctl+0x977/0x14e0 fs/ioctl.c:732 ksys_ioctl+0xab/0xd0 fs/ioctl.c:749 __do_sys_ioctl fs/ioctl.c:756 [inline] __se_sys_ioctl fs/ioctl.c:754 [inline] __x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:754 do_syscall_64+0xfa/0x790 arch/x86/entry/common.c:294 entry_SYSCALL_64_after_hwframe+0x49/0xbe Freed by task 9771: save_stack+0x23/0x90 mm/kasan/common.c:71 set_track mm/kasan/common.c:79 [inline] kasan_set_free_info mm/kasan/common.c:334 [inline] __kasan_slab_free+0x102/0x150 mm/kasan/common.c:473 kasan_slab_free+0xe/0x10 mm/kasan/common.c:482 __cache_free mm/slab.c:3426 [inline] kfree+0x10a/0x2c0 mm/slab.c:3757 tomoyo_init_log+0x15c1/0x2070 security/tomoyo/audit.c:294 tomoyo_supervisor+0x33f/0xef0 security/tomoyo/common.c:2095 tomoyo_audit_env_log security/tomoyo/environ.c:36 [inline] tomoyo_env_perm+0x18e/0x210 security/tomoyo/environ.c:63 tomoyo_environ security/tomoyo/domain.c:670 [inline] tomoyo_find_next_domain+0x1354/0x1f6c security/tomoyo/domain.c:876 tomoyo_bprm_check_security security/tomoyo/tomoyo.c:107 [inline] tomoyo_bprm_check_security+0x124/0x1a0 security/tomoyo/tomoyo.c:97 security_bprm_check+0x63/0xb0 security/security.c:784 search_binary_handler+0x71/0x570 fs/exec.c:1645 exec_binprm fs/exec.c:1701 [inline] __do_execve_file.isra.0+0x1329/0x22b0 fs/exec.c:1821 do_execveat_common fs/exec.c:1867 [inline] do_execve fs/exec.c:1884 [inline] __do_sys_execve fs/exec.c:1960 [inline] __se_sys_execve fs/exec.c:1955 [inline] __x64_sys_execve+0x8f/0xc0 fs/exec.c:1955 do_syscall_64+0xfa/0x790 arch/x86/entry/common.c:294 entry_SYSCALL_64_after_hwframe+0x49/0xbe The buggy address belongs to the object at ffff888094b0a000 which belongs to the cache kmalloc-4k of size 4096 The buggy address is located 2576 bytes inside of 4096-byte region [ffff888094b0a000, ffff888094b0b000) The buggy address belongs to the page: page:ffffea000252c280 refcount:1 mapcount:0 mapping:ffff8880aa402000 =20 index:0x0 compound_mapcount: 0 raw: 00fffe0000010200 ffffea0002a3ae08 ffffea0002a6aa88 ffff8880aa402000 raw: 0000000000000000 ffff888094b0a000 0000000100000001 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff888094b0a900: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff888094b0a980: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > ffff888094b0aa00: 00 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc ^ ffff888094b0aa80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff888094b0ab00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D --- This bug is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this bug report. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. syzbot can test patches for this bug, for details see: https://goo.gl/tpsmEJ#testing-patches From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.4 required=3.0 tests=FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 457DDC43603 for ; Wed, 4 Dec 2019 08:01:20 +0000 (UTC) Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 21EDF20409 for ; Wed, 4 Dec 2019 08:01:20 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 21EDF20409 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=dri-devel-bounces@lists.freedesktop.org Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 15FAA6F43A; Wed, 4 Dec 2019 08:01:17 +0000 (UTC) Received: from mail-io1-f69.google.com (mail-io1-f69.google.com [209.85.166.69]) by gabe.freedesktop.org (Postfix) with ESMTPS id 03B376F425 for ; Tue, 3 Dec 2019 22:25:09 +0000 (UTC) Received: by mail-io1-f69.google.com with SMTP id u13so3605516iol.6 for ; Tue, 03 Dec 2019 14:25:08 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:message-id:subject:from:to; bh=CXOkI0TBPtmTtJsgF6Sr0rjb/p028NpwaM4sLEBYlYQ=; b=brulO+GOquQn0AgeHLqvUCsj4ICeoaBxb2o+Zayyamgg1hA7bUc9sxa4pSUY3De6ST Sf4/Cqz2xmckLjNfwjn73bpLFCyfuqlUx8RuJwDcEGHPA1bIbSbrtGh1L4LeRQrIj5Mh pWpEzUtlqKq0JwJXnrd9dxjB0zSXGbLq9RZp9SeigVbfmMU6hBqJDaTk2fPia6iN9ADr +G6pILp2+dY0b2Xu0UgWX/Sg7jwAhVqHEISPKI2FMRVIKrnzGxvTsnRqaFenCWvSBa+l 8KIR3Ecu0ibKNnX9dMMH/Nhfr1ylo3KsnIS3BRKTpuJcSIS22toNgyut+TWE/dLiDtww Rfqw== X-Gm-Message-State: APjAAAXGLy1eYpL1EArG7EvB0ds3kkIQKzwqVe+wGfyIgRydG9m9aHwI xEQkL3rfuWjwdfAVBuatevLRJIF/JnAl2nJehKo/oX9rOdgo X-Google-Smtp-Source: APXvYqw0xQihGRub9pr2EXHoW6MqapjULktrGjdJ8k6mGFbVD7FZp6C3iVDmayNWFbuvk79pyYzHmOJ+M1o4qnItZXeuDkXdbxWn MIME-Version: 1.0 X-Received: by 2002:a05:6602:2541:: with SMTP id j1mr388622ioe.239.1575411908408; Tue, 03 Dec 2019 14:25:08 -0800 (PST) Date: Tue, 03 Dec 2019 14:25:08 -0800 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <0000000000002cfc3a0598d42b70@google.com> Subject: KASAN: slab-out-of-bounds Read in fbcon_get_font From: syzbot To: b.zolnierkie@samsung.com, daniel.thompson@linaro.org, daniel.vetter@ffwll.ch, dri-devel@lists.freedesktop.org, ghalat@redhat.com, linux-fbdev@vger.kernel.org, linux-kernel@vger.kernel.org, maarten.lankhorst@linux.intel.com, sam@ravnborg.org, syzkaller-bugs@googlegroups.com X-Mailman-Approved-At: Wed, 04 Dec 2019 08:01:16 +0000 X-BeenThere: dri-devel@lists.freedesktop.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Direct Rendering Infrastructure - Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Transfer-Encoding: base64 Content-Type: text/plain; charset="utf-8"; Format="flowed"; DelSp="yes" Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" SGVsbG8sCgpzeXpib3QgZm91bmQgdGhlIGZvbGxvd2luZyBjcmFzaCBvbjoKCkhFQUQgY29tbWl0 OiAgICA3NmJiOGIwNSBNZXJnZSB0YWcgJ2tidWlsZC12NS41JyBvZiBnaXQ6Ly9naXQua2VybmVs Lm9yZy9wLi4KZ2l0IHRyZWU6ICAgICAgIHVwc3RyZWFtCmNvbnNvbGUgb3V0cHV0OiBodHRwczov L3N5emthbGxlci5hcHBzcG90LmNvbS94L2xvZy50eHQ/eD0xMGJmZTI4MmUwMDAwMAprZXJuZWwg Y29uZmlnOiAgaHR0cHM6Ly9zeXprYWxsZXIuYXBwc3BvdC5jb20veC8uY29uZmlnP3g9ZGQyMjY2 NTFjYjBmMzY0YgpkYXNoYm9hcmQgbGluazogaHR0cHM6Ly9zeXprYWxsZXIuYXBwc3BvdC5jb20v YnVnP2V4dGlkPTQ0NTVjYTNiMzI5MWRlODkxYWJjCmNvbXBpbGVyOiAgICAgICBnY2MgKEdDQykg OS4wLjAgMjAxODEyMzEgKGV4cGVyaW1lbnRhbCkKc3l6IHJlcHJvOiAgICAgIGh0dHBzOi8vc3l6 a2FsbGVyLmFwcHNwb3QuY29tL3gvcmVwcm8uc3l6P3g9MTExODFlZGFlMDAwMDAKQyByZXByb2R1 Y2VyOiAgIGh0dHBzOi8vc3l6a2FsbGVyLmFwcHNwb3QuY29tL3gvcmVwcm8uYz94PTEwNWNiYjdh ZTAwMDAwCgpJTVBPUlRBTlQ6IGlmIHlvdSBmaXggdGhlIGJ1ZywgcGxlYXNlIGFkZCB0aGUgZm9s bG93aW5nIHRhZyB0byB0aGUgY29tbWl0OgpSZXBvcnRlZC1ieTogc3l6Ym90KzQ0NTVjYTNiMzI5 MWRlODkxYWJjQHN5emthbGxlci5hcHBzcG90bWFpbC5jb20KCj09PT09PT09PT09PT09PT09PT09 PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQpCVUc6IEtBU0FO OiBzbGFiLW91dC1vZi1ib3VuZHMgaW4gbWVtY3B5IGluY2x1ZGUvbGludXgvc3RyaW5nLmg6Mzgw IFtpbmxpbmVdCkJVRzogS0FTQU46IHNsYWItb3V0LW9mLWJvdW5kcyBpbiBmYmNvbl9nZXRfZm9u dCsweDJiMi8weDVlMCAgCmRyaXZlcnMvdmlkZW8vZmJkZXYvY29yZS9mYmNvbi5jOjI0NjUKUmVh ZCBvZiBzaXplIDE2IGF0IGFkZHIgZmZmZjg4ODA5NGIwYWExMCBieSB0YXNrIHN5ei1leGVjdXRv cjQxNC85OTk5CgpDUFU6IDAgUElEOiA5OTk5IENvbW06IHN5ei1leGVjdXRvcjQxNCBOb3QgdGFp bnRlZCA1LjQuMC1zeXprYWxsZXIgIzAKSGFyZHdhcmUgbmFtZTogR29vZ2xlIEdvb2dsZSBDb21w dXRlIEVuZ2luZS9Hb29nbGUgQ29tcHV0ZSBFbmdpbmUsIEJJT1MgIApHb29nbGUgMDEvMDEvMjAx MQpDYWxsIFRyYWNlOgogIF9fZHVtcF9zdGFjayBsaWIvZHVtcF9zdGFjay5jOjc3IFtpbmxpbmVd CiAgZHVtcF9zdGFjaysweDE5Ny8weDIxMCBsaWIvZHVtcF9zdGFjay5jOjExOAogIHByaW50X2Fk ZHJlc3NfZGVzY3JpcHRpb24uY29uc3Rwcm9wLjAuY29sZCsweGQ0LzB4MzBiIG1tL2thc2FuL3Jl cG9ydC5jOjM3NAogIF9fa2FzYW5fcmVwb3J0LmNvbGQrMHgxYi8weDQxIG1tL2thc2FuL3JlcG9y dC5jOjUwNgogIGthc2FuX3JlcG9ydCsweDEyLzB4MjAgbW0va2FzYW4vY29tbW9uLmM6NjM4CiAg Y2hlY2tfbWVtb3J5X3JlZ2lvbl9pbmxpbmUgbW0va2FzYW4vZ2VuZXJpYy5jOjE4NSBbaW5saW5l XQogIGNoZWNrX21lbW9yeV9yZWdpb24rMHgxMzQvMHgxYTAgbW0va2FzYW4vZ2VuZXJpYy5jOjE5 MgogIG1lbWNweSsweDI0LzB4NTAgbW0va2FzYW4vY29tbW9uLmM6MTI0CiAgbWVtY3B5IGluY2x1 ZGUvbGludXgvc3RyaW5nLmg6MzgwIFtpbmxpbmVdCiAgZmJjb25fZ2V0X2ZvbnQrMHgyYjIvMHg1 ZTAgZHJpdmVycy92aWRlby9mYmRldi9jb3JlL2ZiY29uLmM6MjQ2NQogIGNvbl9mb250X2dldCBk cml2ZXJzL3R0eS92dC92dC5jOjQ0NDYgW2lubGluZV0KICBjb25fZm9udF9vcCsweDIwYi8weDEy NTAgZHJpdmVycy90dHkvdnQvdnQuYzo0NjA1CiAgdnRfaW9jdGwrMHgxODFhLzB4MjZkMCBkcml2 ZXJzL3R0eS92dC92dF9pb2N0bC5jOjk2NQogIHR0eV9pb2N0bCsweGEzNy8weDE0ZjAgZHJpdmVy cy90dHkvdHR5X2lvLmM6MjY1OAogIHZmc19pb2N0bCBmcy9pb2N0bC5jOjQ3IFtpbmxpbmVdCiAg ZmlsZV9pb2N0bCBmcy9pb2N0bC5jOjU0NSBbaW5saW5lXQogIGRvX3Zmc19pb2N0bCsweDk3Ny8w eDE0ZTAgZnMvaW9jdGwuYzo3MzIKICBrc3lzX2lvY3RsKzB4YWIvMHhkMCBmcy9pb2N0bC5jOjc0 OQogIF9fZG9fc3lzX2lvY3RsIGZzL2lvY3RsLmM6NzU2IFtpbmxpbmVdCiAgX19zZV9zeXNfaW9j dGwgZnMvaW9jdGwuYzo3NTQgW2lubGluZV0KICBfX3g2NF9zeXNfaW9jdGwrMHg3My8weGIwIGZz L2lvY3RsLmM6NzU0CiAgZG9fc3lzY2FsbF82NCsweGZhLzB4NzkwIGFyY2gveDg2L2VudHJ5L2Nv bW1vbi5jOjI5NAogIGVudHJ5X1NZU0NBTExfNjRfYWZ0ZXJfaHdmcmFtZSsweDQ5LzB4YmUKUklQ OiAwMDMzOjB4NDQ0NGQ5CkNvZGU6IDE4IDg5IGQwIGMzIDY2IDJlIDBmIDFmIDg0IDAwIDAwIDAw IDAwIDAwIDBmIDFmIDAwIDQ4IDg5IGY4IDQ4IDg5IGY3ICAKNDggODkgZDYgNDggODkgY2EgNGQg ODkgYzIgNGQgODkgYzggNGMgOGIgNGMgMjQgMDggMGYgMDUgPDQ4PiAzZCAwMSBmMCBmZiAgCmZm IDBmIDgzIDdiIGQ4IGZiIGZmIGMzIDY2IDJlIDBmIDFmIDg0IDAwIDAwIDAwIDAwClJTUDogMDAy YjowMDAwN2ZmZjZmNDM5M2I4IEVGTEFHUzogMDAwMDAyNDYgT1JJR19SQVg6IDAwMDAwMDAwMDAw MDAwMTAKUkFYOiBmZmZmZmZmZmZmZmZmZmRhIFJCWDogMDAwMDdmZmY2ZjQzOTNjMCBSQ1g6IDAw MDAwMDAwMDA0NDQ0ZDkKUkRYOiAwMDAwMDAwMDIwMDAwNDQwIFJTSTogMDAwMDAwMDAwMDAwNGI3 MiBSREk6IDAwMDAwMDAwMDAwMDAwMDUKUkJQOiAwMDAwMDAwMDAwMDAwMDAwIFIwODogMDAwMDAw MDAwMDAwMDAwMCBSMDk6IDAwMDAwMDAwMDA0MDBkYTAKUjEwOiAwMDAwN2ZmZjZmNDM4ZjAwIFIx MTogMDAwMDAwMDAwMDAwMDI0NiBSMTI6IDAwMDAwMDAwMDA0MDIxZTAKUjEzOiAwMDAwMDAwMDAw NDAyMjcwIFIxNDogMDAwMDAwMDAwMDAwMDAwMCBSMTU6IDAwMDAwMDAwMDAwMDAwMDAKCkFsbG9j YXRlZCBieSB0YXNrIDk5OTk6CiAgc2F2ZV9zdGFjaysweDIzLzB4OTAgbW0va2FzYW4vY29tbW9u LmM6NzEKICBzZXRfdHJhY2sgbW0va2FzYW4vY29tbW9uLmM6NzkgW2lubGluZV0KICBfX2thc2Fu X2ttYWxsb2MgbW0va2FzYW4vY29tbW9uLmM6NTEyIFtpbmxpbmVdCiAgX19rYXNhbl9rbWFsbG9j LmNvbnN0cHJvcC4wKzB4Y2YvMHhlMCBtbS9rYXNhbi9jb21tb24uYzo0ODUKICBrYXNhbl9rbWFs bG9jKzB4OS8weDEwIG1tL2thc2FuL2NvbW1vbi5jOjUyNgogIF9fZG9fa21hbGxvYyBtbS9zbGFi LmM6MzY1NiBbaW5saW5lXQogIF9fa21hbGxvYysweDE2My8weDc3MCBtbS9zbGFiLmM6MzY2NQog IGttYWxsb2MgaW5jbHVkZS9saW51eC9zbGFiLmg6NTYxIFtpbmxpbmVdCiAgZmJjb25fc2V0X2Zv bnQrMHgzMmQvMHg4NjAgZHJpdmVycy92aWRlby9mYmRldi9jb3JlL2ZiY29uLmM6MjY2MwogIGNv bl9mb250X3NldCBkcml2ZXJzL3R0eS92dC92dC5jOjQ1MzggW2lubGluZV0KICBjb25fZm9udF9v cCsweGUxOC8weDEyNTAgZHJpdmVycy90dHkvdnQvdnQuYzo0NjAzCiAgdnRfaW9jdGwrMHhkMmUv MHgyNmQwIGRyaXZlcnMvdHR5L3Z0L3Z0X2lvY3RsLmM6OTEzCiAgdHR5X2lvY3RsKzB4YTM3LzB4 MTRmMCBkcml2ZXJzL3R0eS90dHlfaW8uYzoyNjU4CiAgdmZzX2lvY3RsIGZzL2lvY3RsLmM6NDcg W2lubGluZV0KICBmaWxlX2lvY3RsIGZzL2lvY3RsLmM6NTQ1IFtpbmxpbmVdCiAgZG9fdmZzX2lv Y3RsKzB4OTc3LzB4MTRlMCBmcy9pb2N0bC5jOjczMgogIGtzeXNfaW9jdGwrMHhhYi8weGQwIGZz L2lvY3RsLmM6NzQ5CiAgX19kb19zeXNfaW9jdGwgZnMvaW9jdGwuYzo3NTYgW2lubGluZV0KICBf X3NlX3N5c19pb2N0bCBmcy9pb2N0bC5jOjc1NCBbaW5saW5lXQogIF9feDY0X3N5c19pb2N0bCsw eDczLzB4YjAgZnMvaW9jdGwuYzo3NTQKICBkb19zeXNjYWxsXzY0KzB4ZmEvMHg3OTAgYXJjaC94 ODYvZW50cnkvY29tbW9uLmM6Mjk0CiAgZW50cnlfU1lTQ0FMTF82NF9hZnRlcl9od2ZyYW1lKzB4 NDkvMHhiZQoKRnJlZWQgYnkgdGFzayA5NzcxOgogIHNhdmVfc3RhY2srMHgyMy8weDkwIG1tL2th c2FuL2NvbW1vbi5jOjcxCiAgc2V0X3RyYWNrIG1tL2thc2FuL2NvbW1vbi5jOjc5IFtpbmxpbmVd CiAga2FzYW5fc2V0X2ZyZWVfaW5mbyBtbS9rYXNhbi9jb21tb24uYzozMzQgW2lubGluZV0KICBf X2thc2FuX3NsYWJfZnJlZSsweDEwMi8weDE1MCBtbS9rYXNhbi9jb21tb24uYzo0NzMKICBrYXNh bl9zbGFiX2ZyZWUrMHhlLzB4MTAgbW0va2FzYW4vY29tbW9uLmM6NDgyCiAgX19jYWNoZV9mcmVl IG1tL3NsYWIuYzozNDI2IFtpbmxpbmVdCiAga2ZyZWUrMHgxMGEvMHgyYzAgbW0vc2xhYi5jOjM3 NTcKICB0b21veW9faW5pdF9sb2crMHgxNWMxLzB4MjA3MCBzZWN1cml0eS90b21veW8vYXVkaXQu YzoyOTQKICB0b21veW9fc3VwZXJ2aXNvcisweDMzZi8weGVmMCBzZWN1cml0eS90b21veW8vY29t bW9uLmM6MjA5NQogIHRvbW95b19hdWRpdF9lbnZfbG9nIHNlY3VyaXR5L3RvbW95by9lbnZpcm9u LmM6MzYgW2lubGluZV0KICB0b21veW9fZW52X3Blcm0rMHgxOGUvMHgyMTAgc2VjdXJpdHkvdG9t b3lvL2Vudmlyb24uYzo2MwogIHRvbW95b19lbnZpcm9uIHNlY3VyaXR5L3RvbW95by9kb21haW4u Yzo2NzAgW2lubGluZV0KICB0b21veW9fZmluZF9uZXh0X2RvbWFpbisweDEzNTQvMHgxZjZjIHNl Y3VyaXR5L3RvbW95by9kb21haW4uYzo4NzYKICB0b21veW9fYnBybV9jaGVja19zZWN1cml0eSBz ZWN1cml0eS90b21veW8vdG9tb3lvLmM6MTA3IFtpbmxpbmVdCiAgdG9tb3lvX2Jwcm1fY2hlY2tf c2VjdXJpdHkrMHgxMjQvMHgxYTAgc2VjdXJpdHkvdG9tb3lvL3RvbW95by5jOjk3CiAgc2VjdXJp dHlfYnBybV9jaGVjaysweDYzLzB4YjAgc2VjdXJpdHkvc2VjdXJpdHkuYzo3ODQKICBzZWFyY2hf YmluYXJ5X2hhbmRsZXIrMHg3MS8weDU3MCBmcy9leGVjLmM6MTY0NQogIGV4ZWNfYmlucHJtIGZz L2V4ZWMuYzoxNzAxIFtpbmxpbmVdCiAgX19kb19leGVjdmVfZmlsZS5pc3JhLjArMHgxMzI5LzB4 MjJiMCBmcy9leGVjLmM6MTgyMQogIGRvX2V4ZWN2ZWF0X2NvbW1vbiBmcy9leGVjLmM6MTg2NyBb aW5saW5lXQogIGRvX2V4ZWN2ZSBmcy9leGVjLmM6MTg4NCBbaW5saW5lXQogIF9fZG9fc3lzX2V4 ZWN2ZSBmcy9leGVjLmM6MTk2MCBbaW5saW5lXQogIF9fc2Vfc3lzX2V4ZWN2ZSBmcy9leGVjLmM6 MTk1NSBbaW5saW5lXQogIF9feDY0X3N5c19leGVjdmUrMHg4Zi8weGMwIGZzL2V4ZWMuYzoxOTU1 CiAgZG9fc3lzY2FsbF82NCsweGZhLzB4NzkwIGFyY2gveDg2L2VudHJ5L2NvbW1vbi5jOjI5NAog IGVudHJ5X1NZU0NBTExfNjRfYWZ0ZXJfaHdmcmFtZSsweDQ5LzB4YmUKClRoZSBidWdneSBhZGRy ZXNzIGJlbG9uZ3MgdG8gdGhlIG9iamVjdCBhdCBmZmZmODg4MDk0YjBhMDAwCiAgd2hpY2ggYmVs b25ncyB0byB0aGUgY2FjaGUga21hbGxvYy00ayBvZiBzaXplIDQwOTYKVGhlIGJ1Z2d5IGFkZHJl c3MgaXMgbG9jYXRlZCAyNTc2IGJ5dGVzIGluc2lkZSBvZgogIDQwOTYtYnl0ZSByZWdpb24gW2Zm ZmY4ODgwOTRiMGEwMDAsIGZmZmY4ODgwOTRiMGIwMDApClRoZSBidWdneSBhZGRyZXNzIGJlbG9u Z3MgdG8gdGhlIHBhZ2U6CnBhZ2U6ZmZmZmVhMDAwMjUyYzI4MCByZWZjb3VudDoxIG1hcGNvdW50 OjAgbWFwcGluZzpmZmZmODg4MGFhNDAyMDAwICAKaW5kZXg6MHgwIGNvbXBvdW5kX21hcGNvdW50 OiAwCnJhdzogMDBmZmZlMDAwMDAxMDIwMCBmZmZmZWEwMDAyYTNhZTA4IGZmZmZlYTAwMDJhNmFh ODggZmZmZjg4ODBhYTQwMjAwMApyYXc6IDAwMDAwMDAwMDAwMDAwMDAgZmZmZjg4ODA5NGIwYTAw MCAwMDAwMDAwMTAwMDAwMDAxIDAwMDAwMDAwMDAwMDAwMDAKcGFnZSBkdW1wZWQgYmVjYXVzZTog a2FzYW46IGJhZCBhY2Nlc3MgZGV0ZWN0ZWQKCk1lbW9yeSBzdGF0ZSBhcm91bmQgdGhlIGJ1Z2d5 IGFkZHJlc3M6CiAgZmZmZjg4ODA5NGIwYTkwMDogMDAgMDAgMDAgMDAgMDAgMDAgMDAgMDAgMDAg MDAgMDAgMDAgMDAgMDAgMDAgMDAKICBmZmZmODg4MDk0YjBhOTgwOiAwMCAwMCAwMCAwMCAwMCAw MCAwMCAwMCAwMCAwMCAwMCAwMCAwMCAwMCAwMCAwMAo+IGZmZmY4ODgwOTRiMGFhMDA6IDAwIDAw IGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjCiAgICAgICAgICAgICAg ICAgICAgICAgICAgXgogIGZmZmY4ODgwOTRiMGFhODA6IGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZj IGZjIGZjIGZjIGZjIGZjIGZjIGZjIGZjCiAgZmZmZjg4ODA5NGIwYWIwMDogZmMgZmMgZmMgZmMg ZmMgZmMgZmMgZmMgZmMgZmMgZmMgZmMgZmMgZmMgZmMgZmMKPT09PT09PT09PT09PT09PT09PT09 PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09CgoKLS0tClRoaXMg YnVnIGlzIGdlbmVyYXRlZCBieSBhIGJvdC4gSXQgbWF5IGNvbnRhaW4gZXJyb3JzLgpTZWUgaHR0 cHM6Ly9nb28uZ2wvdHBzbUVKIGZvciBtb3JlIGluZm9ybWF0aW9uIGFib3V0IHN5emJvdC4Kc3l6 Ym90IGVuZ2luZWVycyBjYW4gYmUgcmVhY2hlZCBhdCBzeXprYWxsZXJAZ29vZ2xlZ3JvdXBzLmNv bS4KCnN5emJvdCB3aWxsIGtlZXAgdHJhY2sgb2YgdGhpcyBidWcgcmVwb3J0LiBTZWU6Cmh0dHBz Oi8vZ29vLmdsL3Rwc21FSiNzdGF0dXMgZm9yIGhvdyB0byBjb21tdW5pY2F0ZSB3aXRoIHN5emJv dC4Kc3l6Ym90IGNhbiB0ZXN0IHBhdGNoZXMgZm9yIHRoaXMgYnVnLCBmb3IgZGV0YWlscyBzZWU6 Cmh0dHBzOi8vZ29vLmdsL3Rwc21FSiN0ZXN0aW5nLXBhdGNoZXMKX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fX18KZHJpLWRldmVsIG1haWxpbmcgbGlzdApkcmkt ZGV2ZWxAbGlzdHMuZnJlZWRlc2t0b3Aub3JnCmh0dHBzOi8vbGlzdHMuZnJlZWRlc2t0b3Aub3Jn L21haWxtYW4vbGlzdGluZm8vZHJpLWRldmVs From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.4 required=3.0 tests=FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5B9E2C432C0 for ; Tue, 3 Dec 2019 22:25:10 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 26DD020684 for ; Tue, 3 Dec 2019 22:25:10 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727579AbfLCWZJ (ORCPT ); Tue, 3 Dec 2019 17:25:09 -0500 Received: from mail-io1-f69.google.com ([209.85.166.69]:56298 "EHLO mail-io1-f69.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727208AbfLCWZJ (ORCPT ); Tue, 3 Dec 2019 17:25:09 -0500 Received: by mail-io1-f69.google.com with SMTP id z21so3556461iob.22 for ; Tue, 03 Dec 2019 14:25:08 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:message-id:subject:from:to; bh=CXOkI0TBPtmTtJsgF6Sr0rjb/p028NpwaM4sLEBYlYQ=; b=TaTxXn+jddrEjRA+Kx6ltJHMvvjcuBsPElNj7REBlpKhlapE5+wRszsEwWe/5ttCpt EWelRChbJWUzfBZvzDOBrq+2vrd1dno7F5UBFnM7rg5At2Oz7EYdcJl3Crg/r3HLyHkb 4soMXY4gDsOWOCffwrPShRzn4uPe+Q9gt1dT8F2Ftp4wUmEnIz5vINbhyOqJtnD//Hzw nGfpjs75WidDySaBYFeA5ryaZ7sVDVQaXpbn3lzkpBNEhilrehH9v/mj1FFGkbC8fkOQ WBXFpCvKGhUkGuTR7I0gEdMuYXTyzksWyP4hsgsbrE4/iKZfsM0Sq+/P40EIG2mI/jQD /XDA== X-Gm-Message-State: APjAAAXgxnG6Z4kv5tRhL+C4bzKTuXayVtN1jRRbfHDkNzv7ysJY9zIv d1MtA7oPhBwCjTUninVqyfqe4VD4IyKVh4K11xCQ474X87dJ X-Google-Smtp-Source: APXvYqw0xQihGRub9pr2EXHoW6MqapjULktrGjdJ8k6mGFbVD7FZp6C3iVDmayNWFbuvk79pyYzHmOJ+M1o4qnItZXeuDkXdbxWn MIME-Version: 1.0 X-Received: by 2002:a05:6602:2541:: with SMTP id j1mr388622ioe.239.1575411908408; Tue, 03 Dec 2019 14:25:08 -0800 (PST) Date: Tue, 03 Dec 2019 14:25:08 -0800 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <0000000000002cfc3a0598d42b70@google.com> Subject: KASAN: slab-out-of-bounds Read in fbcon_get_font From: syzbot To: b.zolnierkie@samsung.com, daniel.thompson@linaro.org, daniel.vetter@ffwll.ch, dri-devel@lists.freedesktop.org, ghalat@redhat.com, linux-fbdev@vger.kernel.org, linux-kernel@vger.kernel.org, maarten.lankhorst@linux.intel.com, sam@ravnborg.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hello, syzbot found the following crash on: HEAD commit: 76bb8b05 Merge tag 'kbuild-v5.5' of git://git.kernel.org/p.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=10bfe282e00000 kernel config: https://syzkaller.appspot.com/x/.config?x=dd226651cb0f364b dashboard link: https://syzkaller.appspot.com/bug?extid=4455ca3b3291de891abc compiler: gcc (GCC) 9.0.0 20181231 (experimental) syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11181edae00000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=105cbb7ae00000 IMPORTANT: if you fix the bug, please add the following tag to the commit: Reported-by: syzbot+4455ca3b3291de891abc@syzkaller.appspotmail.com ================================================================== BUG: KASAN: slab-out-of-bounds in memcpy include/linux/string.h:380 [inline] BUG: KASAN: slab-out-of-bounds in fbcon_get_font+0x2b2/0x5e0 drivers/video/fbdev/core/fbcon.c:2465 Read of size 16 at addr ffff888094b0aa10 by task syz-executor414/9999 CPU: 0 PID: 9999 Comm: syz-executor414 Not tainted 5.4.0-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:77 [inline] dump_stack+0x197/0x210 lib/dump_stack.c:118 print_address_description.constprop.0.cold+0xd4/0x30b mm/kasan/report.c:374 __kasan_report.cold+0x1b/0x41 mm/kasan/report.c:506 kasan_report+0x12/0x20 mm/kasan/common.c:638 check_memory_region_inline mm/kasan/generic.c:185 [inline] check_memory_region+0x134/0x1a0 mm/kasan/generic.c:192 memcpy+0x24/0x50 mm/kasan/common.c:124 memcpy include/linux/string.h:380 [inline] fbcon_get_font+0x2b2/0x5e0 drivers/video/fbdev/core/fbcon.c:2465 con_font_get drivers/tty/vt/vt.c:4446 [inline] con_font_op+0x20b/0x1250 drivers/tty/vt/vt.c:4605 vt_ioctl+0x181a/0x26d0 drivers/tty/vt/vt_ioctl.c:965 tty_ioctl+0xa37/0x14f0 drivers/tty/tty_io.c:2658 vfs_ioctl fs/ioctl.c:47 [inline] file_ioctl fs/ioctl.c:545 [inline] do_vfs_ioctl+0x977/0x14e0 fs/ioctl.c:732 ksys_ioctl+0xab/0xd0 fs/ioctl.c:749 __do_sys_ioctl fs/ioctl.c:756 [inline] __se_sys_ioctl fs/ioctl.c:754 [inline] __x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:754 do_syscall_64+0xfa/0x790 arch/x86/entry/common.c:294 entry_SYSCALL_64_after_hwframe+0x49/0xbe RIP: 0033:0x4444d9 Code: 18 89 d0 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 7b d8 fb ff c3 66 2e 0f 1f 84 00 00 00 00 RSP: 002b:00007fff6f4393b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007fff6f4393c0 RCX: 00000000004444d9 RDX: 0000000020000440 RSI: 0000000000004b72 RDI: 0000000000000005 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000400da0 R10: 00007fff6f438f00 R11: 0000000000000246 R12: 00000000004021e0 R13: 0000000000402270 R14: 0000000000000000 R15: 0000000000000000 Allocated by task 9999: save_stack+0x23/0x90 mm/kasan/common.c:71 set_track mm/kasan/common.c:79 [inline] __kasan_kmalloc mm/kasan/common.c:512 [inline] __kasan_kmalloc.constprop.0+0xcf/0xe0 mm/kasan/common.c:485 kasan_kmalloc+0x9/0x10 mm/kasan/common.c:526 __do_kmalloc mm/slab.c:3656 [inline] __kmalloc+0x163/0x770 mm/slab.c:3665 kmalloc include/linux/slab.h:561 [inline] fbcon_set_font+0x32d/0x860 drivers/video/fbdev/core/fbcon.c:2663 con_font_set drivers/tty/vt/vt.c:4538 [inline] con_font_op+0xe18/0x1250 drivers/tty/vt/vt.c:4603 vt_ioctl+0xd2e/0x26d0 drivers/tty/vt/vt_ioctl.c:913 tty_ioctl+0xa37/0x14f0 drivers/tty/tty_io.c:2658 vfs_ioctl fs/ioctl.c:47 [inline] file_ioctl fs/ioctl.c:545 [inline] do_vfs_ioctl+0x977/0x14e0 fs/ioctl.c:732 ksys_ioctl+0xab/0xd0 fs/ioctl.c:749 __do_sys_ioctl fs/ioctl.c:756 [inline] __se_sys_ioctl fs/ioctl.c:754 [inline] __x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:754 do_syscall_64+0xfa/0x790 arch/x86/entry/common.c:294 entry_SYSCALL_64_after_hwframe+0x49/0xbe Freed by task 9771: save_stack+0x23/0x90 mm/kasan/common.c:71 set_track mm/kasan/common.c:79 [inline] kasan_set_free_info mm/kasan/common.c:334 [inline] __kasan_slab_free+0x102/0x150 mm/kasan/common.c:473 kasan_slab_free+0xe/0x10 mm/kasan/common.c:482 __cache_free mm/slab.c:3426 [inline] kfree+0x10a/0x2c0 mm/slab.c:3757 tomoyo_init_log+0x15c1/0x2070 security/tomoyo/audit.c:294 tomoyo_supervisor+0x33f/0xef0 security/tomoyo/common.c:2095 tomoyo_audit_env_log security/tomoyo/environ.c:36 [inline] tomoyo_env_perm+0x18e/0x210 security/tomoyo/environ.c:63 tomoyo_environ security/tomoyo/domain.c:670 [inline] tomoyo_find_next_domain+0x1354/0x1f6c security/tomoyo/domain.c:876 tomoyo_bprm_check_security security/tomoyo/tomoyo.c:107 [inline] tomoyo_bprm_check_security+0x124/0x1a0 security/tomoyo/tomoyo.c:97 security_bprm_check+0x63/0xb0 security/security.c:784 search_binary_handler+0x71/0x570 fs/exec.c:1645 exec_binprm fs/exec.c:1701 [inline] __do_execve_file.isra.0+0x1329/0x22b0 fs/exec.c:1821 do_execveat_common fs/exec.c:1867 [inline] do_execve fs/exec.c:1884 [inline] __do_sys_execve fs/exec.c:1960 [inline] __se_sys_execve fs/exec.c:1955 [inline] __x64_sys_execve+0x8f/0xc0 fs/exec.c:1955 do_syscall_64+0xfa/0x790 arch/x86/entry/common.c:294 entry_SYSCALL_64_after_hwframe+0x49/0xbe The buggy address belongs to the object at ffff888094b0a000 which belongs to the cache kmalloc-4k of size 4096 The buggy address is located 2576 bytes inside of 4096-byte region [ffff888094b0a000, ffff888094b0b000) The buggy address belongs to the page: page:ffffea000252c280 refcount:1 mapcount:0 mapping:ffff8880aa402000 index:0x0 compound_mapcount: 0 raw: 00fffe0000010200 ffffea0002a3ae08 ffffea0002a6aa88 ffff8880aa402000 raw: 0000000000000000 ffff888094b0a000 0000000100000001 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff888094b0a900: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff888094b0a980: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > ffff888094b0aa00: 00 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc ^ ffff888094b0aa80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff888094b0ab00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ================================================================== --- This bug is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this bug report. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. syzbot can test patches for this bug, for details see: https://goo.gl/tpsmEJ#testing-patches