From: syzbot <syzbot+fe2a9f19481e3bfed524@syzkaller.appspotmail.com>
To: bp@alien8.de, hpa@zytor.com, linux-kernel@vger.kernel.org,
luto@kernel.org, mingo@redhat.com,
syzkaller-bugs@googlegroups.com, tglx@linutronix.de,
x86@kernel.org
Subject: KASAN: user-memory-access Read in vdso_fault
Date: Thu, 24 Sep 2020 02:42:19 -0700 [thread overview]
Message-ID: <0000000000002d3bc705b00c04fa@google.com> (raw)
Hello,
syzbot found the following issue on:
HEAD commit: eb5f95f1 Merge tag 's390-5.9-6' of git://git.kernel.org/pu..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1077ecc3900000
kernel config: https://syzkaller.appspot.com/x/.config?x=cd992d74d6c7e62
dashboard link: https://syzkaller.appspot.com/bug?extid=fe2a9f19481e3bfed524
compiler: clang version 10.0.0 (https://github.com/llvm/llvm-project/ c2443155a0fb245c8f17f2c1c72b6ea391e86e81)
Unfortunately, I don't have any reproducer for this issue yet.
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+fe2a9f19481e3bfed524@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: user-memory-access in vdso_fault+0xc1/0x1b0 arch/x86/entry/vdso/vma.c:67
Read of size 8 at addr 000000001953fc48 by task systemd-udevd/9883
CPU: 0 PID: 9883 Comm: systemd-udevd Not tainted 5.9.0-rc5-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1d6/0x29e lib/dump_stack.c:118
__kasan_report mm/kasan/report.c:517 [inline]
kasan_report+0x151/0x1d0 mm/kasan/report.c:530
vdso_fault+0xc1/0x1b0 arch/x86/entry/vdso/vma.c:67
__do_fault+0x138/0x3b0 mm/memory.c:3450
do_read_fault+0x5a6/0x9e0 mm/memory.c:3843
do_fault mm/memory.c:3971 [inline]
handle_pte_fault mm/memory.c:4211 [inline]
__handle_mm_fault mm/memory.c:4346 [inline]
handle_mm_fault+0x1d73/0x29a0 mm/memory.c:4444
do_user_addr_fault+0x515/0xa90 arch/x86/mm/fault.c:1372
handle_page_fault arch/x86/mm/fault.c:1429 [inline]
exc_page_fault+0x129/0x240 arch/x86/mm/fault.c:1482
asm_exc_page_fault+0x1e/0x30 arch/x86/include/asm/idtentry.h:538
RIP: 0033:0x7ffedaddb630
Code: Bad RIP value.
RSP: 002b:00007ffedad997b8 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000015
RDX: 0000000058585858 RSI: 0000000000000000 RDI: 00007ffedad997e0
RBP: 0000000000000000 R08: 000000000000fefe R09: 0000000000000030
R10: 0000000000000000 R11: 0000000000000206 R12: 000055e855d83675
R13: 00007ffedad99938 R14: 0000000000080000 R15: 000055e855d83660
==================================================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
next reply other threads:[~2020-09-24 9:42 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-09-24 9:42 syzbot [this message]
2020-09-25 12:17 ` KASAN: user-memory-access Read in vdso_fault Dmitry Vyukov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0000000000002d3bc705b00c04fa@google.com \
--to=syzbot+fe2a9f19481e3bfed524@syzkaller.appspotmail.com \
--cc=bp@alien8.de \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=syzkaller-bugs@googlegroups.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.