From: syzbot <syzbot+c23c5421600e9b454849@syzkaller.appspotmail.com>
To: andrii@kernel.org, ast@kernel.org, bpf@vger.kernel.org,
daniel@iogearbox.net, davem@davemloft.net,
john.fastabend@gmail.com, kafai@fb.com, kpsingh@kernel.org,
kuba@kernel.org, linux-kernel@vger.kernel.org,
netdev@vger.kernel.org, songliubraving@fb.com,
syzkaller-bugs@googlegroups.com, yhs@fb.com
Subject: [syzbot] BUG: unable to handle kernel access to user memory in sock_ioctl
Date: Wed, 10 Mar 2021 10:28:16 -0800 [thread overview]
Message-ID: <00000000000096cdaa05bd32d46f@google.com> (raw)
Hello,
syzbot found the following issue on:
HEAD commit: 0d7588ab riscv: process: Fix no prototype for arch_dup_tas..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux.git fixes
console output: https://syzkaller.appspot.com/x/log.txt?x=122c343ad00000
kernel config: https://syzkaller.appspot.com/x/.config?x=e3c595255fb2d136
dashboard link: https://syzkaller.appspot.com/bug?extid=c23c5421600e9b454849
userspace arch: riscv64
Unfortunately, I don't have any reproducer for this issue yet.
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c23c5421600e9b454849@syzkaller.appspotmail.com
Unable to handle kernel access to user memory without uaccess routines at virtual address 0000000020000300
Oops [#1]
Modules linked in:
CPU: 1 PID: 4488 Comm: syz-executor.0 Not tainted 5.12.0-rc2-syzkaller-00467-g0d7588ab9ef9 #0
Hardware name: riscv-virtio,qemu (DT)
epc : sock_ioctl+0x424/0x6ac net/socket.c:1124
ra : sock_ioctl+0x424/0x6ac net/socket.c:1124
epc : ffffffe002aeeb3e ra : ffffffe002aeeb3e sp : ffffffe023867da0
gp : ffffffe005d25378 tp : ffffffe007e116c0 t0 : 0000000000000000
t1 : 0000000000000001 t2 : 0000003fb8035e44 s0 : ffffffe023867e30
s1 : 0000000000040000 a0 : 0000000000000000 a1 : 0000000000000007
a2 : 1ffffffc00fc22d8 a3 : ffffffe003bc1d02 a4 : 0000000000000000
a5 : 0000000000000000 a6 : 0000000000f00000 a7 : ffffffe000082eba
s2 : 0000000000000000 s3 : 0000000000008902 s4 : 0000000020000300
s5 : ffffffe005d2b0d0 s6 : ffffffe010facfc0 s7 : ffffffe008e00000
s8 : 0000000000008903 s9 : ffffffe010fad080 s10: 0000000000000000
s11: 0000000000020000 t3 : 982de389919f6300 t4 : ffffffc401175688
t5 : ffffffc401175691 t6 : 0000000000000007
status: 0000000000000120 badaddr: 0000000020000300 cause: 000000000000000f
Call Trace:
[<ffffffe002aeeb3e>] sock_ioctl+0x424/0x6ac net/socket.c:1124
[<ffffffe0003fdb6a>] vfs_ioctl fs/ioctl.c:48 [inline]
[<ffffffe0003fdb6a>] __do_sys_ioctl fs/ioctl.c:753 [inline]
[<ffffffe0003fdb6a>] sys_ioctl+0x5c2/0xd56 fs/ioctl.c:739
[<ffffffe000005562>] ret_from_syscall+0x0/0x2
Dumping ftrace buffer:
(ftrace buffer empty)
---[ end trace a5f91e70f37b907b ]---
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
next reply other threads:[~2021-03-10 18:28 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-03-10 18:28 syzbot [this message]
2021-03-10 18:53 ` [syzbot] BUG: unable to handle kernel access to user memory in sock_ioctl Dmitry Vyukov
2021-03-10 18:53 ` Dmitry Vyukov
2021-03-14 10:01 ` Dmitry Vyukov
2021-03-14 10:01 ` Dmitry Vyukov
2021-03-14 11:03 ` Dmitry Vyukov
2021-03-14 11:03 ` Dmitry Vyukov
2021-03-15 11:30 ` Ben Dooks
2021-03-15 11:30 ` Ben Dooks
2021-03-15 11:52 ` Dmitry Vyukov
2021-03-15 11:52 ` Dmitry Vyukov
2021-03-15 14:41 ` Ben Dooks
2021-03-15 14:41 ` Ben Dooks
2021-03-18 15:18 ` Dmitry Vyukov
2021-03-18 15:18 ` Dmitry Vyukov
2021-03-18 15:34 ` Ben Dooks
2021-03-18 15:34 ` Ben Dooks
2021-03-18 15:54 ` Dmitry Vyukov
2021-03-18 15:54 ` Dmitry Vyukov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=00000000000096cdaa05bd32d46f@google.com \
--to=syzbot+c23c5421600e9b454849@syzkaller.appspotmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=john.fastabend@gmail.com \
--cc=kafai@fb.com \
--cc=kpsingh@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=songliubraving@fb.com \
--cc=syzkaller-bugs@googlegroups.com \
--cc=yhs@fb.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.