From: syzbot <syzbot+9a4fbb77c9d4aacd3388@syzkaller.appspotmail.com>
To: hariconscious@gmail.com, linux-kernel@vger.kernel.org,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [tipc?] KMSAN: uninit-value in tipc_rcv (2)
Date: Fri, 07 Nov 2025 01:21:02 -0800 [thread overview]
Message-ID: <690db9fe.a70a0220.22f260.002f.GAE@google.com> (raw)
In-Reply-To: <5715ad57-d676-ecde-1636-1634b49316d6@gmail.com>
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
kernel BUG in tipc_buf_acquire
tipc: Started in network mode
tipc: Node identity 5e9377e8cc82, cluster identity 4711
tipc: tipc_buf_acquire
skbuff: skb_over_panic: text:ffffffff8fe53c01 len:76 put:76 head:0000000000000000 data:00000000000000d0 tail:0x11c end:0x0 dev:<NULL>
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:212!
Oops: invalid opcode: 0000 [#1] SMP PTI
CPU: 0 UID: 0 PID: 6600 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(none)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025
RIP: 0010:skb_panic+0x2d3/0x340 net/core/skbuff.c:212
Code: d0 44 8b 45 cc 4c 8b 8d 58 ff ff ff 41 52 ff b5 70 ff ff ff ff b5 68 ff ff ff ff b5 60 ff ff ff e8 d2 5d ee ff 48 83 c4 20 90 <0f> 0b e8 c6 8f 69 01 48 83 7d a0 00 0f 84 6a ff ff ff 48 8b 7d c0
RSP: 0018:ffff88801f8cf0e8 EFLAGS: 00010286
RAX: 0000000000000085 RBX: ffff88811718cda0 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000002
RBP: ffff88801f8cf1a0 R08: ffffea000000000f R09: 0000000000000000
R10: ffff888237c7e028 R11: ffff88823f278d40 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
FS: 00007f26537fe6c0(0000) GS:ffff8881aaf8d000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2654574620 CR3: 0000000049ab8000 CR4: 00000000003526f0
Call Trace:
<TASK>
skb_over_panic net/core/skbuff.c:217 [inline]
skb_put+0x1f5/0x250 net/core/skbuff.c:2583
tipc_buf_acquire+0x141/0x1b0 net/tipc/msg.c:77
tipc_disc_create+0x12f/0x870 net/tipc/discover.c:359
tipc_enable_bearer net/tipc/bearer.c:348 [inline]
__tipc_nl_bearer_enable+0x1f61/0x2a00 net/tipc/bearer.c:1047
__tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline]
tipc_nl_compat_doit+0x67b/0xa10 net/tipc/netlink_compat.c:393
tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline]
tipc_nl_compat_recv+0x1007/0x1670 net/tipc/netlink_compat.c:1321
genl_family_rcv_msg_doit+0x338/0x3f0 net/netlink/genetlink.c:1115
genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]
genl_rcv_msg+0xacf/0xc10 net/netlink/genetlink.c:1210
netlink_rcv_skb+0x54d/0x680 net/netlink/af_netlink.c:2552
genl_rcv+0x41/0x60 net/netlink/genetlink.c:1219
netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
netlink_unicast+0xf04/0x12b0 net/netlink/af_netlink.c:1346
netlink_sendmsg+0x10b3/0x1250 net/netlink/af_netlink.c:1896
sock_sendmsg_nosec net/socket.c:727 [inline]
__sock_sendmsg+0x333/0x3d0 net/socket.c:742
____sys_sendmsg+0x7e0/0xd80 net/socket.c:2630
___sys_sendmsg+0x271/0x3b0 net/socket.c:2684
__sys_sendmsg net/socket.c:2716 [inline]
__do_sys_sendmsg net/socket.c:2721 [inline]
__se_sys_sendmsg net/socket.c:2719 [inline]
__x64_sys_sendmsg+0x211/0x3e0 net/socket.c:2719
x64_sys_call+0x1dfd/0x3e30 arch/x86/include/generated/asm/syscalls_64.h:47
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xd9/0xfa0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f265458eb69
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f26537fe038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f26547b5fa0 RCX: 00007f265458eb69
RDX: 0000000000000000 RSI: 00002000000002c0 RDI: 0000000000000006
RBP: 00007f2654611df1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007f26547b5fa0 R15: 00007ffe744cefd8
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:skb_panic+0x2d3/0x340 net/core/skbuff.c:212
Code: d0 44 8b 45 cc 4c 8b 8d 58 ff ff ff 41 52 ff b5 70 ff ff ff ff b5 68 ff ff ff ff b5 60 ff ff ff e8 d2 5d ee ff 48 83 c4 20 90 <0f> 0b e8 c6 8f 69 01 48 83 7d a0 00 0f 84 6a ff ff ff 48 8b 7d c0
RSP: 0018:ffff88801f8cf0e8 EFLAGS: 00010286
RAX: 0000000000000085 RBX: ffff88811718cda0 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000002
RBP: ffff88801f8cf1a0 R08: ffffea000000000f R09: 0000000000000000
R10: ffff888237c7e028 R11: ffff88823f278d40 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
FS: 00007f26537fe6c0(0000) GS:ffff8881aaf8d000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2654574620 CR3: 0000000049ab8000 CR4: 00000000003526f0
Tested on:
commit: 4a0c9b33 Merge tag 'probes-fixes-v6.18-rc4' of git://g..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=17a79084580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2901a6a99b67fbcc
dashboard link: https://syzkaller.appspot.com/bug?extid=9a4fbb77c9d4aacd3388
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=107a332f980000
next parent reply other threads:[~2025-11-07 9:21 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <5715ad57-d676-ecde-1636-1634b49316d6@gmail.com>
2025-11-07 9:21 ` syzbot [this message]
[not found] <CABBwEEgK85XKVdisWmzKVUQS0ZKnVa0TmRQHP+g1t+mfEWpu0A@mail.gmail.com>
2025-11-22 10:11 ` [syzbot] [tipc?] KMSAN: uninit-value in tipc_rcv (2) syzbot
[not found] <0f7bf1a1-7708-b253-fd8a-3bfbefe4e309@gmail.com>
2025-11-18 13:28 ` syzbot
[not found] <CABBwEEhHeCq3Ry-6JoG1ruTTbfeRUKcYxTobQd88O8wYvOQBUQ@mail.gmail.com>
2025-11-07 10:58 ` syzbot
[not found] <e8b78334-cb9f-900b-f05a-23a0d0ee902a@gmail.com>
2025-11-07 6:46 ` syzbot
[not found] <20250920170037.9612-1-hariconscious@gmail.com>
2025-09-20 19:43 ` syzbot
[not found] <20250919152337.47803-1-hariconscious@gmail.com>
2025-09-19 17:10 ` syzbot
2025-07-23 14:45 syzbot
2025-08-03 9:39 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=690db9fe.a70a0220.22f260.002f.GAE@google.com \
--to=syzbot+9a4fbb77c9d4aacd3388@syzkaller.appspotmail.com \
--cc=hariconscious@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.