From: syzbot <syzbot+19bed92c97bee999e5db@syzkaller.appspotmail.com>
To: gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org,
linux-usb@vger.kernel.org, stern@rowland.harvard.edu,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [usb?] general protection fault in usb_gadget_udc_reset (4)
Date: Mon, 09 Mar 2026 07:55:02 -0700 [thread overview]
Message-ID: <69aedf46.050a0220.310d8.0027.GAE@google.com> (raw)
In-Reply-To: <e9d9d118-e6fc-42de-847d-e58eaf7bcba5@rowland.harvard.edu>
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
general protection fault in usb_gadget_udc_reset
raw-gadget.0 gadget.1: Reset #2
usb 2-1: device descriptor read/64, error -32
gadget gadget.1: Reset #1, driver 0000000000000000
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000008: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000040-0x0000000000000047]
CPU: 0 UID: 0 PID: 5814 Comm: kworker/0:3 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026
Workqueue: usb_hub_wq hub_event
RIP: 0010:usb_gadget_udc_reset+0x42/0x80 drivers/usb/gadget/udc/core.c:1201
Code: 01 00 00 4c 89 f7 48 c7 c6 a0 d2 fb 8b 4c 89 fa e8 23 5b fd ff 49 83 c7 40 4c 89 f8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df <80> 3c 08 00 74 08 4c 89 ff e8 f0 da fb 00 4d 8b 1f 48 89 df 2e 2e
RSP: 0018:ffffc90004be64c0 EFLAGS: 00010202
RAX: 0000000000000008 RBX: ffff888029e78c40 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffff8880348cba6c R08: 0000000000000000 R09: 0000000000000000
R10: dffffc0000000000 R11: fffff5200097cc01 R12: ffff888029e78c40
R13: 1ffff110053ee2a1 R14: ffff888029e78d58 R15: 0000000000000040
FS: 0000000000000000(0000) GS:ffff88812633d000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f16fca6890f CR3: 000000003df2e000 CR4: 00000000003526f0
Call Trace:
<TASK>
set_link_state+0x80b/0x1220 drivers/usb/gadget/udc/dummy_hcd.c:469
dummy_hub_control+0xa09/0x1a00 drivers/usb/gadget/udc/dummy_hcd.c:-1
rh_call_control drivers/usb/core/hcd.c:652 [inline]
rh_urb_enqueue drivers/usb/core/hcd.c:817 [inline]
usb_hcd_submit_urb+0xdbe/0x1b50 drivers/usb/core/hcd.c:1538
usb_start_wait_urb+0x12b/0x510 drivers/usb/core/message.c:59
usb_internal_control_msg drivers/usb/core/message.c:103 [inline]
usb_control_msg+0x232/0x3e0 drivers/usb/core/message.c:154
set_port_feature drivers/usb/core/hub.c:466 [inline]
hub_port_reset+0x3c7/0x1820 drivers/usb/core/hub.c:3083
hub_port_init+0x299/0x28c0 drivers/usb/core/hub.c:4939
usb_reset_and_verify_device+0x105d/0x1af0 drivers/usb/core/hub.c:6215
usb_reset_device+0x551/0xb40 drivers/usb/core/hub.c:6410
sd_config+0x27f/0x15b0 drivers/media/usb/gspca/se401.c:221
gspca_dev_probe2+0x81e/0x1450 drivers/media/usb/gspca/gspca.c:1529
usb_probe_interface+0x668/0xc90 drivers/usb/core/driver.c:396
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x267/0xaf0 drivers/base/dd.c:661
__driver_probe_device+0x18c/0x320 drivers/base/dd.c:803
driver_probe_device+0x4f/0x240 drivers/base/dd.c:833
__device_attach_driver+0x2d4/0x4c0 drivers/base/dd.c:961
bus_for_each_drv+0x25b/0x2f0 drivers/base/bus.c:500
__device_attach+0x2c8/0x450 drivers/base/dd.c:1033
device_initial_probe+0xa1/0xd0 drivers/base/dd.c:1088
bus_probe_device+0x12d/0x220 drivers/base/bus.c:574
device_add+0x7b6/0xb80 drivers/base/core.c:3689
usb_set_configuration+0x1a87/0x2110 drivers/usb/core/message.c:2208
usb_generic_driver_probe+0x8d/0x150 drivers/usb/core/generic.c:250
usb_probe_device+0x1c4/0x3b0 drivers/usb/core/driver.c:291
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x267/0xaf0 drivers/base/dd.c:661
__driver_probe_device+0x18c/0x320 drivers/base/dd.c:803
driver_probe_device+0x4f/0x240 drivers/base/dd.c:833
__device_attach_driver+0x2d4/0x4c0 drivers/base/dd.c:961
bus_for_each_drv+0x25b/0x2f0 drivers/base/bus.c:500
__device_attach+0x2c8/0x450 drivers/base/dd.c:1033
device_initial_probe+0xa1/0xd0 drivers/base/dd.c:1088
bus_probe_device+0x12d/0x220 drivers/base/bus.c:574
device_add+0x7b6/0xb80 drivers/base/core.c:3689
usb_new_device+0x9f8/0x16e0 drivers/usb/core/hub.c:2695
hub_port_connect drivers/usb/core/hub.c:5567 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5707 [inline]
port_event drivers/usb/core/hub.c:5871 [inline]
hub_event+0x2a49/0x4f60 drivers/usb/core/hub.c:5953
process_one_work kernel/workqueue.c:3275 [inline]
process_scheduled_works+0xb02/0x1830 kernel/workqueue.c:3358
worker_thread+0xa50/0xfc0 kernel/workqueue.c:3439
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:usb_gadget_udc_reset+0x42/0x80 drivers/usb/gadget/udc/core.c:1201
Code: 01 00 00 4c 89 f7 48 c7 c6 a0 d2 fb 8b 4c 89 fa e8 23 5b fd ff 49 83 c7 40 4c 89 f8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df <80> 3c 08 00 74 08 4c 89 ff e8 f0 da fb 00 4d 8b 1f 48 89 df 2e 2e
RSP: 0018:ffffc90004be64c0 EFLAGS: 00010202
RAX: 0000000000000008 RBX: ffff888029e78c40 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffff8880348cba6c R08: 0000000000000000 R09: 0000000000000000
R10: dffffc0000000000 R11: fffff5200097cc01 R12: ffff888029e78c40
R13: 1ffff110053ee2a1 R14: ffff888029e78d58 R15: 0000000000000040
FS: 0000000000000000(0000) GS:ffff88812633d000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f16fca6890f CR3: 000000003df2e000 CR4: 00000000003526f0
----------------
Code disassembly (best guess):
0: 01 00 add %eax,(%rax)
2: 00 4c 89 f7 add %cl,-0x9(%rcx,%rcx,4)
6: 48 c7 c6 a0 d2 fb 8b mov $0xffffffff8bfbd2a0,%rsi
d: 4c 89 fa mov %r15,%rdx
10: e8 23 5b fd ff call 0xfffd5b38
15: 49 83 c7 40 add $0x40,%r15
19: 4c 89 f8 mov %r15,%rax
1c: 48 c1 e8 03 shr $0x3,%rax
20: 48 b9 00 00 00 00 00 movabs $0xdffffc0000000000,%rcx
27: fc ff df
* 2a: 80 3c 08 00 cmpb $0x0,(%rax,%rcx,1) <-- trapping instruction
2e: 74 08 je 0x38
30: 4c 89 ff mov %r15,%rdi
33: e8 f0 da fb 00 call 0xfbdb28
38: 4d 8b 1f mov (%r15),%r11
3b: 48 89 df mov %rbx,%rdi
3e: 2e cs
3f: 2e cs
Tested on:
commit: 65169048 Merge tag 'spi-fix-v7.0-rc2' of git://git.ker..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=144e6016580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2a019678b1a3a692
dashboard link: https://syzkaller.appspot.com/bug?extid=19bed92c97bee999e5db
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=131c375a580000
next prev parent reply other threads:[~2026-03-09 14:55 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-25 7:30 [syzbot] [usb?] general protection fault in usb_gadget_udc_reset (4) syzbot
2026-03-07 10:52 ` syzbot
2026-03-08 15:36 ` Alan Stern
2026-03-08 16:01 ` syzbot
2026-03-09 14:25 ` Alan Stern
2026-03-09 14:55 ` syzbot [this message]
2026-03-09 15:24 ` Alan Stern
2026-03-09 15:43 ` syzbot
2026-03-10 15:50 ` Alan Stern
2026-03-10 16:09 ` syzbot
2026-03-10 19:02 ` Alan Stern
2026-03-10 19:32 ` syzbot
2026-03-11 1:50 ` Alan Stern
2026-03-11 3:16 ` syzbot
2026-03-11 18:44 ` Alan Stern
2026-03-11 19:25 ` syzbot
2026-03-12 17:56 ` Alan Stern
2026-03-12 18:29 ` syzbot
2026-03-13 2:05 ` Alan Stern
2026-03-13 2:42 ` syzbot
2026-03-13 16:07 ` Alan Stern
2026-03-13 16:32 ` syzbot
2026-03-13 19:47 ` Alan Stern
2026-03-13 21:28 ` syzbot
2026-03-14 16:42 ` Alan Stern
2026-03-14 17:07 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=69aedf46.050a0220.310d8.0027.GAE@google.com \
--to=syzbot+19bed92c97bee999e5db@syzkaller.appspotmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=stern@rowland.harvard.edu \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.