* [syzbot] [kvm-x86?] KASAN: use-after-free Read in kvm_setup_guest_pvclock
@ 2026-06-29 13:06 syzbot
2026-06-30 20:10 ` syzbot
0 siblings, 1 reply; 6+ messages in thread
From: syzbot @ 2026-06-29 13:06 UTC (permalink / raw)
To: bp, dave.hansen, hpa, kvm, linux-kernel, mingo, pbonzini, seanjc,
syzkaller-bugs, tglx, x86
Hello,
syzbot found the following issue on:
HEAD commit: dc59e4fea9d8 Linux 7.2-rc1
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=16f1b46e580000
kernel config: https://syzkaller.appspot.com/x/.config?x=77808e35144e725c
dashboard link: https://syzkaller.appspot.com/bug?extid=fb7c2dd166d3ea63df2a
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/9911e5707540/disk-dc59e4fe.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/bb0af0bc6e42/vmlinux-dc59e4fe.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b7ca0661e875/bzImage-dc59e4fe.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+fb7c2dd166d3ea63df2a@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: use-after-free in kvm_setup_guest_pvclock+0x5bf/0x660 arch/x86/kvm/x86.c:3272
Read of size 4 at addr ffff88804c505320 by task syz.1.5312/25543
CPU: 1 UID: 0 PID: 25543 Comm: syz.1.5312 Tainted: G L syzkaller #0 PREEMPT(full)
Tainted: [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/10/2026
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0x13d/0x4b0 mm/kasan/report.c:482
kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
kvm_setup_guest_pvclock+0x5bf/0x660 arch/x86/kvm/x86.c:3272
kvm_guest_time_update+0xa11/0x10b0 arch/x86/kvm/x86.c:3408
vcpu_enter_guest arch/x86/kvm/x86.c:11149 [inline]
vcpu_run+0x1cf1/0x5d50 arch/x86/kvm/x86.c:11707
kvm_arch_vcpu_ioctl_run+0x5b6/0x1890 arch/x86/kvm/x86.c:12062
kvm_vcpu_ioctl+0x730/0x1700 virt/kvm/kvm_main.c:4470
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl fs/ioctl.c:583 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f5deff9ce59
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f5df0dd3028 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007f5df0216090 RCX: 00007f5deff9ce59
RDX: 0000000000000000 RSI: 000000000000ae80 RDI: 0000000000000005
RBP: 00007f5df0032e6f R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f5df0216128 R14: 00007f5df0216090 R15: 00007ffd2f6378e8
</TASK>
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x200000000 pfn:0x4c505
flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000000 ffffea000145ba48 ffff8880b85414b0 0000000000000000
raw: 0000000200000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 0, migratetype Movable, gfp_mask 0x140dca(GFP_HIGHUSER_MOVABLE|__GFP_ZERO|__GFP_COMP), pid 25531, tgid 25531 (syz.1.5312), ts 1799784670966, free_ts 1801394089155
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0xfd/0x120 mm/page_alloc.c:1859
prep_new_page mm/page_alloc.c:1867 [inline]
get_page_from_freelist+0xf48/0x3530 mm/page_alloc.c:3946
__alloc_frozen_pages_noprof+0x299/0x2dc0 mm/page_alloc.c:5304
alloc_pages_mpol+0x1fb/0x540 mm/mempolicy.c:2490
folio_alloc_mpol_noprof+0x36/0x260 mm/mempolicy.c:2509
vma_alloc_folio_noprof+0xed/0x1d0 mm/mempolicy.c:2544
folio_prealloc mm/memory.c:1207 [inline]
alloc_anon_folio mm/memory.c:5247 [inline]
do_anonymous_page+0xb2b/0x2080 mm/memory.c:5342
do_pte_missing mm/memory.c:4564 [inline]
handle_pte_fault mm/memory.c:6379 [inline]
__handle_mm_fault+0x1d2c/0x2a00 mm/memory.c:6517
handle_mm_fault+0x37b/0xa30 mm/memory.c:6686
do_user_addr_fault+0x5a3/0x12f0 arch/x86/mm/fault.c:1343
handle_page_fault arch/x86/mm/fault.c:1483 [inline]
exc_page_fault+0x6f/0xd0 arch/x86/mm/fault.c:1536
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:595
page last free pid 25532 tgid 25531 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
__free_pages_prepare mm/page_alloc.c:1406 [inline]
__free_frozen_pages+0x79f/0x1090 mm/page_alloc.c:2950
__folio_put+0x3b4/0x5f0 mm/swap.c:112
folio_put include/linux/mm.h:2124 [inline]
put_page include/linux/mm.h:2193 [inline]
kvm_release_page_clean virt/kvm/kvm_main.c:2813 [inline]
kvm_release_page_clean+0x1dc/0x250 virt/kvm/kvm_main.c:2807
hva_to_pfn_retry virt/kvm/pfncache.c:246 [inline]
__kvm_gpc_refresh+0x1a63/0x22d0 virt/kvm/pfncache.c:330
__kvm_gpc_activate+0x2ab/0x490 virt/kvm/pfncache.c:424
kvm_gpc_activate_hva+0x73/0xa0 virt/kvm/pfncache.c:444
kvm_xen_vcpu_set_attr+0xfa0/0x1350 arch/x86/kvm/xen.c:938
kvm_arch_vcpu_ioctl+0xf98/0x5730 arch/x86/kvm/x86.c:6612
kvm_vcpu_ioctl+0x8a0/0x1700 virt/kvm/kvm_main.c:4647
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl fs/ioctl.c:583 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff88804c505200: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88804c505280: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88804c505300: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff88804c505380: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88804c505400: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [kvm-x86?] KASAN: use-after-free Read in kvm_setup_guest_pvclock
2026-06-29 13:06 syzbot
@ 2026-06-30 20:10 ` syzbot
0 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-06-30 20:10 UTC (permalink / raw)
To: bp, dave.hansen, hpa, kvm, linux-kernel, mingo, pbonzini, seanjc,
syzkaller-bugs, tglx, x86
syzbot has found a reproducer for the following issue on:
HEAD commit: 7de6ae9e1220 Add linux-next specific files for 20260629
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=163d19de580000
kernel config: https://syzkaller.appspot.com/x/.config?x=93f99737ecde604c
dashboard link: https://syzkaller.appspot.com/bug?extid=fb7c2dd166d3ea63df2a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1309af41580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11f28bae580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/a09187a6eb8d/disk-7de6ae9e.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f0a76dd86b32/vmlinux-7de6ae9e.xz
kernel image: https://storage.googleapis.com/syzbot-assets/864b9d8296e7/bzImage-7de6ae9e.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+fb7c2dd166d3ea63df2a@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: use-after-free in kvm_setup_guest_pvclock+0x439/0x620 arch/x86/kvm/x86.c:1728
Read of size 4 at addr ffff88804d02c320 by task syz.1.180/6591
CPU: 1 UID: 0 PID: 6591 Comm: syz.1.180 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
print_address_description+0x55/0x1e0 mm/kasan/report.c:378
print_report+0x58/0x70 mm/kasan/report.c:482
kasan_report+0x117/0x150 mm/kasan/report.c:595
kvm_setup_guest_pvclock+0x439/0x620 arch/x86/kvm/x86.c:1728
kvm_guest_time_update+0xa32/0xe60 arch/x86/kvm/x86.c:1864
vcpu_enter_guest arch/x86/kvm/x86.c:8038 [inline]
vcpu_run+0x150d/0x73e0 arch/x86/kvm/x86.c:8596
kvm_arch_vcpu_ioctl_run+0xe51/0x1960 arch/x86/kvm/x86.c:8929
kvm_vcpu_ioctl+0xa64/0xfe0 virt/kvm/kvm_main.c:4470
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl+0xff/0x170 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fbebb04ce59
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fbeba68d028 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fbebb2c6090 RCX: 00007fbebb04ce59
RDX: 0000000000000000 RSI: 000000000000ae80 RDI: 0000000000000005
RBP: 00007fbebb0e2e6f R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fbebb2c6128 R14: 00007fbebb2c6090 R15: 00007ffefb5754e8
</TASK>
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x200000000 pfn:0x4d02c
flags: 0x80000000000000(node=0|zone=1)
raw: 0080000000000000 ffffea000159c008 ffff8880b8642f70 0000000000000000
raw: 0000000200000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 0, migratetype Movable, gfp_mask 0x140dca(GFP_HIGHUSER_MOVABLE|__GFP_ZERO|__GFP_COMP), pid 6589, tgid 6589 (syz.1.180), ts 149074813359
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x1f9/0x250 mm/page_alloc.c:1861
prep_new_page mm/page_alloc.c:1869 [inline]
get_page_from_freelist+0x264c/0x26c0 mm/page_alloc.c:3949
__alloc_frozen_pages_noprof+0x1a6/0x390 mm/page_alloc.c:5322
alloc_pages_mpol+0xce/0x280 mm/mempolicy.c:2490
folio_alloc_mpol_noprof+0x3b/0x1e0 mm/mempolicy.c:2509
vma_alloc_folio_noprof+0xe1/0x1e0 mm/mempolicy.c:2544
folio_prealloc mm/memory.c:-1 [inline]
alloc_anon_folio mm/memory.c:5247 [inline]
do_anonymous_page mm/memory.c:5342 [inline]
do_pte_missing+0x835/0x28f0 mm/memory.c:4564
handle_pte_fault mm/memory.c:6379 [inline]
__handle_mm_fault mm/memory.c:6517 [inline]
handle_mm_fault+0xe0b/0x1520 mm/memory.c:6686
do_user_addr_fault+0xa4d/0x1340 arch/x86/mm/fault.c:1343
handle_page_fault arch/x86/mm/fault.c:1483 [inline]
exc_page_fault+0x6a/0xc0 arch/x86/mm/fault.c:1536
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:595
page last free pid 6590 tgid 6589 ts 149102566230 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
__free_pages_prepare mm/page_alloc.c:1408 [inline]
__free_frozen_pages+0x10de/0x11c0 mm/page_alloc.c:2952
__folio_put+0x30f/0x3c0 mm/swap.c:112
hva_to_pfn_retry virt/kvm/pfncache.c:246 [inline]
__kvm_gpc_refresh+0x1277/0x1710 virt/kvm/pfncache.c:330
__kvm_gpc_activate+0x289/0x3b0 virt/kvm/pfncache.c:424
kvm_xen_vcpu_set_attr+0x1d3/0x1190 arch/x86/kvm/xen.c:938
kvm_arch_vcpu_ioctl+0x1467/0x23f0 arch/x86/kvm/x86.c:3815
kvm_vcpu_ioctl+0x7e6/0xfe0 virt/kvm/kvm_main.c:4647
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl+0xff/0x170 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff88804d02c200: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88804d02c280: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88804d02c300: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff88804d02c380: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88804d02c400: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [kvm-x86?] KASAN: use-after-free Read in kvm_setup_guest_pvclock
[not found] <DK3EXQESFKHR.1JMHKZ0ADMVVR@igalia.com>
@ 2026-07-20 13:53 ` syzbot
0 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-07-20 13:53 UTC (permalink / raw)
To: halves, linux-kernel, syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
0000b4600000-0x00000000b8600000] (64MB)
[ 6.255166][ T1] ACPI: bus type thunderbolt registered
[ 6.306362][ T1] RAPL PMU: API unit is 2^-32 Joules, 0 fixed counters, 10737418240 ms ovfl timer
[ 6.320726][ T70] kworker/u8:4 (70) used greatest stack depth: 27600 bytes left
[ 6.392355][ T1] kvm_amd: CPU 0 isn't AMD or Hygon
[ 6.392394][ T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
[ 6.393087][ T1] clocksource: Switched to clocksource tsc
[ 6.393213][ T71] kworker/u8:3 (71) used greatest stack depth: 27344 bytes left
[ 6.418119][ T75] kworker/u8:4 (75) used greatest stack depth: 27200 bytes left
[ 6.516097][ T1] Initialise system trusted keyrings
[ 6.532538][ T1] workingset: timestamp_bits=40 (anon: 35) max_order=21 bucket_order=0 (anon: 0)
[ 6.566694][ T1] DLM installed
[ 6.592800][ T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 6.625574][ T1] NFS: Registering the id_resolver key type
[ 6.625765][ T1] Key type id_resolver registered
[ 6.625780][ T1] Key type id_legacy registered
[ 6.626561][ T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[ 6.626840][ T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[ 6.683834][ T1] smbdirect: subsystem loading...
[ 6.716365][ T1] smbdirect: subsystem loaded
[ 6.763512][ T1] Key type cifs.spnego registered
[ 6.764174][ T1] Key type cifs.idmap registered
[ 6.792353][ T1] ntfs3: Enabled Linux POSIX ACLs support
[ 6.792365][ T1] ntfs3: Read-only LZX/Xpress compression included
[ 6.792747][ T1] jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
[ 6.799004][ T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[ 6.851007][ T1] QNX4 filesystem 0.2.3 registered.
[ 6.851285][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 6.853799][ T1] fuse: init (API version 7.45)
[ 6.887403][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 6.894486][ T1] orangefs_init: module version upstream loaded
[ 6.898940][ T1] JFS: nTxBlock = 8192, nTxLock = 65536
[ 6.932174][ T1] SGI XFS with ACLs, security attributes, realtime, quota, no debug enabled
[ 6.955145][ T1] 9p: Installing v9fs 9p2000 file system support
[ 6.956070][ T1] NILFS version 2 loaded
[ 6.956080][ T1] befs: version: 0.9.3
[ 6.957362][ T1] ocfs2: Registered cluster interface o2cb
[ 6.999664][ T1] ocfs2: Registered cluster interface user
[ 7.020743][ T1] OCFS2 User DLM kernel interface loaded
[ 7.067258][ T1] gfs2: GFS2 installed
[ 7.097413][ T1] ceph: loaded (mds proto 32)
[ 7.117915][ T1] NET: Registered PF_ALG protocol family
[ 7.120294][ T1] async_tx: api initialized (async)
[ 7.120581][ T1] Key type asymmetric registered
[ 7.120754][ T1] Asymmetric key parser 'x509' registered
[ 7.120812][ T1] Asymmetric key parser 'pkcs8' registered
[ 7.121599][ T1] Key type pkcs7_test registered
[ 7.125388][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 7.176102][ T1] io scheduler mq-deadline registered
[ 7.176126][ T1] io scheduler kyber registered
[ 7.176786][ T1] io scheduler bfq registered
[ 7.184322][ T1] raid6: skipped pq benchmark and selected avx2x4
[ 7.222671][ T151] kworker/u8:3 (151) used greatest stack depth: 26912 bytes left
[ 7.246411][ T156] kworker/u8:5 (156) used greatest stack depth: 26048 bytes left
[ 7.267490][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 7.274296][ T1] ACPI: button: Power Button [PWRF]
[ 7.283915][ T1] input: Sleep Button as /devices/platform/LNXSLPBN:00/input/input1
[ 7.290898][ T1] ACPI: button: Sleep Button [SLPF]
[ 7.344578][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 7.411368][ T10] ACPI: \_SB_.LNKC: Enabled at IRQ 11
[ 7.411566][ T10] virtio-pci 0000:00:03.0: virtio_pci: leaving for legacy driver
[ 7.480603][ T10] ACPI: \_SB_.LNKD: Enabled at IRQ 10
[ 7.480814][ T10] virtio-pci 0000:00:04.0: virtio_pci: leaving for legacy driver
[ 7.540509][ T10] ACPI: \_SB_.LNKB: Enabled at IRQ 10
[ 7.540693][ T10] virtio-pci 0000:00:06.0: virtio_pci: leaving for legacy driver
[ 7.589579][ T10] virtio-pci 0000:00:07.0: virtio_pci: leaving for legacy driver
[ 8.845365][ T1] N_HDLC line discipline registered with maxframe=4096
[ 8.848528][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 8.888282][ T1] 00:02: ttyS0 I/O:0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 8.932129][ T1] 00:03: ttyS1 I/O:0x2f8 (irq = 3, base_baud = 115200) is a 16550A
[ 8.975973][ T1] 00:04: ttyS2 I/O:0x3e8 (irq = 6, base_baud = 115200) is a 16550A
[ 9.048379][ T1] 00:05: ttyS3 I/O:0x2e8 (irq = 7, base_baud = 115200) is a 16550A
[ 9.136987][ T1] Non-volatile memory driver v1.3
[ 9.209627][ T1] usbcore: registered new interface driver xillyusb
[ 9.232020][ T1] ACPI: bus type drm_connector registered
[ 9.265590][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 9.287444][ T1] ------------[ cut here ]------------
[ 9.287465][ T1] [PLANE:35:plane-0] pixel format with alpha exposed but blend mode not setup
[ 9.287490][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6d/0x1e60, CPU#1: swapper/0/1
[ 9.287615][ T1] Modules linked in:
[ 9.287649][ T1] CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 9.287667][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
[ 9.287727][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 9.287763][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 fa b0 be fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 d6 55 52 fc 49 bd 00 00 00 00 00 fc ff df
[ 9.287786][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 9.287807][ T1] RAX: 1ffff11004d00408 RBX: dffffc0000000000 RCX: ffff88801c6e5d00
[ 9.287824][ T1] RDX: ffff8880263f9dc0 RSI: 0000000000000023 RDI: ffffffff8fd964c0
[ 9.287840][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 9.287854][ T1] R10: dffffc0000000000 R11: fffffbfff1f9c610 R12: dffffc0000000000
[ 9.287871][ T1] R13: ffffffff8fd964c0 R14: ffff888026802040 R15: ffff888026802030
[ 9.287888][ T1] FS: 0000000000000000(0000) GS:ffff888125b69000(0000) knlGS:0000000000000000
[ 9.287906][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 9.287923][ T1] CR2: 0000000000000000 CR3: 000000000e1b0000 CR4: 00000000003526f0
[ 9.287942][ T1] Call Trace:
[ 9.287957][ T1] <TASK>
[ 9.287982][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 9.288026][ T1] drm_dev_register+0x7f/0xd80
[ 9.288197][ T1] vkms_create+0x40d/0x4f0
[ 9.288232][ T1] ? __pfx_vkms_init+0x10/0x10
[ 9.288272][ T1] vkms_init+0x57/0x80
[ 9.288307][ T1] do_one_initcall+0x250/0x870
[ 9.288334][ T1] ? __pfx_vkms_init+0x10/0x10
[ 9.288371][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 9.288396][ T1] ? ktime_get+0x1f5/0x220
[ 9.288430][ T1] ? clockevents_program_event+0x491/0x630
[ 9.288459][ T1] ? __pfx___schedule+0x10/0x10
[ 9.288513][ T1] ? irqentry_exit+0x218/0x8f0
[ 9.288544][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 9.288579][ T1] ? irqentry_exit+0x218/0x8f0
[ 9.288612][ T1] ? trace_irq_disable+0x3b/0x140
[ 9.288664][ T1] ? next_arg+0x4a0/0x5e0
[ 9.288690][ T1] ? parameq+0x14d/0x170
[ 9.288724][ T1] ? parse_args+0x9c3/0xad0
[ 9.288771][ T1] ? trace_kmalloc+0x2a/0xf0
[ 9.288803][ T1] ? rcu_is_watching+0x15/0xb0
[ 9.288831][ T1] do_initcall_level+0x10a/0x1a0
[ 9.288860][ T1] ? kernel_init+0x22/0x1d0
[ 9.288886][ T1] do_initcalls+0x59/0xa0
[ 9.288913][ T1] kernel_init_freeable+0x29d/0x3e0
[ 9.288939][ T1] ? __pfx_kernel_init+0x10/0x10
[ 9.288967][ T1] kernel_init+0x22/0x1d0
[ 9.288993][ T1] ? __pfx_kernel_init+0x10/0x10
[ 9.289018][ T1] ret_from_fork+0x514/0xb70
[ 9.289072][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 9.289099][ T1] ? __switch_to+0xc89/0x1420
[ 9.289217][ T1] ? __pfx_kernel_init+0x10/0x10
[ 9.289246][ T1] ret_from_fork_asm+0x1a/0x30
[ 9.289296][ T1] </TASK>
[ 9.289319][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 9.289336][ T1] CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 9.289363][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
[ 9.289376][ T1] Call Trace:
[ 9.289394][ T1] <TASK>
[ 9.289403][ T1] vpanic+0x56c/0xa60
[ 9.289437][ T1] ? __pfx__printk+0x10/0x10
[ 9.289460][ T1] ? __pfx_vpanic+0x10/0x10
[ 9.289491][ T1] ? is_bpf_text_address+0x292/0x2b0
[ 9.289513][ T1] ? is_bpf_text_address+0x26/0x2b0
[ 9.289541][ T1] panic+0xc5/0xd0
[ 9.289574][ T1] ? __pfx_panic+0x10/0x10
[ 9.289615][ T1] ? ret_from_fork_asm+0x1a/0x30
[ 9.289646][ T1] __warn+0x315/0x4c0
[ 9.289676][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 9.289707][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 9.289735][ T1] __report_bug+0x276/0x570
[ 9.289773][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 9.289802][ T1] ? __pfx___report_bug+0x10/0x10
[ 9.289844][ T1] ? _raw_spin_unlock_irqrestore+0x30/0x80
[ 9.289879][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 9.289914][ T1] ? rt_mutex_slowunlock+0x4ee/0xa20
[ 9.289945][ T1] report_bug_entry+0x19a/0x290
[ 9.289981][ T1] ? drm_mode_config_validate+0x1cae/0x1e60
[ 9.290008][ T1] ? drm_mode_config_validate+0x1cb3/0x1e60
[ 9.290042][ T1] handle_bug+0xce/0x200
[ 9.290067][ T1] exc_invalid_op+0x1a/0x50
[ 9.290090][ T1] asm_exc_invalid_op+0x1a/0x20
[ 9.290113][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 9.290142][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 fa b0 be fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 d6 55 52 fc 49 bd 00 00 00 00 00 fc ff df
[ 9.290161][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 9.290181][ T1] RAX: 1ffff11004d00408 RBX: dffffc0000000000 RCX: ffff88801c6e5d00
[ 9.290198][ T1] RDX: ffff8880263f9dc0 RSI: 0000000000000023 RDI: ffffffff8fd964c0
[ 9.290213][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 9.290226][ T1] R10: dffffc0000000000 R11: fffffbfff1f9c610 R12: dffffc0000000000
[ 9.290242][ T1] R13: ffffffff8fd964c0 R14: ffff888026802040 R15: ffff888026802030
[ 9.290303][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 9.290342][ T1] drm_dev_register+0x7f/0xd80
[ 9.290372][ T1] vkms_create+0x40d/0x4f0
[ 9.290405][ T1] ? __pfx_vkms_init+0x10/0x10
[ 9.290438][ T1] vkms_init+0x57/0x80
[ 9.290473][ T1] do_one_initcall+0x250/0x870
[ 9.290498][ T1] ? __pfx_vkms_init+0x10/0x10
[ 9.290532][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 9.290654][ T1] ? ktime_get+0x1f5/0x220
[ 9.290683][ T1] ? clockevents_program_event+0x491/0x630
[ 9.290707][ T1] ? __pfx___schedule+0x10/0x10
[ 9.290745][ T1] ? irqentry_exit+0x218/0x8f0
[ 9.290776][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 9.290811][ T1] ? irqentry_exit+0x218/0x8f0
[ 9.290843][ T1] ? trace_irq_disable+0x3b/0x140
[ 9.290894][ T1] ? next_arg+0x4a0/0x5e0
[ 9.290917][ T1] ? parameq+0x14d/0x170
[ 9.290951][ T1] ? parse_args+0x9c3/0xad0
[ 9.290998][ T1] ? trace_kmalloc+0x2a/0xf0
[ 9.291070][ T1] ? rcu_is_watching+0x15/0xb0
[ 9.291100][ T1] do_initcall_level+0x10a/0x1a0
[ 9.291288][ T1] ? kernel_init+0x22/0x1d0
[ 9.291320][ T1] do_initcalls+0x59/0xa0
[ 9.291359][ T1] kernel_init_freeable+0x29d/0x3e0
[ 9.291388][ T1] ? __pfx_kernel_init+0x10/0x10
[ 9.291419][ T1] kernel_init+0x22/0x1d0
[ 9.291446][ T1] ? __pfx_kernel_init+0x10/0x10
[ 9.291482][ T1] ret_from_fork+0x514/0xb70
[ 9.291516][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 9.291545][ T1] ? __switch_to+0xc89/0x1420
[ 9.291569][ T1] ? __pfx_kernel_init+0x10/0x10
[ 9.291596][ T1] ret_from_fork_asm+0x1a/0x30
[ 9.291636][ T1] </TASK>
[ 9.291899][ T1] Kernel Offset: disabled
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build721356953=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs-2/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at 00e8b0fd0d
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=00e8b0fd0d17bb06fe23c0e743356351ada78c22 -X github.com/google/syzkaller/prog.gitRevisionDate=20260630-130833" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=00e8b0fd0d17bb06fe23c0e743356351ada78c22 -X github.com/google/syzkaller/prog.gitRevisionDate=20260630-130833" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=00e8b0fd0d17bb06fe23c0e743356351ada78c22 -X github.com/google/syzkaller/prog.gitRevisionDate=20260630-130833" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"00e8b0fd0d17bb06fe23c0e743356351ada78c22\"
/usr/bin/ld: /tmp/ccMCDxTH.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=124c32b9580000
Tested on:
commit: 0718283a Add linux-next specific files for 20260717
git tree: linux-next
kernel config: https://syzkaller.appspot.com/x/.config?x=c45dee6227f09fbb
dashboard link: https://syzkaller.appspot.com/bug?extid=fb7c2dd166d3ea63df2a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=15f362b9580000
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [kvm-x86?] KASAN: use-after-free Read in kvm_setup_guest_pvclock
[not found] <DK3GW1EZ10DD.19P93MSB49ISS@igalia.com>
@ 2026-07-20 15:22 ` syzbot
0 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-07-20 15:22 UTC (permalink / raw)
To: halves, linux-kernel, syzkaller-bugs
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
lost connection to test machine
Tested on:
commit: 1590cf03 Linux 7.2-rc4
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=159ee2b9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=337c29be5df8a447
dashboard link: https://syzkaller.appspot.com/bug?extid=fb7c2dd166d3ea63df2a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=1021b789580000
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [kvm-x86?] KASAN: use-after-free Read in kvm_setup_guest_pvclock
[not found] <DK4AP9HEJ2ZC.13A6XWLH6AK6B@igalia.com>
@ 2026-07-21 14:40 ` syzbot
0 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-07-21 14:40 UTC (permalink / raw)
To: halves, linux-kernel, syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
0000:00:00.0: Limiting direct PCI/PCI transfers
[ 4.569474][ T1] PCI: CLS 0 bytes, default 64
[ 4.571889][ T1] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
[ 4.571911][ T1] software IO TLB: mapped [mem 0x00000000b4600000-0x00000000b8600000] (64MB)
[ 4.576668][ T1] ACPI: bus type thunderbolt registered
[ 4.604809][ T69] kworker/u8:4 (69) used greatest stack depth: 27824 bytes left
[ 4.605349][ T1] RAPL PMU: API unit is 2^-32 Joules, 0 fixed counters, 10737418240 ms ovfl timer
[ 4.667843][ T68] kworker/u8:3 (68) used greatest stack depth: 27600 bytes left
[ 4.693093][ T1] kvm_amd: CPU 0 isn't AMD or Hygon
[ 4.693126][ T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x1fb7086095e, max_idle_ns: 440795277026 ns
[ 4.693805][ T1] clocksource: Switched to clocksource tsc
[ 4.735937][ T78] kworker/u8:1 (78) used greatest stack depth: 27240 bytes left
[ 4.775502][ T1] Initialise system trusted keyrings
[ 4.776914][ T94] kworker/u8:4 (94) used greatest stack depth: 26856 bytes left
[ 4.778809][ T1] workingset: timestamp_bits=40 (anon: 35) max_order=21 bucket_order=0 (anon: 0)
[ 4.794347][ T1] DLM installed
[ 4.803270][ T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 4.820766][ T1] NFS: Registering the id_resolver key type
[ 4.820934][ T1] Key type id_resolver registered
[ 4.820948][ T1] Key type id_legacy registered
[ 4.821314][ T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[ 4.821516][ T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[ 4.828086][ T1] smbdirect: subsystem loading...
[ 4.842980][ T1] smbdirect: subsystem loaded
[ 4.891092][ T1] Key type cifs.spnego registered
[ 4.891558][ T1] Key type cifs.idmap registered
[ 4.906529][ T1] ntfs3: Enabled Linux POSIX ACLs support
[ 4.906543][ T1] ntfs3: Read-only LZX/Xpress compression included
[ 4.907114][ T1] jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
[ 4.911063][ T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[ 4.911761][ T1] QNX4 filesystem 0.2.3 registered.
[ 4.911930][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 4.913356][ T1] fuse: init (API version 7.45)
[ 4.922704][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 4.926315][ T1] orangefs_init: module version upstream loaded
[ 4.927651][ T1] JFS: nTxBlock = 8192, nTxLock = 65536
[ 4.944092][ T1] SGI XFS with ACLs, security attributes, realtime, quota, no debug enabled
[ 4.957411][ T1] 9p: Installing v9fs 9p2000 file system support
[ 4.991879][ T1] NILFS version 2 loaded
[ 4.991899][ T1] befs: version: 0.9.3
[ 4.993486][ T1] ocfs2: Registered cluster interface o2cb
[ 4.995705][ T1] ocfs2: Registered cluster interface user
[ 5.006868][ T1] OCFS2 User DLM kernel interface loaded
[ 5.046841][ T1] gfs2: GFS2 installed
[ 5.068429][ T1] ceph: loaded (mds proto 32)
[ 5.102190][ T1] NET: Registered PF_ALG protocol family
[ 5.103074][ T1] async_tx: api initialized (async)
[ 5.103141][ T1] Key type asymmetric registered
[ 5.103216][ T1] Asymmetric key parser 'x509' registered
[ 5.103231][ T1] Asymmetric key parser 'pkcs8' registered
[ 5.103244][ T1] Key type pkcs7_test registered
[ 5.105026][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 5.107338][ T1] io scheduler mq-deadline registered
[ 5.107356][ T1] io scheduler kyber registered
[ 5.107949][ T1] io scheduler bfq registered
[ 5.110066][ T1] raid6: skipped pq benchmark and selected avx2x4
[ 5.162638][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 5.164944][ T1] ACPI: button: Power Button [PWRF]
[ 5.167933][ T1] input: Sleep Button as /devices/platform/LNXSLPBN:00/input/input1
[ 5.172152][ T1] ACPI: button: Sleep Button [SLPF]
[ 5.227446][ T156] kworker/u8:3 (156) used greatest stack depth: 26464 bytes left
[ 5.249131][ T192] kworker/u8:7 (192) used greatest stack depth: 26184 bytes left
[ 5.258909][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 5.298972][ T10] ACPI: \_SB_.LNKC: Enabled at IRQ 11
[ 5.299187][ T10] virtio-pci 0000:00:03.0: virtio_pci: leaving for legacy driver
[ 5.343562][ T10] ACPI: \_SB_.LNKD: Enabled at IRQ 10
[ 5.343730][ T10] virtio-pci 0000:00:04.0: virtio_pci: leaving for legacy driver
[ 5.382813][ T10] ACPI: \_SB_.LNKB: Enabled at IRQ 10
[ 5.382940][ T10] virtio-pci 0000:00:06.0: virtio_pci: leaving for legacy driver
[ 5.411801][ T10] virtio-pci 0000:00:07.0: virtio_pci: leaving for legacy driver
[ 6.372357][ T1] N_HDLC line discipline registered with maxframe=4096
[ 6.375656][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 6.396359][ T1] 00:02: ttyS0 I/O:0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 6.424359][ T1] 00:03: ttyS1 I/O:0x2f8 (irq = 3, base_baud = 115200) is a 16550A
[ 6.452988][ T1] 00:04: ttyS2 I/O:0x3e8 (irq = 6, base_baud = 115200) is a 16550A
[ 6.479183][ T1] 00:05: ttyS3 I/O:0x2e8 (irq = 7, base_baud = 115200) is a 16550A
[ 6.531386][ T1] Non-volatile memory driver v1.3
[ 6.575265][ T1] usbcore: registered new interface driver xillyusb
[ 6.587434][ T1] ACPI: bus type drm_connector registered
[ 6.599051][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 6.607283][ T1] ------------[ cut here ]------------
[ 6.607294][ T1] [PLANE:35:plane-0] pixel format with alpha exposed but blend mode not setup
[ 6.607314][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6d/0x1e60, CPU#0: swapper/0/1
[ 6.607376][ T1] Modules linked in:
[ 6.607413][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 6.607432][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
[ 6.607449][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 6.607476][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 9a 8a be fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 b6 24 52 fc 49 bd 00 00 00 00 00 fc ff df
[ 6.607494][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 6.607516][ T1] RAX: 1ffff11004c7f408 RBX: dffffc0000000000 RCX: ffff88801c6e5d00
[ 6.607530][ T1] RDX: ffff8880262a51c0 RSI: 0000000000000023 RDI: ffffffff8fd973c0
[ 6.607543][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 6.607554][ T1] R10: dffffc0000000000 R11: fffffbfff1f9c7f0 R12: dffffc0000000000
[ 6.607568][ T1] R13: ffffffff8fd973c0 R14: ffff8880263fa040 R15: ffff8880263fa030
[ 6.607582][ T1] FS: 0000000000000000(0000) GS:ffff888125a66000(0000) knlGS:0000000000000000
[ 6.607597][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 6.607608][ T1] CR2: ffff88823ffff000 CR3: 000000000e1b0000 CR4: 00000000003526f0
[ 6.607623][ T1] Call Trace:
[ 6.607634][ T1] <TASK>
[ 6.607659][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 6.607689][ T1] drm_dev_register+0x7f/0xd80
[ 6.607719][ T1] vkms_create+0x40d/0x4f0
[ 6.607741][ T1] ? __pfx_vkms_init+0x10/0x10
[ 6.607769][ T1] vkms_init+0x57/0x80
[ 6.607791][ T1] do_one_initcall+0x250/0x870
[ 6.607811][ T1] ? __pfx_vkms_init+0x10/0x10
[ 6.607834][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 6.607867][ T1] ? __pfx___schedule+0x10/0x10
[ 6.607905][ T1] ? irqentry_exit+0x218/0x8f0
[ 6.607926][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 6.607947][ T1] ? irqentry_exit+0x218/0x8f0
[ 6.607966][ T1] ? trace_irq_disable+0x3b/0x140
[ 6.608002][ T1] ? parameq+0x14d/0x170
[ 6.608028][ T1] ? parse_args+0x9c3/0xad0
[ 6.608065][ T1] ? trace_kmalloc+0x2a/0xf0
[ 6.608089][ T1] ? rcu_is_watching+0x15/0xb0
[ 6.608111][ T1] do_initcall_level+0x10a/0x1a0
[ 6.608138][ T1] ? kernel_init+0x22/0x1d0
[ 6.608163][ T1] do_initcalls+0x59/0xa0
[ 6.608189][ T1] kernel_init_freeable+0x29d/0x3e0
[ 6.608214][ T1] ? __pfx_kernel_init+0x10/0x10
[ 6.608239][ T1] kernel_init+0x22/0x1d0
[ 6.608262][ T1] ? __pfx_kernel_init+0x10/0x10
[ 6.608284][ T1] ret_from_fork+0x514/0xb70
[ 6.608308][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 6.608329][ T1] ? __switch_to+0xc89/0x1420
[ 6.608347][ T1] ? __pfx_kernel_init+0x10/0x10
[ 6.608373][ T1] ret_from_fork_asm+0x1a/0x30
[ 6.608405][ T1] </TASK>
[ 6.608426][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 6.608438][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 6.608458][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
[ 6.608467][ T1] Call Trace:
[ 6.608474][ T1] <TASK>
[ 6.608481][ T1] vpanic+0x56c/0xa60
[ 6.608512][ T1] ? __pfx__printk+0x10/0x10
[ 6.608530][ T1] ? __pfx_vpanic+0x10/0x10
[ 6.608550][ T1] ? is_bpf_text_address+0x292/0x2b0
[ 6.608567][ T1] ? is_bpf_text_address+0x26/0x2b0
[ 6.608593][ T1] panic+0xc5/0xd0
[ 6.608615][ T1] ? __pfx_panic+0x10/0x10
[ 6.608646][ T1] ? ret_from_fork_asm+0x1a/0x30
[ 6.608671][ T1] __warn+0x315/0x4c0
[ 6.608692][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 6.608721][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 6.608745][ T1] __report_bug+0x276/0x570
[ 6.608771][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 6.608800][ T1] ? __pfx___report_bug+0x10/0x10
[ 6.608826][ T1] ? _raw_spin_unlock_irqrestore+0x30/0x80
[ 6.608848][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 6.608871][ T1] ? rt_mutex_slowunlock+0x4ee/0xa20
[ 6.608892][ T1] report_bug_entry+0x19a/0x290
[ 6.608914][ T1] ? drm_mode_config_validate+0x1cae/0x1e60
[ 6.608938][ T1] ? drm_mode_config_validate+0x1cb3/0x1e60
[ 6.608962][ T1] handle_bug+0xce/0x200
[ 6.608985][ T1] exc_invalid_op+0x1a/0x50
[ 6.609007][ T1] asm_exc_invalid_op+0x1a/0x20
[ 6.609025][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 6.609050][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 9a 8a be fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 b6 24 52 fc 49 bd 00 00 00 00 00 fc ff df
[ 6.609064][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 6.609078][ T1] RAX: 1ffff11004c7f408 RBX: dffffc0000000000 RCX: ffff88801c6e5d00
[ 6.609092][ T1] RDX: ffff8880262a51c0 RSI: 0000000000000023 RDI: ffffffff8fd973c0
[ 6.609105][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 6.609116][ T1] R10: dffffc0000000000 R11: fffffbfff1f9c7f0 R12: dffffc0000000000
[ 6.609129][ T1] R13: ffffffff8fd973c0 R14: ffff8880263fa040 R15: ffff8880263fa030
[ 6.609167][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 6.609195][ T1] drm_dev_register+0x7f/0xd80
[ 6.609224][ T1] vkms_create+0x40d/0x4f0
[ 6.609245][ T1] ? __pfx_vkms_init+0x10/0x10
[ 6.609267][ T1] vkms_init+0x57/0x80
[ 6.609289][ T1] do_one_initcall+0x250/0x870
[ 6.609309][ T1] ? __pfx_vkms_init+0x10/0x10
[ 6.609332][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 6.609366][ T1] ? __pfx___schedule+0x10/0x10
[ 6.609396][ T1] ? irqentry_exit+0x218/0x8f0
[ 6.609416][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 6.609437][ T1] ? irqentry_exit+0x218/0x8f0
[ 6.609456][ T1] ? trace_irq_disable+0x3b/0x140
[ 6.609493][ T1] ? parameq+0x14d/0x170
[ 6.609516][ T1] ? parse_args+0x9c3/0xad0
[ 6.609516][ T1] ? trace_kmalloc+0x2a/0xf0
[ 6.609516][ T1] ? rcu_is_watching+0x15/0xb0
[ 6.609516][ T1] do_initcall_level+0x10a/0x1a0
[ 6.609516][ T1] ? kernel_init+0x22/0x1d0
[ 6.609516][ T1] do_initcalls+0x59/0xa0
[ 6.609516][ T1] kernel_init_freeable+0x29d/0x3e0
[ 6.609516][ T1] ? __pfx_kernel_init+0x10/0x10
[ 6.609516][ T1] kernel_init+0x22/0x1d0
[ 6.609516][ T1] ? __pfx_kernel_init+0x10/0x10
[ 6.609516][ T1] ret_from_fork+0x514/0xb70
[ 6.609516][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 6.609516][ T1] ? __switch_to+0xc89/0x1420
[ 6.609516][ T1] ? __pfx_kernel_init+0x10/0x10
[ 6.609516][ T1] ret_from_fork_asm+0x1a/0x30
[ 6.609516][ T1] </TASK>
[ 6.609516][ T1] Kernel Offset: disabled
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build3991592182=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at 00e8b0fd0d
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=00e8b0fd0d17bb06fe23c0e743356351ada78c22 -X github.com/google/syzkaller/prog.gitRevisionDate=20260630-130833" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=00e8b0fd0d17bb06fe23c0e743356351ada78c22 -X github.com/google/syzkaller/prog.gitRevisionDate=20260630-130833" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=00e8b0fd0d17bb06fe23c0e743356351ada78c22 -X github.com/google/syzkaller/prog.gitRevisionDate=20260630-130833" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"00e8b0fd0d17bb06fe23c0e743356351ada78c22\"
/usr/bin/ld: /tmp/ccOIdA2r.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=10d692b9580000
Tested on:
commit: 3fe08b97 Add linux-next specific files for 20260720
git tree: linux-next
kernel config: https://syzkaller.appspot.com/x/.config?x=65d6389adb1eb707
dashboard link: https://syzkaller.appspot.com/bug?extid=fb7c2dd166d3ea63df2a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Note: no patches were applied.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [kvm-x86?] KASAN: use-after-free Read in kvm_setup_guest_pvclock
[not found] <DK582SQ6WP0Q.O9P9KPEGWJQ0@igalia.com>
@ 2026-07-22 18:37 ` syzbot
0 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-07-22 18:37 UTC (permalink / raw)
To: halves, linux-kernel, syzkaller-bugs
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
lost connection to test machine
Tested on:
commit: b4515cf4 Add linux-next specific files for 20260722
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=15b78099580000
kernel config: https://syzkaller.appspot.com/x/.config?x=11d45755069d7236
dashboard link: https://syzkaller.appspot.com/bug?extid=fb7c2dd166d3ea63df2a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=16862ab9580000
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-07-22 18:37 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <DK4AP9HEJ2ZC.13A6XWLH6AK6B@igalia.com>
2026-07-21 14:40 ` [syzbot] [kvm-x86?] KASAN: use-after-free Read in kvm_setup_guest_pvclock syzbot
[not found] <DK582SQ6WP0Q.O9P9KPEGWJQ0@igalia.com>
2026-07-22 18:37 ` syzbot
[not found] <DK3GW1EZ10DD.19P93MSB49ISS@igalia.com>
2026-07-20 15:22 ` syzbot
[not found] <DK3EXQESFKHR.1JMHKZ0ADMVVR@igalia.com>
2026-07-20 13:53 ` syzbot
2026-06-29 13:06 syzbot
2026-06-30 20:10 ` syzbot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.