From: syzbot <syzbot+1f4e278e8e1a9b01f95f@syzkaller.appspotmail.com>
To: gregkh@linuxfoundation.org, kriish.sharma2006@gmail.com,
linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
rafael@kernel.org, syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [kernel?] general protection fault in device_move
Date: Fri, 07 Aug 2026 06:56:34 -0700 [thread overview]
Message-ID: <6a75e412.01d0871a.3a0d52.0049.GAE@google.com> (raw)
In-Reply-To: <673e3029.050a0220.363a1b.0024.GAE@google.com>
syzbot has found a reproducer for the following issue on:
HEAD commit: f9a2394a2348 Merge tag 'mm-hotfixes-stable-2026-08-06-18-4..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=101a02c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=86ba763b42fa66a
dashboard link: https://syzkaller.appspot.com/bug?extid=1f4e278e8e1a9b01f95f
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=170d0fb9580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1f4e278e8e1a9b01f95f@syzkaller.appspotmail.com
Oops: general protection fault, probably for non-canonical address 0xdffffc000000000b: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000058-0x000000000000005f]
CPU: 1 UID: 0 PID: 4943 Comm: kworker/u9:1 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: hci0 hci_rx_work
RIP: 0010:klist_put lib/klist.c:212 [inline]
RIP: 0010:klist_del lib/klist.c:230 [inline]
RIP: 0010:klist_remove+0x156/0x340 lib/klist.c:249
Code: 4d 89 f5 49 c1 ed 03 43 80 7c 3d 00 00 74 08 4c 89 f7 e8 8d 64 84 f6 4d 8b 26 49 83 e4 fe 49 8d 7c 24 58 48 89 f8 48 c1 e8 03 <42> 80 3c 38 00 74 05 e8 6e 64 84 f6 49 8b 44 24 58 48 89 44 24 08
RSP: 0018:ffffc9000fc87700 EFLAGS: 00010202
RAX: 000000000000000b RBX: ffff888035a90000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000058
RBP: ffffc9000fc877e8 R08: ffffffff90199ae3 R09: 1ffffffff203335c
R10: dffffc0000000000 R11: fffffbfff203335d R12: 0000000000000000
R13: 1ffff1100e64e20c R14: ffff888073271060 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff888125306000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f4691400c30 CR3: 00000000750f0000 CR4: 00000000003526f0
Call Trace:
<TASK>
device_move+0x18e/0x720 drivers/base/core.c:4698
hci_conn_del_sysfs+0xb8/0x1a0 net/bluetooth/hci_sysfs.c:75
hci_conn_cleanup net/bluetooth/hci_conn.c:170 [inline]
hci_conn_del+0xc3d/0x1200 net/bluetooth/hci_conn.c:1308
hci_disconn_complete_evt+0x5ac/0x890 net/bluetooth/hci_event.c:3470
hci_event_func net/bluetooth/hci_event.c:7784 [inline]
hci_event_packet+0x6cd/0xf10 net/bluetooth/hci_event.c:7835
hci_rx_work+0x3ee/0x1020 net/bluetooth/hci_core.c:4039
process_one_work kernel/workqueue.c:3322 [inline]
process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:klist_put lib/klist.c:212 [inline]
RIP: 0010:klist_del lib/klist.c:230 [inline]
RIP: 0010:klist_remove+0x156/0x340 lib/klist.c:249
Code: 4d 89 f5 49 c1 ed 03 43 80 7c 3d 00 00 74 08 4c 89 f7 e8 8d 64 84 f6 4d 8b 26 49 83 e4 fe 49 8d 7c 24 58 48 89 f8 48 c1 e8 03 <42> 80 3c 38 00 74 05 e8 6e 64 84 f6 49 8b 44 24 58 48 89 44 24 08
RSP: 0018:ffffc9000fc87700 EFLAGS: 00010202
RAX: 000000000000000b RBX: ffff888035a90000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000058
RBP: ffffc9000fc877e8 R08: ffffffff90199ae3 R09: 1ffffffff203335c
R10: dffffc0000000000 R11: fffffbfff203335d R12: 0000000000000000
R13: 1ffff1100e64e20c R14: ffff888073271060 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff888125306000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f4691400c30 CR3: 000000007e68e000 CR4: 00000000003526f0
----------------
Code disassembly (best guess):
0: 4d 89 f5 mov %r14,%r13
3: 49 c1 ed 03 shr $0x3,%r13
7: 43 80 7c 3d 00 00 cmpb $0x0,0x0(%r13,%r15,1)
d: 74 08 je 0x17
f: 4c 89 f7 mov %r14,%rdi
12: e8 8d 64 84 f6 call 0xf68464a4
17: 4d 8b 26 mov (%r14),%r12
1a: 49 83 e4 fe and $0xfffffffffffffffe,%r12
1e: 49 8d 7c 24 58 lea 0x58(%r12),%rdi
23: 48 89 f8 mov %rdi,%rax
26: 48 c1 e8 03 shr $0x3,%rax
* 2a: 42 80 3c 38 00 cmpb $0x0,(%rax,%r15,1) <-- trapping instruction
2f: 74 05 je 0x36
31: e8 6e 64 84 f6 call 0xf68464a4
36: 49 8b 44 24 58 mov 0x58(%r12),%rax
3b: 48 89 44 24 08 mov %rax,0x8(%rsp)
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
next prev parent reply other threads:[~2026-08-07 13:56 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-20 18:53 [syzbot] [kernel?] general protection fault in device_move syzbot
2024-12-21 19:34 ` syzbot
2025-09-24 6:46 ` Forwarded: upstream test syzbot
2026-08-07 13:56 ` syzbot [this message]
[not found] <CAL4kbRPJhQq7r8Ts_iuqW0c=__eWgdYvVmBLCx+DCj8RkEEf=Q@mail.gmail.com>
2025-09-24 7:23 ` [syzbot] [kernel?] general protection fault in device_move syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a75e412.01d0871a.3a0d52.0049.GAE@google.com \
--to=syzbot+1f4e278e8e1a9b01f95f@syzkaller.appspotmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=kriish.sharma2006@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=rafael@kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.