From: syzbot <syzbot+8496ab5e117502750445@syzkaller.appspotmail.com>
To: khiemtranzo532001@gmail.com, linux-kernel@vger.kernel.org,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [usb?] WARNING: refcount bug in trace_suspend_resume (2)
Date: Mon, 10 Aug 2026 22:12:03 -0700 [thread overview]
Message-ID: <6a7aaf23.01d0871a.3a0d52.00be.GAE@google.com> (raw)
In-Reply-To: <6a7aa9c4.c4d3d80a.193916.4813@mx.google.com>
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
WARNING: refcount bug in trace_suspend_resume
udc dummy_udc.1: failed to start USB Gadget filesystem: -12
gadgetfs gadget.1: probe with driver gadgetfs failed with error -12
UDC core: USB Gadget filesystem: couldn't find an available UDC
------------[ cut here ]------------
WARNING: lib/refcount.c:28 at refcount_warn_saturate+0x134/0x170 lib/refcount.c:28, CPU#1: syz.2.17/5117
refcount_t: underflow; use-after-free.
Modules linked in:
Kernel panic - not syncing: kernel: panic_on_warn set ...
CPU: 1 UID: 0 PID: 5117 Comm: syz.2.17 Not tainted syzkaller #0 PREEMPT
Hardware name: ARM-Versatile Express
Call trace:
[<80201998>] (dump_backtrace) from [<80201a8c>] (show_stack+0x18/0x1c arch/arm/kernel/traps.c:257)
r7:82a20f78 r6:00000000 r5:823338f8 r4:00000001
[<80201a74>] (show_stack) from [<8021e5b8>] (__dump_stack lib/dump_stack.c:94 [inline])
[<80201a74>] (show_stack) from [<8021e5b8>] (dump_stack_lvl+0x5c/0x70 lib/dump_stack.c:120)
[<8021e55c>] (dump_stack_lvl) from [<8021e5e4>] (dump_stack+0x18/0x1c lib/dump_stack.c:129)
r7:82a20f78 r6:00000000 r5:84166e40 r4:82c82d40
[<8021e5cc>] (dump_stack) from [<80202590>] (vpanic+0x114/0x320 kernel/panic.c:651)
[<8020247c>] (vpanic) from [<802027d0>] (trace_suspend_resume+0x0/0x100 kernel/panic.c:788)
r7:8092f5a8
[<8020279c>] (panic) from [<80250a80>] (check_panic_on_warn kernel/panic.c:525 [inline])
[<8020279c>] (panic) from [<80250a80>] (get_taint+0x0/0x1c kernel/panic.c:520)
r3:82a0b144 r2:00000001 r1:8231965c r0:82320fb8
[<80250a08>] (check_panic_on_warn) from [<80250bfc>] (__warn+0x98/0x1a4 kernel/panic.c:1104)
[<80250b64>] (__warn) from [<80250ef0>] (warn_slowpath_fmt+0x1e8/0x1f4 kernel/panic.c:1144)
r8:00000009 r7:8238d554 r6:dfa09da4 r5:84166e40 r4:00000000
[<80250d0c>] (warn_slowpath_fmt) from [<8092f5a8>] (refcount_warn_saturate+0x134/0x170 lib/refcount.c:28)
r10:850839c0 r9:00000000 r8:830e9c10 r7:8346cc00 r6:85e35660 r5:00000000
r4:8550ca00
[<8092f474>] (refcount_warn_saturate) from [<8111fd0c>] (__refcount_sub_and_test include/linux/refcount.h:400 [inline])
[<8092f474>] (refcount_warn_saturate) from [<8111fd0c>] (__refcount_dec_and_test include/linux/refcount.h:432 [inline])
[<8092f474>] (refcount_warn_saturate) from [<8111fd0c>] (refcount_dec_and_test include/linux/refcount.h:450 [inline])
[<8092f474>] (refcount_warn_saturate) from [<8111fd0c>] (put_dev+0x4c/0x6c drivers/usb/gadget/legacy/inode.c:165)
[<8111fcc0>] (put_dev) from [<8111fdd4>] (dev_release+0x48/0x6c drivers/usb/gadget/legacy/inode.c:1224)
[<8111fd8c>] (dev_release) from [<805a168c>] (__fput+0xd8/0x2f4 fs/file_table.c:512)
r5:040f801b r4:83981480
[<805a15b4>] (__fput) from [<805a193c>] (____fput+0x14/0x18 fs/file_table.c:540)
r9:00000000 r8:841676d4 r7:82c836ac r6:84166e40 r5:841676a0 r4:00000000
[<805a1928>] (____fput) from [<8027d7c8>] (task_work_run+0x8c/0xb4 kernel/task_work.c:233)
[<8027d73c>] (task_work_run) from [<80257888>] (exit_task_work include/linux/task_work.h:40 [inline])
[<8027d73c>] (task_work_run) from [<80257888>] (do_exit+0x2ac/0xadc kernel/exit.c:1009)
r9:00000000 r8:dfa09e90 r7:841676d0 r6:84ff1d4c r5:84166e40 r4:84ff1c00
[<802575dc>] (do_exit) from [<8025828c>] (do_group_exit+0x40/0x8c kernel/exit.c:1152)
r7:00000004
[<8025824c>] (do_group_exit) from [<80269358>] (get_signal+0xa68/0xa90 kernel/signal.c:3046)
r7:00000004 r4:84166e40
[<802688f0>] (get_signal) from [<8022a630>] (do_signal arch/arm/kernel/signal.c:579 [inline])
[<802688f0>] (get_signal) from [<8022a630>] (do_work_pending+0x124/0x4f0 arch/arm/kernel/signal.c:619)
r10:00000004 r9:84166e40 r8:0000001f r7:00000004 r6:8020029c r5:dfa09fb0
r4:84166e40
[<8022a50c>] (do_work_pending) from [<80200088>] (slow_work_pending+0xc/0x24)
Exception stack(0xdfa09fb0 to 0xdfa09ff8)
9fa0: 0000001f 20000400 0000001f 00000000
9fc0: 00000000 00000000 00356310 00000004 003562d8 00000000 00000001 76f4f0dc
9fe0: 76f4ee88 76f4ee78 00018fa0 001309d0 60000010 00000003
r10:00000004 r9:84166e40 r8:8020029c r7:00000004 r6:00356310 r5:00000000
r4:00000000
Rebooting in 86400 seconds..
Tested on:
commit: 5d5fd841 Merge 7.2-rc5 into usb-next
git tree: https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-next
console output: https://syzkaller.appspot.com/x/log.txt?x=162dca9e580000
kernel config: https://syzkaller.appspot.com/x/.config?x=db7ba9edb9755fc1
dashboard link: https://syzkaller.appspot.com/bug?extid=8496ab5e117502750445
compiler: arm-linux-gnueabi-gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
userspace arch: arm
patch: https://syzkaller.appspot.com/x/patch.diff?x=132112c6580000
next parent reply other threads:[~2026-08-11 5:12 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <6a7aa9c4.c4d3d80a.193916.4813@mx.google.com>
2026-08-11 5:12 ` syzbot [this message]
[not found] <6a7ab147.dbb26164.13295f.f9f9@mx.google.com>
2026-08-11 6:05 ` [syzbot] [usb?] WARNING: refcount bug in trace_suspend_resume (2) syzbot
2026-08-09 19:13 syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a7aaf23.01d0871a.3a0d52.00be.GAE@google.com \
--to=syzbot+8496ab5e117502750445@syzkaller.appspotmail.com \
--cc=khiemtranzo532001@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.