All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+b72767277f29b6407083@syzkaller.appspotmail.com>
To: bridge@lists.linux.dev, davem@davemloft.net, edumazet@google.com,
	 horms@kernel.org, idosch@nvidia.com, kuba@kernel.org,
	 linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
	pabeni@redhat.com,  razor@blackwall.org,
	syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [bridge?] KASAN: use-after-free Read in filemap_map_pages
Date: Sat, 15 Aug 2026 05:51:23 -0700	[thread overview]
Message-ID: <6a8060cb.5ca1970b.32aa76.0008.GAE@google.com> (raw)
In-Reply-To: <6a1d714e.c1435f33.295d1e.2a35.GAE@google.com>

syzbot has found a reproducer for the following issue on:

HEAD commit:    15ef2f78c49d Merge tag 'input-for-v7.2-rc7' of git://git.k..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=11cfe279580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=1d67342c314f228d
dashboard link: https://syzkaller.appspot.com/bug?extid=b72767277f29b6407083
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=15cfe279580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b72767277f29b6407083@syzkaller.appspotmail.com

==================================================================
BUG: KASAN: use-after-free in ptep_get include/linux/pgtable.h:495 [inline]
BUG: KASAN: use-after-free in filemap_map_folio_range mm/filemap.c:3820 [inline]
BUG: KASAN: use-after-free in filemap_map_pages+0x1b75/0x1f80 mm/filemap.c:3955
Read of size 8 at addr ffff88803f851a00 by task syz-executor403/6035

CPU: 2 UID: 0 PID: 6035 Comm: syz-executor403 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
 print_address_description mm/kasan/report.c:378 [inline]
 print_report+0x13d/0x4b0 mm/kasan/report.c:482
 kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
 ptep_get include/linux/pgtable.h:495 [inline]
 filemap_map_folio_range mm/filemap.c:3820 [inline]
 filemap_map_pages+0x1b75/0x1f80 mm/filemap.c:3955
 do_fault_around mm/memory.c:5818 [inline]
 do_read_fault mm/memory.c:5851 [inline]
 do_fault+0x985/0x1750 mm/memory.c:5994
 do_pte_missing mm/memory.c:4566 [inline]
 handle_pte_fault mm/memory.c:6379 [inline]
 __handle_mm_fault+0x187d/0x2a00 mm/memory.c:6517
 handle_mm_fault+0x37b/0xa30 mm/memory.c:6686
 do_user_addr_fault+0x74c/0x12f0 arch/x86/mm/fault.c:1394
 handle_page_fault arch/x86/mm/fault.c:1483 [inline]
 exc_page_fault+0x6f/0xd0 arch/x86/mm/fault.c:1536
 asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:595
RIP: 0010:fault_in_readable+0xde/0x190 mm/gup.c:2161
Code: 68 46 ae ff 4c 89 f0 48 85 c0 0f 85 bf 00 00 00 e8 77 4c ae ff 0f 01 cb 0f ae e8 4c 89 fb 4d 85 ff 75 31 eb 48 e8 62 4c ae ff <44> 8a 33 e8 5a 4c ae ff 48 81 c3 00 10 00 00 31 ff 48 81 e3 00 f0
RSP: 0018:ffffc90003a87af8 EFLAGS: 00050293
RAX: 0000000000000000 RBX: 00007fe62c200000 RCX: ffffffff825c2758
RDX: ffff888033b84a80 RSI: ffffffff825c271e RDI: ffff888033b84a80
RBP: 00007fe62c200001 R08: 0000000000000006 R09: 00007fe62c200001
R10: 00007fe62c200000 R11: 0000000000000000 R12: 0000000000000001
R13: 1ffff92000750f60 R14: 0000000000000000 R15: 00007fe62c200000
 fault_in_iov_iter_readable+0x101/0x2c0 lib/iov_iter.c:106
 generic_perform_write+0x863/0xa40 mm/filemap.c:4413
 shmem_file_write_iter+0x10e/0x140 mm/shmem.c:3424
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x6ac/0x1050 fs/read_write.c:687
 ksys_pwrite64 fs/read_write.c:794 [inline]
 __do_sys_pwrite64 fs/read_write.c:802 [inline]
 __se_sys_pwrite64 fs/read_write.c:799 [inline]
 __x64_sys_pwrite64+0x1eb/0x250 fs/read_write.c:799
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe62c7fce5e
Code: 08 0f 85 f5 e2 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 90 41 57 41 56 4d 89 c6 41 55 4d 89 cd 41 54 55 53 48 83 ec 08
RSP: 002b:00007fe62b9fe1a8 EFLAGS: 00000246 ORIG_RAX: 0000000000000012
RAX: ffffffffffffffda RBX: 00007fe62b9fe6c0 RCX: 00007fe62c7fce5e
RDX: 0000000000000001 RSI: 00007fe62c200000 RDI: 0000000000000003
RBP: 0000000000000021 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffffd0
R13: 0000000000000000 R14: 00007ffdde346d90 R15: 00007ffdde346e78
 </TASK>

The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff888000000000 pfn:0x3f851
flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000000 dead000000000100 dead000000000122 0000000000000000
raw: ffff888000000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 0, migratetype Unmovable, gfp_mask 0x440dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO|__GFP_COMP), pid 6004, tgid 6004 (cmp), ts 79653237963, free_ts 79740307238
 set_page_owner include/linux/page_owner.h:32 [inline]
 post_alloc_hook+0xfd/0x120 mm/page_alloc.c:1859
 prep_new_page mm/page_alloc.c:1867 [inline]
 get_page_from_freelist+0xf48/0x3530 mm/page_alloc.c:3946
 __alloc_frozen_pages_noprof+0x299/0x2dc0 mm/page_alloc.c:5304
 alloc_pages_mpol+0x1fb/0x540 mm/mempolicy.c:2490
 alloc_pages_noprof+0x1a/0x160 mm/mempolicy.c:2581
 pagetable_alloc_noprof include/linux/mm.h:3685 [inline]
 pmd_alloc_one_noprof include/asm-generic/pgalloc.h:143 [inline]
 __pmd_alloc+0x3b/0x950 mm/memory.c:6772
 pmd_alloc include/linux/mm.h:3601 [inline]
 __handle_mm_fault+0xa9c/0x2a00 mm/memory.c:6469
 handle_mm_fault+0x37b/0xa30 mm/memory.c:6686
 do_user_addr_fault+0x5a3/0x12f0 arch/x86/mm/fault.c:1343
 handle_page_fault arch/x86/mm/fault.c:1483 [inline]
 exc_page_fault+0x6f/0xd0 arch/x86/mm/fault.c:1536
 asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:595
page last free pid 6002 tgid 6002 stack trace:
 reset_page_owner include/linux/page_owner.h:25 [inline]
 __free_pages_prepare mm/page_alloc.c:1406 [inline]
 __free_frozen_pages+0x79f/0x1090 mm/page_alloc.c:2950
 __pagetable_free include/linux/mm.h:3695 [inline]
 pagetable_free include/linux/mm.h:3719 [inline]
 pagetable_dtor_free include/linux/mm.h:3818 [inline]
 __tlb_remove_table include/asm-generic/tlb.h:221 [inline]
 __tlb_remove_table_free mm/mmu_gather.c:228 [inline]
 tlb_remove_table_rcu+0x2cf/0x380 mm/mmu_gather.c:291
 rcu_do_batch kernel/rcu/tree.c:2645 [inline]
 rcu_core+0x5a2/0x10d0 kernel/rcu/tree.c:2897
 handle_softirqs+0x1ea/0x9b0 kernel/softirq.c:622
 __do_softirq kernel/softirq.c:656 [inline]
 invoke_softirq kernel/softirq.c:496 [inline]
 __irq_exit_rcu+0x162/0x210 kernel/softirq.c:735
 irq_exit_rcu+0x9/0x30 kernel/softirq.c:752
 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
 sysvec_apic_timer_interrupt+0xa3/0xc0 arch/x86/kernel/apic/apic.c:1062
 asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674

Memory state around the buggy address:
 ffff88803f851900: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
 ffff88803f851980: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88803f851a00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                   ^
 ffff88803f851a80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
 ffff88803f851b00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
----------------
Code disassembly (best guess):
   0:	68 46 ae ff 4c       	push   $0x4cffae46
   5:	89 f0                	mov    %esi,%eax
   7:	48 85 c0             	test   %rax,%rax
   a:	0f 85 bf 00 00 00    	jne    0xcf
  10:	e8 77 4c ae ff       	call   0xffae4c8c
  15:	0f 01 cb             	stac
  18:	0f ae e8             	lfence
  1b:	4c 89 fb             	mov    %r15,%rbx
  1e:	4d 85 ff             	test   %r15,%r15
  21:	75 31                	jne    0x54
  23:	eb 48                	jmp    0x6d
  25:	e8 62 4c ae ff       	call   0xffae4c8c
* 2a:	44 8a 33             	mov    (%rbx),%r14b <-- trapping instruction
  2d:	e8 5a 4c ae ff       	call   0xffae4c8c
  32:	48 81 c3 00 10 00 00 	add    $0x1000,%rbx
  39:	31 ff                	xor    %edi,%edi
  3b:	48                   	rex.W
  3c:	81                   	.byte 0x81
  3d:	e3 00                	jrcxz  0x3f
  3f:	f0                   	lock


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

  reply	other threads:[~2026-08-15 12:51 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-01 11:47 [syzbot] [net?] KASAN: use-after-free Read in filemap_map_pages syzbot
2026-08-15 12:51 ` syzbot [this message]
2026-08-16  2:17   ` [syzbot] [bridge?] " Hillf Danton
2026-08-16  2:34     ` syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a8060cb.5ca1970b.32aa76.0008.GAE@google.com \
    --to=syzbot+b72767277f29b6407083@syzkaller.appspotmail.com \
    --cc=bridge@lists.linux.dev \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=razor@blackwall.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.