From: syzbot <syzbot+b72767277f29b6407083@syzkaller.appspotmail.com>
To: bridge@lists.linux.dev, davem@davemloft.net, edumazet@google.com,
horms@kernel.org, idosch@nvidia.com, kuba@kernel.org,
linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
pabeni@redhat.com, razor@blackwall.org,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [bridge?] KASAN: use-after-free Read in filemap_map_pages
Date: Sat, 15 Aug 2026 05:51:23 -0700 [thread overview]
Message-ID: <6a8060cb.5ca1970b.32aa76.0008.GAE@google.com> (raw)
In-Reply-To: <6a1d714e.c1435f33.295d1e.2a35.GAE@google.com>
syzbot has found a reproducer for the following issue on:
HEAD commit: 15ef2f78c49d Merge tag 'input-for-v7.2-rc7' of git://git.k..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=11cfe279580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1d67342c314f228d
dashboard link: https://syzkaller.appspot.com/bug?extid=b72767277f29b6407083
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15cfe279580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b72767277f29b6407083@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: use-after-free in ptep_get include/linux/pgtable.h:495 [inline]
BUG: KASAN: use-after-free in filemap_map_folio_range mm/filemap.c:3820 [inline]
BUG: KASAN: use-after-free in filemap_map_pages+0x1b75/0x1f80 mm/filemap.c:3955
Read of size 8 at addr ffff88803f851a00 by task syz-executor403/6035
CPU: 2 UID: 0 PID: 6035 Comm: syz-executor403 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0x13d/0x4b0 mm/kasan/report.c:482
kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
ptep_get include/linux/pgtable.h:495 [inline]
filemap_map_folio_range mm/filemap.c:3820 [inline]
filemap_map_pages+0x1b75/0x1f80 mm/filemap.c:3955
do_fault_around mm/memory.c:5818 [inline]
do_read_fault mm/memory.c:5851 [inline]
do_fault+0x985/0x1750 mm/memory.c:5994
do_pte_missing mm/memory.c:4566 [inline]
handle_pte_fault mm/memory.c:6379 [inline]
__handle_mm_fault+0x187d/0x2a00 mm/memory.c:6517
handle_mm_fault+0x37b/0xa30 mm/memory.c:6686
do_user_addr_fault+0x74c/0x12f0 arch/x86/mm/fault.c:1394
handle_page_fault arch/x86/mm/fault.c:1483 [inline]
exc_page_fault+0x6f/0xd0 arch/x86/mm/fault.c:1536
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:595
RIP: 0010:fault_in_readable+0xde/0x190 mm/gup.c:2161
Code: 68 46 ae ff 4c 89 f0 48 85 c0 0f 85 bf 00 00 00 e8 77 4c ae ff 0f 01 cb 0f ae e8 4c 89 fb 4d 85 ff 75 31 eb 48 e8 62 4c ae ff <44> 8a 33 e8 5a 4c ae ff 48 81 c3 00 10 00 00 31 ff 48 81 e3 00 f0
RSP: 0018:ffffc90003a87af8 EFLAGS: 00050293
RAX: 0000000000000000 RBX: 00007fe62c200000 RCX: ffffffff825c2758
RDX: ffff888033b84a80 RSI: ffffffff825c271e RDI: ffff888033b84a80
RBP: 00007fe62c200001 R08: 0000000000000006 R09: 00007fe62c200001
R10: 00007fe62c200000 R11: 0000000000000000 R12: 0000000000000001
R13: 1ffff92000750f60 R14: 0000000000000000 R15: 00007fe62c200000
fault_in_iov_iter_readable+0x101/0x2c0 lib/iov_iter.c:106
generic_perform_write+0x863/0xa40 mm/filemap.c:4413
shmem_file_write_iter+0x10e/0x140 mm/shmem.c:3424
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x6ac/0x1050 fs/read_write.c:687
ksys_pwrite64 fs/read_write.c:794 [inline]
__do_sys_pwrite64 fs/read_write.c:802 [inline]
__se_sys_pwrite64 fs/read_write.c:799 [inline]
__x64_sys_pwrite64+0x1eb/0x250 fs/read_write.c:799
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe62c7fce5e
Code: 08 0f 85 f5 e2 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 90 41 57 41 56 4d 89 c6 41 55 4d 89 cd 41 54 55 53 48 83 ec 08
RSP: 002b:00007fe62b9fe1a8 EFLAGS: 00000246 ORIG_RAX: 0000000000000012
RAX: ffffffffffffffda RBX: 00007fe62b9fe6c0 RCX: 00007fe62c7fce5e
RDX: 0000000000000001 RSI: 00007fe62c200000 RDI: 0000000000000003
RBP: 0000000000000021 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffffd0
R13: 0000000000000000 R14: 00007ffdde346d90 R15: 00007ffdde346e78
</TASK>
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff888000000000 pfn:0x3f851
flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000000 dead000000000100 dead000000000122 0000000000000000
raw: ffff888000000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 0, migratetype Unmovable, gfp_mask 0x440dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO|__GFP_COMP), pid 6004, tgid 6004 (cmp), ts 79653237963, free_ts 79740307238
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0xfd/0x120 mm/page_alloc.c:1859
prep_new_page mm/page_alloc.c:1867 [inline]
get_page_from_freelist+0xf48/0x3530 mm/page_alloc.c:3946
__alloc_frozen_pages_noprof+0x299/0x2dc0 mm/page_alloc.c:5304
alloc_pages_mpol+0x1fb/0x540 mm/mempolicy.c:2490
alloc_pages_noprof+0x1a/0x160 mm/mempolicy.c:2581
pagetable_alloc_noprof include/linux/mm.h:3685 [inline]
pmd_alloc_one_noprof include/asm-generic/pgalloc.h:143 [inline]
__pmd_alloc+0x3b/0x950 mm/memory.c:6772
pmd_alloc include/linux/mm.h:3601 [inline]
__handle_mm_fault+0xa9c/0x2a00 mm/memory.c:6469
handle_mm_fault+0x37b/0xa30 mm/memory.c:6686
do_user_addr_fault+0x5a3/0x12f0 arch/x86/mm/fault.c:1343
handle_page_fault arch/x86/mm/fault.c:1483 [inline]
exc_page_fault+0x6f/0xd0 arch/x86/mm/fault.c:1536
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:595
page last free pid 6002 tgid 6002 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
__free_pages_prepare mm/page_alloc.c:1406 [inline]
__free_frozen_pages+0x79f/0x1090 mm/page_alloc.c:2950
__pagetable_free include/linux/mm.h:3695 [inline]
pagetable_free include/linux/mm.h:3719 [inline]
pagetable_dtor_free include/linux/mm.h:3818 [inline]
__tlb_remove_table include/asm-generic/tlb.h:221 [inline]
__tlb_remove_table_free mm/mmu_gather.c:228 [inline]
tlb_remove_table_rcu+0x2cf/0x380 mm/mmu_gather.c:291
rcu_do_batch kernel/rcu/tree.c:2645 [inline]
rcu_core+0x5a2/0x10d0 kernel/rcu/tree.c:2897
handle_softirqs+0x1ea/0x9b0 kernel/softirq.c:622
__do_softirq kernel/softirq.c:656 [inline]
invoke_softirq kernel/softirq.c:496 [inline]
__irq_exit_rcu+0x162/0x210 kernel/softirq.c:735
irq_exit_rcu+0x9/0x30 kernel/softirq.c:752
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0xa3/0xc0 arch/x86/kernel/apic/apic.c:1062
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
Memory state around the buggy address:
ffff88803f851900: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88803f851980: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88803f851a00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff88803f851a80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88803f851b00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
----------------
Code disassembly (best guess):
0: 68 46 ae ff 4c push $0x4cffae46
5: 89 f0 mov %esi,%eax
7: 48 85 c0 test %rax,%rax
a: 0f 85 bf 00 00 00 jne 0xcf
10: e8 77 4c ae ff call 0xffae4c8c
15: 0f 01 cb stac
18: 0f ae e8 lfence
1b: 4c 89 fb mov %r15,%rbx
1e: 4d 85 ff test %r15,%r15
21: 75 31 jne 0x54
23: eb 48 jmp 0x6d
25: e8 62 4c ae ff call 0xffae4c8c
* 2a: 44 8a 33 mov (%rbx),%r14b <-- trapping instruction
2d: e8 5a 4c ae ff call 0xffae4c8c
32: 48 81 c3 00 10 00 00 add $0x1000,%rbx
39: 31 ff xor %edi,%edi
3b: 48 rex.W
3c: 81 .byte 0x81
3d: e3 00 jrcxz 0x3f
3f: f0 lock
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
next prev parent reply other threads:[~2026-08-15 12:51 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-01 11:47 [syzbot] [net?] KASAN: use-after-free Read in filemap_map_pages syzbot
2026-08-15 12:51 ` syzbot [this message]
2026-08-16 2:17 ` [syzbot] [bridge?] " Hillf Danton
2026-08-16 2:34 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a8060cb.5ca1970b.32aa76.0008.GAE@google.com \
--to=syzbot+b72767277f29b6407083@syzkaller.appspotmail.com \
--cc=bridge@lists.linux.dev \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=razor@blackwall.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.