From: syzbot <syzbot+b72767277f29b6407083@syzkaller.appspotmail.com>
To: hdanton@sina.com, linux-kernel@vger.kernel.org,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [bridge?] KASAN: use-after-free Read in filemap_map_pages
Date: Sat, 15 Aug 2026 19:34:02 -0700 [thread overview]
Message-ID: <6a81219a.10853dc7.22f513.000b.GAE@google.com> (raw)
In-Reply-To: <20260816021733.1177-1-hdanton@sina.com>
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
KASAN: slab-out-of-bounds Read in filemap_map_pages
==================================================================
BUG: KASAN: slab-out-of-bounds in ptep_get include/linux/pgtable.h:495 [inline]
BUG: KASAN: slab-out-of-bounds in filemap_map_folio_range mm/filemap.c:3820 [inline]
BUG: KASAN: slab-out-of-bounds in filemap_map_pages+0x1b75/0x1f80 mm/filemap.c:3955
Read of size 8 at addr ffff88803cb81a60 by task syz-executor275/6045
CPU: 0 UID: 0 PID: 6045 Comm: syz-executor275 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0x13d/0x4b0 mm/kasan/report.c:482
kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
ptep_get include/linux/pgtable.h:495 [inline]
filemap_map_folio_range mm/filemap.c:3820 [inline]
filemap_map_pages+0x1b75/0x1f80 mm/filemap.c:3955
do_fault_around mm/memory.c:5818 [inline]
do_read_fault mm/memory.c:5851 [inline]
do_fault+0x985/0x1750 mm/memory.c:5994
do_pte_missing mm/memory.c:4566 [inline]
handle_pte_fault mm/memory.c:6379 [inline]
__handle_mm_fault+0x187d/0x2a00 mm/memory.c:6517
handle_mm_fault+0x37b/0xa30 mm/memory.c:6686
do_user_addr_fault+0x74c/0x12f0 arch/x86/mm/fault.c:1394
handle_page_fault arch/x86/mm/fault.c:1483 [inline]
exc_page_fault+0x6f/0xd0 arch/x86/mm/fault.c:1536
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:595
RIP: 0010:fault_in_readable+0xde/0x190 mm/gup.c:2161
Code: 68 46 ae ff 4c 89 f0 48 85 c0 0f 85 bf 00 00 00 e8 77 4c ae ff 0f 01 cb 0f ae e8 4c 89 fb 4d 85 ff 75 31 eb 48 e8 62 4c ae ff <44> 8a 33 e8 5a 4c ae ff 48 81 c3 00 10 00 00 31 ff 48 81 e3 00 f0
RSP: 0018:ffffc900030d7af8 EFLAGS: 00050293
RAX: 0000000000000000 RBX: 00007fb9fe400000 RCX: ffffffff825c2758
RDX: ffff88802a614a80 RSI: ffffffff825c271e RDI: ffff88802a614a80
RBP: 00007fb9fe400001 R08: 0000000000000006 R09: 00007fb9fe400001
R10: 00007fb9fe400000 R11: 0000000000000000 R12: 0000000000000001
R13: 1ffff9200061af60 R14: 0000000000000000 R15: 00007fb9fe400000
fault_in_iov_iter_readable+0x101/0x2c0 lib/iov_iter.c:106
generic_perform_write+0x863/0xa40 mm/filemap.c:4413
shmem_file_write_iter+0x10e/0x140 mm/shmem.c:3424
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x6ac/0x1050 fs/read_write.c:687
ksys_pwrite64 fs/read_write.c:794 [inline]
__do_sys_pwrite64 fs/read_write.c:802 [inline]
__se_sys_pwrite64 fs/read_write.c:799 [inline]
__x64_sys_pwrite64+0x1eb/0x250 fs/read_write.c:799
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fb9fe9f8e5e
Code: 08 0f 85 f5 e2 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 90 41 57 41 56 4d 89 c6 41 55 4d 89 cd 41 54 55 53 48 83 ec 08
RSP: 002b:00007fb9fdbfe1a8 EFLAGS: 00000246 ORIG_RAX: 0000000000000012
RAX: ffffffffffffffda RBX: 00007fb9fdbfe6c0 RCX: 00007fb9fe9f8e5e
RDX: 0000000000000001 RSI: 00007fb9fe400000 RDI: 0000000000000003
RBP: 0000000000000021 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffffd0
R13: 0000000000000000 R14: 00007fff5b6bda40 R15: 00007fff5b6bdb28
</TASK>
Allocated by task 5144:
kasan_save_stack+0x30/0x50 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263 [inline]
__do_kmalloc_node mm/slub.c:5334 [inline]
__kvmalloc_node_noprof+0x34f/0x970 mm/slub.c:6905
simple_xattr_alloc+0x6c/0xd0 fs/xattr.c:1271
class_simple_xattr_constructor include/linux/xattr.h:166 [inline]
simple_xattr_set+0xa8/0x3ca0 fs/xattr.c:1438
shmem_xattr_handler_set+0x326/0x3c0 mm/shmem.c:4266
__vfs_setxattr+0x175/0x1e0 fs/xattr.c:223
__vfs_setxattr_noperm+0x127/0x660 fs/xattr.c:257
__vfs_setxattr_locked+0x127/0x2b0 fs/xattr.c:318
vfs_setxattr+0x14a/0x390 fs/xattr.c:344
do_setxattr+0x145/0x180 fs/xattr.c:662
filename_setxattr+0x167/0x1d0 fs/xattr.c:690
path_setxattrat+0x1ff/0x3b0 fs/xattr.c:734
__do_sys_lsetxattr fs/xattr.c:775 [inline]
__se_sys_lsetxattr fs/xattr.c:771 [inline]
__x64_sys_lsetxattr+0xc9/0x140 fs/xattr.c:771
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
The buggy address belongs to the object at ffff88803cb81a00
which belongs to the cache kmalloc-cg-128 of size 128
The buggy address is located 96 bytes inside of
allocated 98-byte region [ffff88803cb81a00, ffff88803cb81a62)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88803cb81f00 pfn:0x3cb81
flags: 0xfff00000000200(workingset|node=0|zone=1|lastcpupid=0x7ff)
page_type: f5(slab)
raw: 00fff00000000200 ffff88801c049b80 ffffea000161cb90 ffffea0000b6dbd0
raw: ffff88803cb81f00 000000080010000f 00000000f5000000 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 0, migratetype Unmovable, gfp_mask 0xd2cc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5144, tgid 5144 (udevd), ts 32535993040, free_ts 32521083899
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0xfd/0x120 mm/page_alloc.c:1859
prep_new_page mm/page_alloc.c:1867 [inline]
get_page_from_freelist+0xf48/0x3530 mm/page_alloc.c:3946
__alloc_frozen_pages_noprof+0x299/0x2dc0 mm/page_alloc.c:5304
alloc_slab_page mm/slub.c:3266 [inline]
allocate_slab mm/slub.c:3380 [inline]
new_slab+0xa2/0x640 mm/slub.c:3426
refill_objects+0xe3/0x410 mm/slub.c:7310
refill_sheaf mm/slub.c:2804 [inline]
__pcs_replace_empty_main+0x376/0x680 mm/slub.c:4675
alloc_from_pcs mm/slub.c:4773 [inline]
slab_alloc_node mm/slub.c:4905 [inline]
__do_kmalloc_node mm/slub.c:5333 [inline]
__kvmalloc_node_noprof+0x793/0x970 mm/slub.c:6905
simple_xattr_alloc+0x6c/0xd0 fs/xattr.c:1271
class_simple_xattr_constructor include/linux/xattr.h:166 [inline]
simple_xattr_set+0xa8/0x3ca0 fs/xattr.c:1438
shmem_xattr_handler_set+0x326/0x3c0 mm/shmem.c:4266
__vfs_setxattr+0x175/0x1e0 fs/xattr.c:223
__vfs_setxattr_noperm+0x127/0x660 fs/xattr.c:257
__vfs_setxattr_locked+0x127/0x2b0 fs/xattr.c:318
vfs_setxattr+0x14a/0x390 fs/xattr.c:344
do_setxattr+0x145/0x180 fs/xattr.c:662
filename_setxattr+0x167/0x1d0 fs/xattr.c:690
page last free pid 5152 tgid 5152 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
__free_pages_prepare mm/page_alloc.c:1406 [inline]
__free_frozen_pages+0x79f/0x1090 mm/page_alloc.c:2950
qlink_free mm/kasan/quarantine.c:163 [inline]
qlist_free_all+0x47/0xf0 mm/kasan/quarantine.c:179
kasan_quarantine_reduce+0x1a0/0x1f0 mm/kasan/quarantine.c:286
__kasan_slab_alloc+0x69/0x90 mm/kasan/common.c:350
kasan_slab_alloc include/linux/kasan.h:253 [inline]
slab_post_alloc_hook mm/slub.c:4584 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
__do_kmalloc_node mm/slub.c:5333 [inline]
__kmalloc_noprof+0x2bf/0x820 mm/slub.c:5359
_kmalloc_noprof include/linux/slab.h:992 [inline]
_kzalloc_noprof include/linux/slab.h:1309 [inline]
tomoyo_encode2+0xfb/0x3c0 security/tomoyo/realpath.c:45
tomoyo_encode+0x29/0x50 security/tomoyo/realpath.c:80
tomoyo_realpath_from_path+0x18c/0x690 security/tomoyo/realpath.c:283
tomoyo_get_realpath security/tomoyo/file.c:151 [inline]
tomoyo_path_perm+0x276/0x460 security/tomoyo/file.c:827
security_inode_getattr+0x116/0x280 security/security.c:1895
vfs_getattr fs/stat.c:259 [inline]
vfs_statx_path fs/stat.c:299 [inline]
vfs_statx+0x11f/0x3f0 fs/stat.c:356
vfs_fstatat+0x77/0xe0 fs/stat.c:373
__do_sys_newfstatat+0x9d/0x120 fs/stat.c:538
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff88803cb81900: 00 00 00 00 00 00 00 00 00 00 00 00 02 fc fc fc
ffff88803cb81980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
>ffff88803cb81a00: 00 00 00 00 00 00 00 00 00 00 00 00 02 fc fc fc
^
ffff88803cb81a80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
ffff88803cb81b00: 00 00 00 00 00 00 00 00 00 00 00 00 02 fc fc fc
==================================================================
----------------
Code disassembly (best guess):
0: 68 46 ae ff 4c push $0x4cffae46
5: 89 f0 mov %esi,%eax
7: 48 85 c0 test %rax,%rax
a: 0f 85 bf 00 00 00 jne 0xcf
10: e8 77 4c ae ff call 0xffae4c8c
15: 0f 01 cb stac
18: 0f ae e8 lfence
1b: 4c 89 fb mov %r15,%rbx
1e: 4d 85 ff test %r15,%r15
21: 75 31 jne 0x54
23: eb 48 jmp 0x6d
25: e8 62 4c ae ff call 0xffae4c8c
* 2a: 44 8a 33 mov (%rbx),%r14b <-- trapping instruction
2d: e8 5a 4c ae ff call 0xffae4c8c
32: 48 81 c3 00 10 00 00 add $0x1000,%rbx
39: 31 ff xor %edi,%edi
3b: 48 rex.W
3c: 81 .byte 0x81
3d: e3 00 jrcxz 0x3f
3f: f0 lock
Tested on:
commit: 3eb40771 Merge tag 'soc-fixes-7.2-3' of git://git.kern..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1265e949580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1d67342c314f228d
dashboard link: https://syzkaller.appspot.com/bug?extid=b72767277f29b6407083
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch: https://syzkaller.appspot.com/x/patch.diff?x=1197b279580000
prev parent reply other threads:[~2026-08-16 2:34 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-01 11:47 [syzbot] [net?] KASAN: use-after-free Read in filemap_map_pages syzbot
2026-08-15 12:51 ` [syzbot] [bridge?] " syzbot
2026-08-16 2:17 ` Hillf Danton
2026-08-16 2:34 ` syzbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a81219a.10853dc7.22f513.000b.GAE@google.com \
--to=syzbot+b72767277f29b6407083@syzkaller.appspotmail.com \
--cc=hdanton@sina.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.