All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Zi Yan" <ziy@nvidia.com>
To: "syzbot" <syzbot+805630f1453e490427fa@syzkaller.appspotmail.com>,
	<akpm@linux-foundation.org>, <apopple@nvidia.com>,
	<byungchul@sk.com>, <david@kernel.org>, <gourry@gourry.net>,
	<gregkh@linuxfoundation.org>, <joshua.hahnjy@gmail.com>,
	<linux-kernel@vger.kernel.org>, <linux-mm@kvack.org>,
	<linux-usb@vger.kernel.org>, <matthew.brost@intel.com>,
	<rakie.kim@sk.com>, <stern@rowland.harvard.edu>,
	<syzkaller-bugs@googlegroups.com>, <ying.huang@linux.alibaba.com>
Subject: Re: [syzbot] [mm?] WARNING in ep_write_iter
Date: Mon, 17 Aug 2026 15:45:15 -0400	[thread overview]
Message-ID: <DKRH6MEVABEQ.28CPBZM86HRGF@nvidia.com> (raw)
In-Reply-To: <6a82d0f7.dbb3a75c.20434b.004d.GAE@google.com>

On Mon Aug 17, 2026 at 5:14 AM EDT, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit:    8d3ae59288f1 Linux 7.2
> git tree:       upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=13bad949580000
> kernel config:  https://syzkaller.appspot.com/x/.config?x=1d67342c314f228d
> dashboard link: https://syzkaller.appspot.com/bug?extid=805630f1453e490427fa
> compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
> C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=1637ea25580000
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+805630f1453e490427fa@syzkaller.appspotmail.com
>
> gadgetfs: bound to dummy_udc driver
> ------------[ cut here ]------------
> 1
> WARNING: mm/page_alloc.c:5280 at __alloc_frozen_pages_noprof+0x2427/0x2dc0 mm/page_alloc.c:5280, CPU#2: syz-executor421/6034
> Modules linked in:
> CPU: 2 UID: 0 PID: 6034 Comm: syz-executor421 Not tainted syzkaller #0 PREEMPT(full) 
> Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
> RIP: 0010:__alloc_frozen_pages_noprof+0x2427/0x2dc0 mm/page_alloc.c:5280
> Code: e9 8d fb ff ff 31 d2 be 28 12 00 00 48 c7 c7 a0 74 01 8c e8 7b 95 68 ff 2e 2e 2e 31 c0 e9 02 ed ff ff c6 05 85 90 bc 0e 01 90 <0f> 0b 90 e9 6f df ff ff 48 c7 c7 80 be f3 8e 45 89 f7 44 8b 74 24
> RSP: 0018:ffffc900048c7810 EFLAGS: 00010246
> RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
> RDX: 0000000000000000 RSI: 1ffff92000918f1c RDI: 0000000000040cc0
> RBP: 0000000000000013 R08: 0000000000000005 R09: 0000000000000009
> R10: 0000000000000013 R11: 0000000000000000 R12: 0000000000040cc0
> R13: 1ffff92000918f5a R14: ffffffff9b95c444 R15: 0000000000000001
> FS:  00005555738a6400(0000) GS:ffff8880d5dde000(0000) knlGS:0000000000000000
> CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00007ffd5f5d6fe8 CR3: 0000000020943000 CR4: 0000000000352ef0
> Call Trace:
>  <TASK>
>  alloc_pages_mpol+0x1fb/0x540 mm/mempolicy.c:2490
>  ___kmalloc_large_node+0xe5/0x120 mm/slub.c:5274
>  __kmalloc_large_node_noprof+0x1c/0x70 mm/slub.c:5305
>  __do_kmalloc_node mm/slub.c:5322 [inline]
>  __kmalloc_noprof+0x5a1/0x820 mm/slub.c:5359
>  _kmalloc_noprof include/linux/slab.h:992 [inline]
>  ep_write_iter+0x180/0xbc0 drivers/usb/gadget/legacy/inode.c:669
>  new_sync_write fs/read_write.c:595 [inline]
>  vfs_write+0x6ac/0x1050 fs/read_write.c:687
>  ksys_write+0x12a/0x250 fs/read_write.c:739
>  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
>  do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
>  entry_SYSCALL_64_after_hwframe+0x77/0x7f
> RIP: 0033:0x7f7cc18b5cb7
> Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
> RSP: 002b:00007ffd5f5d76e0 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
> RAX: ffffffffffffffda RBX: 00005555738a6400 RCX: 00007f7cc18b5cb7
> RDX: 000000007fffffff RSI: 0000000000000000 RDI: 0000000000000004
> RBP: 00007ffd5f5d7730 R08: 0000000000000000 R09: 0000000000000000
> R10: 0000000000000000 R11: 0000000000000202 R12: 00007ffd5f5d7930
> R13: 00007f7cc18ea039 R14: 00007ffd5f5d7b30 R15: 0000000000000002
>  </TASK>
>
>
> ---
> If you want syzbot to run the reproducer, reply with:
> #syz test: git://repo/address.git branch-or-commit-hash
> If you attach or paste a git patch, syzbot will apply it before testing.


#syz test


diff --git a/mm/slub.c b/mm/slub.c
index 0337e60db5ace..2d87896c6dfbf 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -5265,6 +5265,9 @@ static void *___kmalloc_large_node(size_t size, gfp_t flags, int node)
 	void *ptr = NULL;
 	unsigned int order = get_order(size);
 
+	if (size > KMALLOC_MAX_SIZE)
+		return NULL;
+
 	if (unlikely(flags & GFP_SLAB_BUG_MASK))
 		flags = kmalloc_fix_flags(flags);
 


-- 
Best Regards,
Yan, Zi



  reply	other threads:[~2026-08-17 19:45 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-16 19:25 [syzbot] [mm?] WARNING in ep_write_iter syzbot
2026-08-16 20:52 ` Andrew Morton
2026-08-16 21:47   ` Zi Yan
2026-08-16 23:32     ` Alan Stern
2026-08-17  0:13       ` Zi Yan
2026-08-17  1:15         ` Alan Stern
2026-08-17  1:47           ` Zi Yan
2026-08-17  2:42             ` Andrew Morton
2026-08-17 13:55               ` Alan Stern
2026-08-17 14:34                 ` Zi Yan
2026-08-17 14:37                   ` Zi Yan
2026-08-17 15:06                     ` Alan Stern
2026-08-17 15:22                       ` Zi Yan
2026-08-17 15:37                         ` Alan Stern
2026-08-17 18:45                           ` Zi Yan
2026-08-18  3:12                             ` Alan Stern
2026-08-17 15:06                   ` Greg Kroah-Hartman
2026-08-17 15:19                     ` Zi Yan
2026-08-17 15:55                       ` Greg Kroah-Hartman
2026-08-17 18:51                         ` Zi Yan
2026-08-17 20:34                           ` John Hubbard
2026-08-17  9:14 ` syzbot
2026-08-17 19:45   ` Zi Yan [this message]
2026-08-17 19:59     ` syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKRH6MEVABEQ.28CPBZM86HRGF@nvidia.com \
    --to=ziy@nvidia.com \
    --cc=akpm@linux-foundation.org \
    --cc=apopple@nvidia.com \
    --cc=byungchul@sk.com \
    --cc=david@kernel.org \
    --cc=gourry@gourry.net \
    --cc=gregkh@linuxfoundation.org \
    --cc=joshua.hahnjy@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=matthew.brost@intel.com \
    --cc=rakie.kim@sk.com \
    --cc=stern@rowland.harvard.edu \
    --cc=syzbot+805630f1453e490427fa@syzkaller.appspotmail.com \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=ying.huang@linux.alibaba.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.