Linux Modules
 help / color / mirror / Atom feed
* [BUG] KASAN: wild-memory-access in idempotent (concurrent finit_module) [dw_xdata_pcie] [syzkaller]
@ 2026-08-09 13:18 Yang Zi
  0 siblings, 0 replies; only message in thread
From: Yang Zi @ 2026-08-09 13:18 UTC (permalink / raw)
  To: linux-modules; +Cc: linux-kernel

Hi,

While fuzzing the kernel v7.1 with syzkaller (KASAN), we triggered a
wild-memory-access in the module-loading de-duplication helper. Concurrent
`finit_module` calls pass `file_inode(f)` as the `cookie` into `idempotent()`,
which traverses the shared `idem_hash` hlist; under an fd/close race the inode
can be released and reused, turning the cookie into a non-canonical address that
is dereferenced during the list walk.

Reproducer summary (see attached report/log):

    BUG: KASAN: wild-memory-access in idempotent kernel/module/main.c:3682 [inline]
    BUG: KASAN: wild-memory-access in idempotent_init_module kernel/module/main.c:3788 [inline]
    BUG: KASAN: wild-memory-access in __do_sys_finit_module kernel/module/main.c:3815 [inline]
    BUG: KASAN: wild-memory-access in __se_sys_finit_module+0x145/0x410 kernel/module/main.c:3799
    Read of size 8 at addr 8000000053120fff by task modprobe/1106

    Oops: general protection fault, probably for non-canonical address
    0x800000005...: 0000 [#2] SMP KASAN NOPTI

The trap compares `existing->cookie` against `cookie` by dereferencing a
corrupted hlist node pointer (`cmp %rbx,0x0(%r13)`). The second-order crash is
in the `igbvf` driver probe path, i.e. the same concurrent load/probe had
already corrupted memory, eventually escalating to BAD_PAGE / DIE.

Root-cause hypothesis: `idempotent()` relies on the lifetime of `cookie`
(= the inode from `file_inode(f)`), but a concurrent `close()` / fd reuse can
free and repurpose that inode while the hlist traversal still holds a stale
pointer to it — classic use-after-free, here manifesting as a wild read on a
non-canonical address.

The crash report attached below:

BUG: KASAN: wild-memory-access in idempotent kernel/module/main.c:3682 [inline]
BUG: KASAN: wild-memory-access in idempotent_init_module kernel/module/main.c:3788 [inline]
BUG: KASAN: wild-memory-access in __do_sys_finit_module kernel/module/main.c:3815 [inline]
BUG: KASAN: wild-memory-access in __se_sys_finit_module+0x145/0x410 kernel/module/main.c:3799
Read of size 8 at addr 8000000053120fff by task modprobe/1106

CPU: 0 UID: 0 PID: 1106 Comm: modprobe Tainted: G      D W  O        7.1.0 #2 PREEMPT(lazy) 
Tainted: [D]=DIE, [W]=WARN, [O]=OOT_MODULE
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xa2/0xd0 lib/dump_stack.c:120
 kasan_report+0x117/0x150 mm/kasan/report.c:595
 idempotent kernel/module/main.c:3682 [inline]
 idempotent_init_module kernel/module/main.c:3788 [inline]
 __do_sys_finit_module kernel/module/main.c:3815 [inline]
 __se_sys_finit_module+0x145/0x410 kernel/module/main.c:3799
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x14b/0x490 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f9cebcc325d
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8b bb 0d 00 f7 d8 64 89 01 48
RSP: 002b:00007ffc05413188 EFLAGS: 00000246 ORIG_RAX: 0000000000000139
RAX: ffffffffffffffda RBX: 0000557fbb772ce0 RCX: 00007f9cebcc325d
RDX: 0000000000000000 RSI: 0000557faa18ae52 RDI: 0000000000000003
RBP: 00007ffc05413240 R08: 0000000000000040 R09: 0000000000000002
R10: 00007f9cebd9fb20 R11: 0000000000000246 R12: 0000557faa18ae52
R13: 0000000000040000 R14: 0000557fbb772c50 R15: 0000000000000000
 </TASK>

Regards,
Yang Zi


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-09 13:18 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-09 13:18 [BUG] KASAN: wild-memory-access in idempotent (concurrent finit_module) [dw_xdata_pcie] [syzkaller] Yang Zi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox