* [syzbot] [usb?] general protection fault in vhci_hcd_probe
@ 2026-08-21 8:03 syzbot
2026-09-05 8:12 ` syzbot
0 siblings, 1 reply; 5+ messages in thread
From: syzbot @ 2026-08-21 8:03 UTC (permalink / raw)
To: gregkh, i, linux-kernel, linux-usb, shuah, syzkaller-bugs,
valentina.manea.m
Hello,
syzbot found the following issue on:
HEAD commit: 4477a78374a5 Add linux-next specific files for 20260814
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=12bed6c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b32a36dd637b06f
dashboard link: https://syzkaller.appspot.com/bug?extid=7300affe388249d66dfe
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11e03a79580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/994c1c8c560e/disk-4477a783.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/cd54543d69ae/vmlinux-4477a783.xz
kernel image: https://storage.googleapis.com/syzbot-assets/407cdf8f3fc2/bzImage-4477a783.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7300affe388249d66dfe@syzkaller.appspotmail.com
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 1 UID: 0 PID: 5839 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:vhci_hcd_probe+0x47/0x3e0 drivers/usb/usbip/vhci_hcd.c:1367
Code: ff 0b eb f9 49 8d 9e 80 00 00 00 48 89 d8 48 c1 e8 03 80 3c 28 00 74 08 48 89 df e8 33 86 59 fa 48 8b 1b 48 89 d8 48 c1 e8 03 <80> 3c 28 00 74 08 48 89 df e8 1b 86 59 fa 4c 8b 23 48 c7 c0 20 e5
RSP: 0018:ffffc9000397fac0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff88802a031f40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88801c76c000
RBP: dffffc0000000000 R08: ffff88802a6f9873 R09: 1ffff110054df30e
R10: dffffc0000000000 R11: ffffffff87dcb110 R12: ffff88801c76c000
R13: ffffffff8fc690a0 R14: ffff88801c76c000 R15: ffffffff87dcb110
FS: 000055556104d500(0000) GS:ffff888124df8000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fe52c870000 CR3: 0000000075d5a000 CR4: 00000000003526f0
Call Trace:
<TASK>
platform_probe+0xf9/0x190 drivers/base/platform.c:1507
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x254/0xae0 drivers/base/dd.c:706
__driver_probe_device+0x1e8/0x360 drivers/base/dd.c:868
device_driver_attach+0xe0/0x1d0 drivers/base/dd.c:1203
bind_store+0x1d0/0x220 drivers/base/bus.c:267
kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x612/0xba0 fs/read_write.c:687
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe52c99e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffc9f637838 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007fe52cc25fa0 RCX: 00007fe52c99e0d9
RDX: 0000000000000006 RSI: 00002000000000c0 RDI: 0000000000000004
RBP: 00007fe52ca35024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fe52cc25fac R14: 00007fe52cc25fa0 R15: 00007fe52cc25fa0
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:vhci_hcd_probe+0x47/0x3e0 drivers/usb/usbip/vhci_hcd.c:1367
Code: ff 0b eb f9 49 8d 9e 80 00 00 00 48 89 d8 48 c1 e8 03 80 3c 28 00 74 08 48 89 df e8 33 86 59 fa 48 8b 1b 48 89 d8 48 c1 e8 03 <80> 3c 28 00 74 08 48 89 df e8 1b 86 59 fa 4c 8b 23 48 c7 c0 20 e5
RSP: 0018:ffffc9000397fac0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff88802a031f40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88801c76c000
RBP: dffffc0000000000 R08: ffff88802a6f9873 R09: 1ffff110054df30e
R10: dffffc0000000000 R11: ffffffff87dcb110 R12: ffff88801c76c000
R13: ffffffff8fc690a0 R14: ffff88801c76c000 R15: ffffffff87dcb110
FS: 000055556104d500(0000) GS:ffff888124df8000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fe52c870000 CR3: 0000000075d5a000 CR4: 00000000003526f0
----------------
Code disassembly (best guess):
0: ff 0b decl (%rbx)
2: eb f9 jmp 0xfffffffd
4: 49 8d 9e 80 00 00 00 lea 0x80(%r14),%rbx
b: 48 89 d8 mov %rbx,%rax
e: 48 c1 e8 03 shr $0x3,%rax
12: 80 3c 28 00 cmpb $0x0,(%rax,%rbp,1)
16: 74 08 je 0x20
18: 48 89 df mov %rbx,%rdi
1b: e8 33 86 59 fa call 0xfa598653
20: 48 8b 1b mov (%rbx),%rbx
23: 48 89 d8 mov %rbx,%rax
26: 48 c1 e8 03 shr $0x3,%rax
* 2a: 80 3c 28 00 cmpb $0x0,(%rax,%rbp,1) <-- trapping instruction
2e: 74 08 je 0x38
30: 48 89 df mov %rbx,%rdi
33: e8 1b 86 59 fa call 0xfa598653
38: 4c 8b 23 mov (%rbx),%r12
3b: 48 rex.W
3c: c7 .byte 0xc7
3d: c0 20 e5 shlb $0xe5,(%rax)
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [usb?] general protection fault in vhci_hcd_probe
2026-08-21 8:03 [syzbot] [usb?] general protection fault in vhci_hcd_probe syzbot
@ 2026-09-05 8:12 ` syzbot
2026-09-05 8:43 ` Michal Pecio
0 siblings, 1 reply; 5+ messages in thread
From: syzbot @ 2026-09-05 8:12 UTC (permalink / raw)
To: gregkh, i, linux-kernel, linux-usb, shuah, syzkaller-bugs,
valentina.manea.m
syzbot has found a reproducer for the following issue on:
HEAD commit: 9d80aa4617b3 Add linux-next specific files for 20260903
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git
console output: https://syzkaller.appspot.com/x/log.txt?x=10adf4f9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=bb4a32c282cc2ec7
dashboard link: https://syzkaller.appspot.com/bug?extid=7300affe388249d66dfe
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=121c7215580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7300affe388249d66dfe@syzkaller.appspotmail.com
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 1 UID: 0 PID: 6482 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:vhci_hcd_probe+0x47/0x3e0 drivers/usb/usbip/vhci_hcd.c:1367
Code: 0f ee e4 f9 49 8d 9e 80 00 00 00 48 89 d8 48 c1 e8 03 80 3c 28 00 74 08 48 89 df e8 13 17 55 fa 48 8b 1b 48 89 d8 48 c1 e8 03 <80> 3c 28 00 74 08 48 89 df e8 fb 16 55 fa 4c 8b 23 48 c7 c0 80 6c
RSP: 0018:ffffc900033c7ac0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff888076a89f40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88801c7a6000
RBP: dffffc0000000000 R08: ffff88802af3ba53 R09: 1ffff110055e774a
R10: dffffc0000000000 R11: ffffffff87e2e6c0 R12: ffff88801c7a6000
R13: ffffffff8fc7ad20 R14: ffff88801c7a6000 R15: ffffffff87e2e6c0
FS: 00007f21f99fe6c0(0000) GS:ffff888124dc0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f21fa270000 CR3: 000000007f704000 CR4: 00000000003526f0
Call Trace:
<TASK>
platform_probe+0xf9/0x190 drivers/base/platform.c:1507
call_driver_probe drivers/base/dd.c:-1 [inline]
really_probe+0x254/0xae0 drivers/base/dd.c:706
__driver_probe_device+0x1e8/0x360 drivers/base/dd.c:868
device_driver_attach+0xe0/0x1d0 drivers/base/dd.c:1203
bind_store+0x1d0/0x220 drivers/base/bus.c:267
kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x612/0xba0 fs/read_write.c:687
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f21fa39e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f21f99fe028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f21fa625fa0 RCX: 00007f21fa39e0d9
RDX: 0000000000000006 RSI: 00002000000000c0 RDI: 0000000000000004
RBP: 00007f21fa435024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f21fa626038 R14: 00007f21fa625fa0 R15: 00007fff742f7888
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:vhci_hcd_probe+0x47/0x3e0 drivers/usb/usbip/vhci_hcd.c:1367
Code: 0f ee e4 f9 49 8d 9e 80 00 00 00 48 89 d8 48 c1 e8 03 80 3c 28 00 74 08 48 89 df e8 13 17 55 fa 48 8b 1b 48 89 d8 48 c1 e8 03 <80> 3c 28 00 74 08 48 89 df e8 fb 16 55 fa 4c 8b 23 48 c7 c0 80 6c
RSP: 0018:ffffc900033c7ac0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff888076a89f40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88801c7a6000
RBP: dffffc0000000000 R08: ffff88802af3ba53 R09: 1ffff110055e774a
R10: dffffc0000000000 R11: ffffffff87e2e6c0 R12: ffff88801c7a6000
R13: ffffffff8fc7ad20 R14: ffff88801c7a6000 R15: ffffffff87e2e6c0
FS: 00007f21f99fe6c0(0000) GS:ffff888124cc0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b34124008 CR3: 000000007f704000 CR4: 00000000003526f0
----------------
Code disassembly (best guess):
0: 0f ee e4 pmaxsw %mm4,%mm4
3: f9 stc
4: 49 8d 9e 80 00 00 00 lea 0x80(%r14),%rbx
b: 48 89 d8 mov %rbx,%rax
e: 48 c1 e8 03 shr $0x3,%rax
12: 80 3c 28 00 cmpb $0x0,(%rax,%rbp,1)
16: 74 08 je 0x20
18: 48 89 df mov %rbx,%rdi
1b: e8 13 17 55 fa call 0xfa551733
20: 48 8b 1b mov (%rbx),%rbx
23: 48 89 d8 mov %rbx,%rax
26: 48 c1 e8 03 shr $0x3,%rax
* 2a: 80 3c 28 00 cmpb $0x0,(%rax,%rbp,1) <-- trapping instruction
2e: 74 08 je 0x38
30: 48 89 df mov %rbx,%rdi
33: e8 fb 16 55 fa call 0xfa551733
38: 4c 8b 23 mov (%rbx),%r12
3b: 48 rex.W
3c: c7 .byte 0xc7
3d: c0 .byte 0xc0
3e: 80 .byte 0x80
3f: 6c insb (%dx),%es:(%rdi)
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [usb?] general protection fault in vhci_hcd_probe
2026-09-05 8:12 ` syzbot
@ 2026-09-05 8:43 ` Michal Pecio
2026-09-05 11:30 ` Greg KH
0 siblings, 1 reply; 5+ messages in thread
From: Michal Pecio @ 2026-09-05 8:43 UTC (permalink / raw)
To: syzbot
Cc: gregkh, i, linux-kernel, linux-usb, shuah, syzkaller-bugs,
valentina.manea.m, syzkaller
On Sat, 05 Sep 2026 01:12:27 -0700, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 9d80aa4617b3 Add linux-next specific files for 20260903
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git
> console output: https://syzkaller.appspot.com/x/log.txt?x=10adf4f9580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=bb4a32c282cc2ec7
> dashboard link: https://syzkaller.appspot.com/bug?extid=7300affe388249d66dfe
> compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=121c7215580000
Who or what is coming up with these ideas and even commenting it?
// Iterate platform devices
dir = opendir("/sys/bus/platform/devices/");
while ((ent = readdir(dir)) != NULL) {
// Set driver override
snprintf(path, sizeof(path), "/sys/bus/platform/devices/%s/driver_override", ent->d_name);
fd = open(path, O_WRONLY);
// Bind to vhci_hcd
fd = open("/sys/bus/platform/drivers/vhci_hcd/bind", O_WRONLY);
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [usb?] general protection fault in vhci_hcd_probe
2026-09-05 8:43 ` Michal Pecio
@ 2026-09-05 11:30 ` Greg KH
2026-09-06 10:38 ` Michal Pecio
0 siblings, 1 reply; 5+ messages in thread
From: Greg KH @ 2026-09-05 11:30 UTC (permalink / raw)
To: Michal Pecio
Cc: syzbot, i, linux-kernel, linux-usb, shuah, syzkaller-bugs,
valentina.manea.m, syzkaller
On Sat, Sep 05, 2026 at 10:43:31AM +0200, Michal Pecio wrote:
> On Sat, 05 Sep 2026 01:12:27 -0700, syzbot wrote:
> > syzbot has found a reproducer for the following issue on:
> >
> > HEAD commit: 9d80aa4617b3 Add linux-next specific files for 20260903
> > git tree: git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git
> > console output: https://syzkaller.appspot.com/x/log.txt?x=10adf4f9580000
> > kernel config: https://syzkaller.appspot.com/x/.config?x=bb4a32c282cc2ec7
> > dashboard link: https://syzkaller.appspot.com/bug?extid=7300affe388249d66dfe
> > compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=121c7215580000
>
> Who or what is coming up with these ideas and even commenting it?
>
> // Iterate platform devices
> dir = opendir("/sys/bus/platform/devices/");
>
> while ((ent = readdir(dir)) != NULL) {
>
> // Set driver override
> snprintf(path, sizeof(path), "/sys/bus/platform/devices/%s/driver_override", ent->d_name);
> fd = open(path, O_WRONLY);
>
> // Bind to vhci_hcd
> fd = open("/sys/bus/platform/drivers/vhci_hcd/bind", O_WRONLY);
That will taint the kernel in newer releases, and syzbot has already
been told not to do this, it's not "valid" at all.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [usb?] general protection fault in vhci_hcd_probe
2026-09-05 11:30 ` Greg KH
@ 2026-09-06 10:38 ` Michal Pecio
0 siblings, 0 replies; 5+ messages in thread
From: Michal Pecio @ 2026-09-06 10:38 UTC (permalink / raw)
To: Greg KH
Cc: syzbot, i, linux-kernel, linux-usb, shuah, syzkaller-bugs,
valentina.manea.m, syzkaller
On Sat, 5 Sep 2026 13:30:01 +0200, Greg KH wrote:
> On Sat, Sep 05, 2026 at 10:43:31AM +0200, Michal Pecio wrote:
> > On Sat, 05 Sep 2026 01:12:27 -0700, syzbot wrote:
> > > syzbot has found a reproducer for the following issue on:
> > >
> > > HEAD commit: 9d80aa4617b3 Add linux-next specific files for 20260903
> > > git tree: git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git
> > > console output: https://syzkaller.appspot.com/x/log.txt?x=10adf4f9580000
> > > kernel config: https://syzkaller.appspot.com/x/.config?x=bb4a32c282cc2ec7
> > > dashboard link: https://syzkaller.appspot.com/bug?extid=7300affe388249d66dfe
> > > compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> > > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=121c7215580000
> >
> > Who or what is coming up with these ideas and even commenting it?
> >
> > // Iterate platform devices
> > dir = opendir("/sys/bus/platform/devices/");
> >
> > while ((ent = readdir(dir)) != NULL) {
> >
> > // Set driver override
> > snprintf(path, sizeof(path), "/sys/bus/platform/devices/%s/driver_override", ent->d_name);
> > fd = open(path, O_WRONLY);
> >
> > // Bind to vhci_hcd
> > fd = open("/sys/bus/platform/drivers/vhci_hcd/bind", O_WRONLY);
>
> That will taint the kernel in newer releases, and syzbot has already
> been told not to do this, it's not "valid" at all.
What cought my attention is that Google apparently has some capability
(human, machine or otherwise) to understand how this repro works, and
yet they keep reporting this broken pattern.
It's just waste of time, including syzbot's own time.
Hence syzkaller@googlegroups.com in Cc, wonder if there is any truth in
> See https://goo.gl/tpsmEJ for more information about syzbot.
> syzbot engineers can be reached at syzkaller@googlegroups.com.
Regards,
Michal
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-06 10:38 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-21 8:03 [syzbot] [usb?] general protection fault in vhci_hcd_probe syzbot
2026-09-05 8:12 ` syzbot
2026-09-05 8:43 ` Michal Pecio
2026-09-05 11:30 ` Greg KH
2026-09-06 10:38 ` Michal Pecio
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox