From: Johan Hovold <johan@kernel.org>
To: syzbot <syzbot+2fd6aefc361af86911d5@syzkaller.appspotmail.com>
Cc: elder@kernel.org, gregkh@linuxfoundation.org,
greybus-dev@lists.linaro.org, linux-kernel@vger.kernel.org,
linux-media@vger.kernel.org, linux-staging@lists.linux.dev,
linux-usb@vger.kernel.org, syzkaller-bugs@googlegroups.com,
Yang Zi <2959243019@qq.com>
Subject: Re: [syzbot] [greybus?] [usb?] KASAN: slab-out-of-bounds Write in gb_operation_message_alloc
Date: Fri, 28 Aug 2026 08:48:34 +0200 [thread overview]
Message-ID: <apEvQq8aBBlije3K@hovoldconsulting.com> (raw)
In-Reply-To: <6a908733.1d9ded08.62e62.00d8.GAE@google.com>
On Thu, Aug 27, 2026 at 11:51:31AM -0700, syzbot wrote:
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 45c13f3f9e3b Merge tag 'hwlock-v7.3' of git://git.kernel.o..
> git tree: https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-testing
> console output: https://syzkaller.appspot.com/x/log.txt?x=17ab5299580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=9b0fc292fc5639c
> dashboard link: https://syzkaller.appspot.com/bug?extid=2fd6aefc361af86911d5
> compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=137a3579580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=173ed625580000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/ac6556827073/disk-45c13f3f.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/01ff014f18d2/vmlinux-45c13f3f.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/77e9c6302a14/bzImage-45c13f3f.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+2fd6aefc361af86911d5@syzkaller.appspotmail.com
>
> usb 4-1: invalid cport id 160 received
> ==================================================================
> BUG: KASAN: slab-out-of-bounds in gb_operation_message_init drivers/greybus/operation.c:341 [inline]
> BUG: KASAN: slab-out-of-bounds in gb_operation_message_alloc+0x26e/0x2c0 drivers/greybus/operation.c:385
> Write of size 2 at addr ffff888100b7e582 by task syz.3.17/3979
>
> CPU: 1 UID: 0 PID: 3979 Comm: syz.3.17 Not tainted syzkaller #0 PREEMPT(lazy)
> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
> Call Trace:
> <IRQ>
> __dump_stack lib/dump_stack.c:94 [inline]
> dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
> print_address_description mm/kasan/report.c:378 [inline]
> print_report+0x13d/0x4b0 mm/kasan/report.c:482
> kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
> gb_operation_message_init drivers/greybus/operation.c:341 [inline]
> gb_operation_message_alloc+0x26e/0x2c0 drivers/greybus/operation.c:385
> gb_operation_create_common+0x9f/0x710 drivers/greybus/operation.c:532
> gb_operation_create_incoming drivers/greybus/operation.c:644 [inline]
> gb_connection_recv_request drivers/greybus/operation.c:926 [inline]
> gb_connection_recv+0x1dc/0x1050 drivers/greybus/operation.c:1063
> greybus_data_rcvd+0x244/0x600 drivers/greybus/connection.c:89
This appears to be the same issue being fixed here:
https://lore.kernel.org/all/tencent_4F423FBD3FCE6066A8538BB3CFBCB0C41E09@qq.com/
Hopefully, Yang will produce a non-corrupt patch soon.
Johan
prev parent reply other threads:[~2026-08-28 6:48 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 18:51 [syzbot] [greybus?] [usb?] KASAN: slab-out-of-bounds Write in gb_operation_message_alloc syzbot
2026-08-28 6:48 ` Johan Hovold [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apEvQq8aBBlije3K@hovoldconsulting.com \
--to=johan@kernel.org \
--cc=2959243019@qq.com \
--cc=elder@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=greybus-dev@lists.linaro.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=linux-staging@lists.linux.dev \
--cc=linux-usb@vger.kernel.org \
--cc=syzbot+2fd6aefc361af86911d5@syzkaller.appspotmail.com \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox