The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [syzbot] WARNING: ODEBUG bug in hwsim_del_radio_nl
@ 2026-08-18 10:47 syzbot
  0 siblings, 0 replies; only message in thread
From: syzbot @ 2026-08-18 10:47 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

Hello,

syzbot found the following issue on:

HEAD commit:    2f1baf1fc892 Merge tag 'trace-v7.2-rc7' of git://git.kerne..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=108da279580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=c44651ea7dd2f307
dashboard link: https://syzkaller.appspot.com/bug?extid=19cbce4cc656ecd4febc
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=157df149580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+19cbce4cc656ecd4febc@syzkaller.appspotmail.com

------------[ cut here ]------------
ODEBUG: free active (active state 0) object: ffff88802e98a900 object type: timer_list hint: mac802154_scan_worker+0x0/0x1450 arch/x86/include/asm/bitops.h:202
WARNING: lib/debugobjects.c:629 at debug_print_object+0x198/0x2b0 lib/debugobjects.c:629, CPU#2: syz-executor392/6031
Modules linked in:
CPU: 2 UID: 0 PID: 6031 Comm: syz-executor392 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:debug_print_object+0x1a5/0x2b0 lib/debugobjects.c:629
Code: b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 48 8d 3d e8 28 05 0c 41 56 48 8b 14 ed 40 16 40 8c 4c 89 e6 <67> 48 0f b9 3a 58 83 05 62 4a fa 0b 01 48 83 c4 18 5b 5d 41 5c 41
RSP: 0018:ffffc90004d57538 EFLAGS: 00010246
RAX: dffffc0000000000 RBX: ffffc90004d57620 RCX: 0000000000000000
RDX: ffffffff8c401580 RSI: ffffffff8c401120 RDI: ffffffff912cab20
RBP: 0000000000000003 R08: ffff88802e98a900 R09: ffffffff8bd2f280
R10: 0000000000000001 R11: 0000000000000000 R12: ffffffff8c401120
R13: ffffffff8bd2f2c0 R14: ffffffff8b759990 R15: ffffc90004d57638
FS:  000055555d787400(0000) GS:ffff8880d5fe9000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000560dc5482000 CR3: 0000000027949000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 __debug_check_no_obj_freed lib/debugobjects.c:1171 [inline]
 debug_check_no_obj_freed+0x4da/0x630 lib/debugobjects.c:1201
 slab_free_hook mm/slub.c:2608 [inline]
 slab_free mm/slub.c:6377 [inline]
 kfree+0x3d8/0x6c0 mm/slub.c:6692
 device_release+0xd2/0x270 drivers/base/core.c:2636
 kobject_cleanup lib/kobject.c:689 [inline]
 kobject_release lib/kobject.c:720 [inline]
 kref_put include/linux/kref.h:65 [inline]
 kobject_put+0x1f7/0x640 lib/kobject.c:737
 put_device+0x1f/0x30 drivers/base/core.c:3880
 hwsim_del_radio_nl+0x161/0x200 drivers/net/ieee802154/mac802154_hwsim.c:358
 genl_family_rcv_msg_doit+0x214/0x300 net/netlink/genetlink.c:1114
 genl_family_rcv_msg net/netlink/genetlink.c:1194 [inline]
 genl_rcv_msg+0x560/0x800 net/netlink/genetlink.c:1209
 netlink_rcv_skb+0x159/0x420 net/netlink/af_netlink.c:2556
 genl_rcv+0x28/0x40 net/netlink/genetlink.c:1218
 netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
 netlink_unicast+0x585/0x850 net/netlink/af_netlink.c:1345
 netlink_sendmsg+0x8b0/0xda0 net/netlink/af_netlink.c:1900
 sock_sendmsg_nosec net/socket.c:775 [inline]
 __sock_sendmsg net/socket.c:790 [inline]
 __sys_sendto+0x48b/0x4e0 net/socket.c:2252
 __do_sys_sendto net/socket.c:2259 [inline]
 __se_sys_sendto net/socket.c:2255 [inline]
 __x64_sys_sendto+0xe0/0x1c0 net/socket.c:2255
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f86a2fe5fb7
Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffd8a516790 EFLAGS: 00000202 ORIG_RAX: 000000000000002c
----------------
Code disassembly (best guess):
   0:	b8 00 00 00 00       	mov    $0x0,%eax
   5:	00 fc                	add    %bh,%ah
   7:	ff                   	lcall  (bad)
   8:	df 48 89             	fisttps -0x77(%rax)
   b:	fa                   	cli
   c:	48 c1 ea 03          	shr    $0x3,%rdx
  10:	80 3c 02 00          	cmpb   $0x0,(%rdx,%rax,1)
  14:	75 4f                	jne    0x65
  16:	48 8d 3d e8 28 05 0c 	lea    0xc0528e8(%rip),%rdi        # 0xc052905
  1d:	41 56                	push   %r14
  1f:	48 8b 14 ed 40 16 40 	mov    -0x73bfe9c0(,%rbp,8),%rdx
  26:	8c
  27:	4c 89 e6             	mov    %r12,%rsi
* 2a:	67 48 0f b9 3a       	ud1    (%edx),%rdi <-- trapping instruction
  2f:	58                   	pop    %rax
  30:	83 05 62 4a fa 0b 01 	addl   $0x1,0xbfa4a62(%rip)        # 0xbfa4a99
  37:	48 83 c4 18          	add    $0x18,%rsp
  3b:	5b                   	pop    %rbx
  3c:	5d                   	pop    %rbp
  3d:	41 5c                	pop    %r12
  3f:	41                   	rex.B


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-18 10:47 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-18 10:47 [syzbot] WARNING: ODEBUG bug in hwsim_del_radio_nl syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox