From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id A190AE77173 for ; Fri, 6 Dec 2024 21:18:33 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 17E288D000F; Fri, 6 Dec 2024 16:18:33 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 12DCE8D000B; Fri, 6 Dec 2024 16:18:33 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id F108C8D000F; Fri, 6 Dec 2024 16:18:32 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0012.hostedemail.com [216.40.44.12]) by kanga.kvack.org (Postfix) with ESMTP id CD5C78D000B for ; Fri, 6 Dec 2024 16:18:32 -0500 (EST) Received: from smtpin20.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay05.hostedemail.com (Postfix) with ESMTP id 55F3942F87 for ; Fri, 6 Dec 2024 21:18:32 +0000 (UTC) X-FDA: 82865796804.20.F637621 Received: from mail-il1-f205.google.com (mail-il1-f205.google.com [209.85.166.205]) by imf08.hostedemail.com (Postfix) with ESMTP id 1EC44160014 for ; Fri, 6 Dec 2024 21:18:18 +0000 (UTC) Authentication-Results: imf08.hostedemail.com; dkim=none; spf=pass (imf08.hostedemail.com: domain of 3JWpTZwkbAIg4ABwmxxq3m11up.s00sxq64q3o0z5qz5.o0y@M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com designates 209.85.166.205 as permitted sender) smtp.mailfrom=3JWpTZwkbAIg4ABwmxxq3m11up.s00sxq64q3o0z5qz5.o0y@M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; dmarc=fail reason="SPF not aligned (relaxed), No valid DKIM" header.from=appspotmail.com (policy=none) ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1733519894; a=rsa-sha256; cv=none; b=KUEODNG8BVbzTRf+UfBoEHsZi1ZkHAvU/RYFvd2abVYPdVWrzaZm4PQLG+I20ddvzjmQJF B+YP6P3X3UkLpDdL0u/AZeNUGvWcioSQYKRMLaxbtap7+P2J5P0mPxV32vkDCodNcvC+/s FKi8wk6VprqvUt8IH7heOftoebOBkow= ARC-Authentication-Results: i=1; imf08.hostedemail.com; dkim=none; spf=pass (imf08.hostedemail.com: domain of 3JWpTZwkbAIg4ABwmxxq3m11up.s00sxq64q3o0z5qz5.o0y@M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com designates 209.85.166.205 as permitted sender) smtp.mailfrom=3JWpTZwkbAIg4ABwmxxq3m11up.s00sxq64q3o0z5qz5.o0y@M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; dmarc=fail reason="SPF not aligned (relaxed), No valid DKIM" header.from=appspotmail.com (policy=none) ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1733519894; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding:in-reply-to: references; bh=A/jTcw9U659NHfbVfvyGE0LV6xQht4eNjTO4MSHUBKQ=; b=8htb3VScKl9xFH8WVRvkNZstQzX5wFKH9cRAwJtpBNWoEHkRJJe2bU5su0FiXyBwrFumKn Kd10rGXM9hpWXwF0y630ETZLGxFRncmxFOanNbfTYNb5rCQk+xxpGaYGs6Dqsu9J/SPy/d Hdr7g+RtxxGCAJWPTT4nMdO3KXWV4c0= Received: by mail-il1-f205.google.com with SMTP id e9e14a558f8ab-3a81754abb7so9699485ab.2 for ; Fri, 06 Dec 2024 13:18:30 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1733519909; x=1734124709; h=to:from:subject:message-id:date:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=A/jTcw9U659NHfbVfvyGE0LV6xQht4eNjTO4MSHUBKQ=; b=UtE7AziCTZuHXFQYe03/Sw+rCoLM+r0CzsdpFI53TfSIKdH0Fgphd86AAoLr1HGRJe DR7hRuCqM4Cqqbrj3bOOmhDso9Di2yMRq30u/+J08nudW6aZr/3Pgnq5tCT+DHOE/y5X 8+9QZDy6p+zR1FoljZuPfCLRvnKodO0Jd46i9Wq7ca+WqwLNXwU5ODJpmQXHeb0bUagn gQXPvctegvTpfI5WEWml4gmmeaD+uvAGga5LZ2zgPP+jEMumr85t3e6lkKWsXaIbcWV9 8ogCKvy/9kRfSg98dci1CLMPD5bqcAgLS2btQqHTRPAADWfcMgRpf9HR24p1XnCW3qWZ rs3w== X-Forwarded-Encrypted: i=1; AJvYcCVYJjKiZIoO7cM2uOYg50/zT8vjSitL4E6Znlg5aaCSBi8piqbB0YMHXpSSenDLxyHpE5+1NXqUlQ==@kvack.org X-Gm-Message-State: AOJu0Yw2MZA3UC89JLhPC1Rlgi0K3trGBRVV031POOmK4YHGt6fKcMLL wZBm0on8Y8wa+XhvtpoEpGYEAdVQOaiG8RC3VZfyV2Tzt+Doim8IcsJQqt8LWGC/RImHHvNZ+eH 30D869u3YKYwsG8kEyybxrQ8MuVO2pGD2p7rCT0IjZe9qiKl60QWxocM= X-Google-Smtp-Source: AGHT+IGRx17FYEQ2w8eg11cCqnscOvxvcb7OopEbd3IvadfHyFoDYjmAe7ikiLwJNSkWZSKBW4xkLuG6ZxmqYx9iO9nV8zfaAtOK MIME-Version: 1.0 X-Received: by 2002:a05:6e02:1a8c:b0:3a0:8c5f:90c0 with SMTP id e9e14a558f8ab-3a811d87696mr53753785ab.10.1733519909710; Fri, 06 Dec 2024 13:18:29 -0800 (PST) Date: Fri, 06 Dec 2024 13:18:29 -0800 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <67536a25.050a0220.a30f1.0149.GAE@google.com> Subject: [syzbot] [mm?] KASAN: slab-use-after-free Read in __mmap_region From: syzbot To: Liam.Howlett@oracle.com, akpm@linux-foundation.org, jannh@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, lorenzo.stoakes@oracle.com, syzkaller-bugs@googlegroups.com, vbabka@suse.cz Content-Type: text/plain; charset="UTF-8" X-Rspamd-Queue-Id: 1EC44160014 X-Stat-Signature: piw85i93s1o1pwjrjdt9hr81n68r1r5j X-Rspam-User: X-Rspamd-Server: rspam09 X-HE-Tag: 1733519898-175052 X-HE-Meta: U2FsdGVkX187KhjEIgCxe/lmkDMUweXSJkr0DZBhh2D/sDANWg/RJ6bXLmEFfEWIpK9Dc0jqOf66t+peAvXXq0EQfuPjWsSiT81ISuArVgF3mlrUkKrDo+Sn66lowXXq1bCt4a+hSXgvEiD6xGFuhvWSaIZ2DFhV0oHIYWqDtc2Vg8QxJ1+pCJaYmzFxG8GPEbHOk5AifOHXyt0+5ncb+lP7oqObwSkvFs4NVZjlrptk+Vt9tMtr0iltoAr74XXhdYXaO7eTlmrDw/pJa4aabjK+LlVlYxEwcqRIYibJsRTxXDRb1bxS/HhiKXlx2EJdHvMrPFvrg0N9Cb4bsC3WhBhh7sbZyZeeDR9UZCUbTZk6+idV2cYry+7Fb8shCwl622thDPij1RH/kMlsmG57UxKXqI22QslMLLMXEDh/aiNp4GV/XWoUq2SSvT6/7RRMYVhUGHWlhlr7r0L5EJv5sbYMqyzioUVHrdIen78JKpjzYjSoqdfdwtl20PzSNIbF5O8gCufHVhAfGAmnA37qWtQqA8owiIuxnnOi+xxKxuyH+rics6NXG+TX/LczckN9/l9yx9L09iskIc7DR+QQAboMJs8mW/rLAO/JNTn8rTMPzUX38A3RVAwtCVzyyBl3iSfcrQTmqNa4UGbe+xMDMpjBN4vrVb+bM03K4cnuxnCh+yqd3NDNnntrdEOOjihzyMF9t/KlDXzOOSz9JFVawI7wb3n0w+H4i86gye19lpdNrEvnsMXn6ot2s/DHnR8C8FCi8J8V+HWLzEdf+lHkbGtXaaIgb3BkxK3/rK2m8s9yCKnqJF0cBizrkuvd/lTLp1Pc9dQvSKu2wdtz+wVCgRfP4y1FIfVeY2COBXGy/ibYYe7ssm2cf+zcDizvMLMupbRqdz3scnIuVAx0tFTm9BDABDhXUEGA2UhlYjnSJRUsnuqPdmosA0+945C5qQOBwSgmvvcDGJi1XjjwXNw 2vIMCqNE R8Aa170BdS55hPLirxggncCFhR65j9lGTkQi5aCSH8c+x1LPyrxfM0kJx6ibOq3EqzSJBxe1VHFhK4leedDrXe/VfEziPVeUcQMiS2XhjzILxgDdZsBGNBwShSTjvIz2brrfYUkfdbVs1F3QtMS4tOBgz0dnvZrczv9se47e6/UnuQcqe7Kif6dQXvUoy2pGldTOA/emqWEiKR7aXnO2krem7tX2K0chdqxeCTF10Oi+uD3RBDF3CePSwbeYL4Z56rS/rqu70vjP/N1q/UP6rWJMP2LpKeelIqaf3FyZLTToYUF5lFL1xA4c1DH95nNw6tVylHj/lx/QoI2MpTKCPb4hvLdJJQldUp1Q0PquJieokRYvXGEAfMPefU20RxEpUk3LAcrlDA8P0dMmLVkOBTWevt5ttytlX00HCc7h83kjnSxqvaEQ4i9VIyd68Y21jSLHm5/Tnbr9cXEpUfyHC7as0llihhYb4TYNdPh1SVpO3FgUb8Pv06GGSCUfSiZJZGedmPCf5e5w6Ef+/lvBf3VhtQIT120yCc8RA6VXOX3iSrwnzOPEFko4W9vJgFRliI24BeP1kNr3rv/ZB/I8sZnliYo0cANGMLbWiIVTuODQ5UBNJATmCuuW6zLyHDBYlGXZsVA0KErBLGDeocrWbWFPCYnYdRSm7QnJX0WiEbaFm962740ETPWO+5VxWuKPQDzVpYPjeCnV2YhvnSBFpFsMDvfR/s0h3r46K7ce1XH75dEnBDzaIzRrL9UEx8fUW2kz7GrsT1SdzIaB+xzsU6/tTyI5qhPxman0577yD8LPKdwqU82en5PV/HYxXboxytwbRDpeElqeYefM+DT2YKKuJyoiGvf2GY6ddueMOsn4+us/ovUp7vvSbq9tCJyldUSV328j0MEce+YIRLZaPtPzPLVmJ452c837zofoSyhUve1eAESV7CfE1Zzr/YJTbQfanncmlnp/BSucfNhpzdkvre2cm MNeD3ArN Q7Kw19eKqncdsS8w36/nzITeu/C5swkCyQ0uu6nSFajY22/8+I+06yEDkXZHqIxDx2T5rIVvaXTFu0EDaefO3Q2eVm15u+EdKpWsdHu+zDhwyIZKDTQGamXzaiaiB4zQqQXzdZ3TUmNPGK4SQZvoTdg+OovtcrylJoqQke5uiitggDy/WLMrT9E2U7tdgJJUrVpTQE1I0OSS448mODg6kP2f7F0JMdUdGHvswFhkf+RJrfejtDcQo0aBhgSJRmWvh2hJrYdm2Er0qIqbC5fJdlQ3ENYALE9OrsP14w9fYMiGLjbFfI13iuNlbxwWrhN03PEbEU103Qgl0NHDiYDdDuouVsyTxALzNQtV5MdZLQtvd9S+RjA5bM/2KlE82iyQCeySkZCrn5oyBzLrpOqVe+ELn2UYBPZ1 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: Hello, syzbot found the following issue on: HEAD commit: e70140ba0d2b Get rid of 'remove_new' relic from platform d.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=13300330580000 kernel config: https://syzkaller.appspot.com/x/.config?x=50c7a61469ce77e7 dashboard link: https://syzkaller.appspot.com/bug?extid=91cf8da9401355f946c3 compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=124130df980000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10a280f8580000 Downloadable assets: disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7feb34a89c2a/non_bootable_disk-e70140ba.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/91f313d8125b/vmlinux-e70140ba.xz kernel image: https://storage.googleapis.com/syzbot-assets/a9bdf286943a/bzImage-e70140ba.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+91cf8da9401355f946c3@syzkaller.appspotmail.com ================================================================== BUG: KASAN: slab-use-after-free in __mmap_complete mm/vma.c:2408 [inline] BUG: KASAN: slab-use-after-free in __mmap_region+0x1802/0x2cd0 mm/vma.c:2469 Read of size 8 at addr ffff8880403a6118 by task syz-executor239/5461 CPU: 0 UID: 0 PID: 5461 Comm: syz-executor239 Not tainted 6.13.0-rc1-syzkaller-00001-ge70140ba0d2b #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0x169/0x550 mm/kasan/report.c:489 kasan_report+0x143/0x180 mm/kasan/report.c:602 __mmap_complete mm/vma.c:2408 [inline] __mmap_region+0x1802/0x2cd0 mm/vma.c:2469 mmap_region+0x226/0x2c0 mm/mmap.c:1347 do_mmap+0x8f0/0x1000 mm/mmap.c:496 vm_mmap_pgoff+0x1dd/0x3d0 mm/util.c:580 ksys_mmap_pgoff+0x4eb/0x720 mm/mmap.c:542 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f8522e6cb29 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffc930f7e48 EFLAGS: 00000246 ORIG_RAX: 0000000000000009 RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8522e6cb29 RDX: 0000000000000000 RSI: 0000000000001008 RDI: 0000000020ffc000 RBP: 00000000000f4240 R08: 0000000000000003 R09: 0000000000000000 R10: 0000000000000013 R11: 0000000000000246 R12: 000000000001294d R13: 00007ffc930f7e6c R14: 00007ffc930f7e80 R15: 00007ffc930f7e70 Allocated by task 5461: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3f/0x80 mm/kasan/common.c:68 unpoison_slab_object mm/kasan/common.c:319 [inline] __kasan_slab_alloc+0x66/0x80 mm/kasan/common.c:345 kasan_slab_alloc include/linux/kasan.h:250 [inline] slab_post_alloc_hook mm/slub.c:4104 [inline] slab_alloc_node mm/slub.c:4153 [inline] kmem_cache_alloc_noprof+0x1d9/0x380 mm/slub.c:4160 vm_area_alloc+0x24/0x1d0 kernel/fork.c:472 __mmap_new_vma mm/vma.c:2340 [inline] __mmap_region+0x196e/0x2cd0 mm/vma.c:2456 mmap_region+0x226/0x2c0 mm/mmap.c:1347 do_mmap+0x8f0/0x1000 mm/mmap.c:496 vm_mmap_pgoff+0x1dd/0x3d0 mm/util.c:580 ksys_mmap_pgoff+0x4eb/0x720 mm/mmap.c:542 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 5295: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3f/0x80 mm/kasan/common.c:68 kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582 poison_slab_object mm/kasan/common.c:247 [inline] __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264 kasan_slab_free include/linux/kasan.h:233 [inline] slab_free_hook mm/slub.c:2338 [inline] slab_free mm/slub.c:4598 [inline] kmem_cache_free+0x195/0x410 mm/slub.c:4700 rcu_do_batch kernel/rcu/tree.c:2567 [inline] rcu_core+0xaaa/0x17a0 kernel/rcu/tree.c:2823 handle_softirqs+0x2d4/0x9b0 kernel/softirq.c:554 do_softirq+0x11b/0x1e0 kernel/softirq.c:455 __local_bh_enable_ip+0x1bb/0x200 kernel/softirq.c:382 lock_sock include/net/sock.h:1617 [inline] tcp_sendmsg+0x22/0x50 net/ipv4/tcp.c:1357 sock_sendmsg_nosec net/socket.c:711 [inline] __sock_sendmsg+0x1a6/0x270 net/socket.c:726 sock_write_iter+0x2d7/0x3f0 net/socket.c:1147 new_sync_write fs/read_write.c:586 [inline] vfs_write+0xaeb/0xd30 fs/read_write.c:679 ksys_write+0x18f/0x2b0 fs/read_write.c:731 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Last potentially related work creation: kasan_save_stack+0x3f/0x60 mm/kasan/common.c:47 __kasan_record_aux_stack+0xac/0xc0 mm/kasan/generic.c:544 __call_rcu_common kernel/rcu/tree.c:3086 [inline] call_rcu+0x167/0xa70 kernel/rcu/tree.c:3190 vma_complete+0x97f/0xb50 mm/vma.c:310 commit_merge+0x6f6/0x760 mm/vma.c:674 vma_merge_existing_range+0x13b8/0x16f0 mm/vma.c:897 __mmap_region+0x175b/0x2cd0 mm/vma.c:2466 mmap_region+0x226/0x2c0 mm/mmap.c:1347 do_mmap+0x8f0/0x1000 mm/mmap.c:496 vm_mmap_pgoff+0x1dd/0x3d0 mm/util.c:580 ksys_mmap_pgoff+0x4eb/0x720 mm/mmap.c:542 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f The buggy address belongs to the object at ffff8880403a60f8 which belongs to the cache vm_area_struct of size 184 The buggy address is located 32 bytes inside of freed 184-byte region [ffff8880403a60f8, ffff8880403a61b0) The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x403a6 flags: 0x4fff00000000000(node=1|zone=1|lastcpupid=0x7ff) page_type: f5(slab) raw: 04fff00000000000 ffff88801be90b40 dead000000000122 0000000000000000 raw: 0000000000000000 0000000000100010 00000001f5000000 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as allocated page last allocated via order 0, migratetype Unmovable, gfp_mask 0x52cc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP), pid 5461, tgid 5461 (syz-executor239), ts 76280088571, free_ts 76278589874 set_page_owner include/linux/page_owner.h:32 [inline] post_alloc_hook+0x1f3/0x230 mm/page_alloc.c:1556 prep_new_page mm/page_alloc.c:1564 [inline] get_page_from_freelist+0x365c/0x37a0 mm/page_alloc.c:3474 __alloc_pages_noprof+0x292/0x710 mm/page_alloc.c:4751 alloc_pages_mpol_noprof+0x3e8/0x680 mm/mempolicy.c:2265 alloc_slab_page+0x6a/0x140 mm/slub.c:2408 allocate_slab+0x5a/0x2f0 mm/slub.c:2574 new_slab mm/slub.c:2627 [inline] ___slab_alloc+0xcd1/0x14b0 mm/slub.c:3815 __slab_alloc+0x58/0xa0 mm/slub.c:3905 __slab_alloc_node mm/slub.c:3980 [inline] slab_alloc_node mm/slub.c:4141 [inline] kmem_cache_alloc_noprof+0x268/0x380 mm/slub.c:4160 vm_area_dup+0x27/0x290 kernel/fork.c:487 __split_vma+0x1cb/0xc50 mm/vma.c:434 vms_gather_munmap_vmas+0x4c1/0x1600 mm/vma.c:1288 __mmap_prepare mm/vma.c:2241 [inline] __mmap_region+0x7de/0x2cd0 mm/vma.c:2443 mmap_region+0x226/0x2c0 mm/mmap.c:1347 do_mmap+0x8f0/0x1000 mm/mmap.c:496 vm_mmap_pgoff+0x1dd/0x3d0 mm/util.c:580 page last free pid 5457 tgid 5457 stack trace: reset_page_owner include/linux/page_owner.h:25 [inline] free_pages_prepare mm/page_alloc.c:1127 [inline] free_unref_folios+0xf62/0x1a90 mm/page_alloc.c:2704 folios_put_refs+0x76c/0x860 mm/swap.c:962 free_pages_and_swap_cache+0x5c8/0x690 mm/swap_state.c:335 __tlb_batch_free_encoded_pages mm/mmu_gather.c:136 [inline] tlb_batch_pages_flush mm/mmu_gather.c:149 [inline] tlb_flush_mmu_free mm/mmu_gather.c:366 [inline] tlb_flush_mmu+0x3a3/0x680 mm/mmu_gather.c:373 tlb_finish_mmu+0xd4/0x200 mm/mmu_gather.c:465 exit_mmap+0x496/0xc20 mm/mmap.c:1680 __mmput+0x115/0x3c0 kernel/fork.c:1353 exit_mm+0x220/0x310 kernel/exit.c:570 do_exit+0x9b2/0x28e0 kernel/exit.c:925 do_group_exit+0x207/0x2c0 kernel/exit.c:1087 __do_sys_exit_group kernel/exit.c:1098 [inline] __se_sys_exit_group kernel/exit.c:1096 [inline] __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1096 x64_sys_call+0x26a8/0x26b0 arch/x86/include/generated/asm/syscalls_64.h:232 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Memory state around the buggy address: ffff8880403a6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff8880403a6080: 00 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fa >ffff8880403a6100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff8880403a6180: fb fb fb fb fb fb fc fc fc fc fc fc fc fc fa fb ffff8880403a6200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ================================================================== --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing. If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup