1
loop5: detected capacity change from 0 to 512
9pnet_fd: Insufficient options for proto=fd
netlink: 8 bytes leftover after parsing attributes in process `syz.3.6268'.
------------[ cut here ]------------
WARNING: CPU: 0 PID: 20628 at net/ipv4/ipmr.c:440 ipmr_free_table net/ipv4/ipmr.c:440 [inline]
WARNING: CPU: 0 PID: 20628 at net/ipv4/ipmr.c:440 ipmr_rules_exit+0x13a/0x1c0 net/ipv4/ipmr.c:361
FAULT_INJECTION: forcing a failure.
name fail_usercopy, interval 1, probability 0, space 0, times 0
Modules linked in:
CPU: 1 UID: 0 PID: 20645 Comm: syz.4.6269 Not tainted 6.15.0-rc5 #1 PREEMPT(voluntary) 
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xfa/0x120 lib/dump_stack.c:120
 fail_dump lib/fault-inject.c:73 [inline]
 should_fail_ex+0x4d7/0x5e0 lib/fault-inject.c:174
 copy_from_user_iter lib/iov_iter.c:50 [inline]
 iterate_ubuf include/linux/iov_iter.h:30 [inline]
 iterate_and_advance2 include/linux/iov_iter.h:300 [inline]
 iterate_and_advance include/linux/iov_iter.h:328 [inline]
 __copy_from_iter lib/iov_iter.c:249 [inline]
 _copy_from_iter+0x1dc/0x15c0 lib/iov_iter.c:260
 copy_from_iter include/linux/uio.h:228 [inline]
 copy_from_iter_full include/linux/uio.h:245 [inline]
 memcpy_from_msg include/linux/skbuff.h:4180 [inline]
 netlink_sendmsg+0x809/0xd80 net/netlink/af_netlink.c:1868
 sock_sendmsg_nosec net/socket.c:712 [inline]
 __sock_sendmsg net/socket.c:727 [inline]
 ____sys_sendmsg+0xa67/0xc20 net/socket.c:2566
 ___sys_sendmsg+0x10f/0x1b0 net/socket.c:2620
 __sys_sendmsg+0x150/0x200 net/socket.c:2652
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xbf/0x1d0 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f9375dea12d
Code: 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f93743a6fa8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f93760f5fa0 RCX: 00007f9375dea12d
RDX: 00000000000008c0 RSI: 00002000000003c0 RDI: 0000000000000004
RBP: 00007f93743a7020 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
R13: 0000000000000000 R14: 00007f9375d862a0 R15: 00007f9374387000
 </TASK>

CPU: 0 UID: 0 PID: 20628 Comm: syz.5.6264 Not tainted 6.15.0-rc5 #1 PREEMPT(voluntary) 
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
RIP: 0010:ipmr_free_table net/ipv4/ipmr.c:440 [inline]
RIP: 0010:ipmr_rules_exit+0x13a/0x1c0 net/ipv4/ipmr.c:361
Code: ff df 48 c1 ea 03 80 3c 02 00 75 7d 48 c7 83 58 08 00 00 00 00 00 00 5b 5d 41 5c 41 5d 41 5e e9 c7 b7 0b fd e8 a7 01 6e fd 90 <0f> 0b 90 eb 93 e8 9c 01 6e fd 0f b6 2d d4 85 16 02 31 ff 89 ee e8
RSP: 0018:ffff88810a627c20 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff888011124680 RCX: ffffffffa2048949
RDX: ffff888112098000 RSI: 0000000000000000 RDI: 0000000000000005
RBP: ffff888107fdc000 R08: 0000000000000000 R09: ffffed10022248fd
R10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000001
R13: ffff888011124ed8 R14: ffff888011124680 R15: fffffbfff4810e78
FS:  00007f36df74e640(0000) GS:ffff888175725000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2bc99456c0 CR3: 0000000106ef9003 CR4: 0000000000770ef0
PKRU: 80000000
Call Trace:
 <TASK>
 ipmr_net_exit_batch+0x53/0xa0 net/ipv4/ipmr.c:3160
 ops_exit_list+0x12b/0x180 net/core/net_namespace.c:177
 setup_net+0x492/0x7a0 net/core/net_namespace.c:396
 copy_net_ns+0x2e3/0x650 net/core/net_namespace.c:518
 create_new_namespaces+0x3f6/0xaf0 kernel/nsproxy.c:110
 unshare_nsproxy_namespaces+0xc0/0x200 kernel/nsproxy.c:228
 ksys_unshare+0x468/0xa10 kernel/fork.c:3375
 __do_sys_unshare kernel/fork.c:3446 [inline]
 __se_sys_unshare kernel/fork.c:3444 [inline]
 __x64_sys_unshare+0x31/0x40 kernel/fork.c:3444
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xbf/0x1d0 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f36e11ba12d
Code: 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f36df74dfa8 EFLAGS: 00000246 ORIG_RAX: 0000000000000110
RAX: ffffffffffffffda RBX: 00007f36e14c6080 RCX: 00007f36e11ba12d
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000048000000
RBP: 00007f36e12a1505 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007f36e11562a0 R15: 00007f36df72e000
 </TASK>
irq event stamp: 13951
hardirqs last  enabled at (13961): [<ffffffff9f536d58>] __up_console_sem+0x78/0x80 kernel/printk/printk.c:344
hardirqs last disabled at (13972): [<ffffffff9f536d3d>] __up_console_sem+0x5d/0x80 kernel/printk/printk.c:342
softirqs last  enabled at (13852): [<ffffffff9f3b274c>] softirq_handle_end kernel/softirq.c:425 [inline]
softirqs last  enabled at (13852): [<ffffffff9f3b274c>] handle_softirqs+0x50c/0x770 kernel/softirq.c:607
softirqs last disabled at (13843): [<ffffffff9f3b2ae4>] __do_softirq kernel/softirq.c:613 [inline]
softirqs last disabled at (13843): [<ffffffff9f3b2ae4>] invoke_softirq kernel/softirq.c:453 [inline]
softirqs last disabled at (13843): [<ffffffff9f3b2ae4>] __irq_exit_rcu+0xc4/0x100 kernel/softirq.c:680
---[ end trace 0000000000000000 ]---

For immediate assistance, please email our customer support: [email protected]

Download RAW File