kernel BUG at mm/slab.c:LINE! (3)

2018-11-13 Thread syzbot

Hello,

syzbot found the following crash on:

HEAD commit:3e536cff3424 net: phy: check if advertising is zero using ..
git tree:   net-next
console output: https://syzkaller.appspot.com/x/log.txt?x=16f95b8340
kernel config:  https://syzkaller.appspot.com/x/.config?x=4a0a89f12ca9b0f5
dashboard link: https://syzkaller.appspot.com/bug?extid=2182db487a523d86bf34
compiler:   gcc (GCC) 8.0.1 20180413 (experimental)
syz repro:  https://syzkaller.appspot.com/x/repro.syz?x=148d46d540
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=15c6a22540

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2182db487a523d86b...@syzkaller.appspotmail.com

[ cut here ]
DEBUG_LOCKS_WARN_ON(depth >= MAX_LOCK_DEPTH)
[ cut here ]
kernel BUG at mm/slab.c:4425!
invalid opcode:  [#1] PREEMPT SMP KASAN
CPU: 0 PID: -642842048 Comm: ksoftirqd/0 Not tainted 4.20.0-rc2+ #294
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011

RIP: 0010:__check_heap_object+0xa7/0xb5 mm/slab.c:4450
Code: 48 c7 c7 15 73 12 89 e8 97 e3 0a 00 5d c3 41 8b 91 04 01 00 00 48 29  
c7 48 39 d7 77 be 48 01 d0 48 29 c8 48 39 f0 72 b3 5d c3 <0f> 0b 48 c7 c7  
15 73 12 89 e8 fd eb 0a 00 44 89 e9 48 c7 c7 d0 73

RSP: 0018:8881d9af0030 EFLAGS: 00010093
RAX: 000a57eb RBX: 11103b35e00d RCX: 000c
RDX: 8881d9af0240 RSI: 0002 RDI: 8881d9af01d8
RBP: 8881d9af0030 R08: 8881d9af0240 R09: 8881da970180
R10: 4afd69e7 R11:  R12: 8881d9af01d8
R13: 0002 R14: ea000766bc00 R15: 0001
FS:  () GS:8881dae0() knlGS:
CS:  0010 DS:  ES:  CR0: 80050033
CR2: 0068 CR3: 0001bb987000 CR4: 001406f0
Call Trace:
Modules linked in:
---[ end trace 1c9eb38e9e38ee03 ]---
RIP: 0010:__check_heap_object+0xa7/0xb5 mm/slab.c:4450
Code: 48 c7 c7 15 73 12 89 e8 97 e3 0a 00 5d c3 41 8b 91 04 01 00 00 48 29  
c7 48 39 d7 77 be 48 01 d0 48 29 c8 48 39 f0 72 b3 5d c3 <0f> 0b 48 c7 c7  
15 73 12 89 e8 fd eb 0a 00 44 89 e9 48 c7 c7 d0 73

RSP: 0018:8881d9af0030 EFLAGS: 00010093
RAX: 000a57eb RBX: 11103b35e00d RCX: 000c
RDX: 8881d9af0240 RSI: 0002 RDI: 8881d9af01d8
RBP: 8881d9af0030 R08: 8881d9af0240 R09: 8881da970180
R10: 4afd69e7 R11:  R12: 8881d9af01d8
R13: 0002 R14: ea000766bc00 R15: 0001
FS:  () GS:8881dae0() knlGS:
CS:  0010 DS:  ES:  CR0: 80050033
CR2: 0068 CR3: 0001bb987000 CR4: 001406f0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkal...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with  
syzbot.

syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches


kernel BUG at mm/slab.c:LINE! (3)

2018-11-13 Thread syzbot

Hello,

syzbot found the following crash on:

HEAD commit:3e536cff3424 net: phy: check if advertising is zero using ..
git tree:   net-next
console output: https://syzkaller.appspot.com/x/log.txt?x=16f95b8340
kernel config:  https://syzkaller.appspot.com/x/.config?x=4a0a89f12ca9b0f5
dashboard link: https://syzkaller.appspot.com/bug?extid=2182db487a523d86bf34
compiler:   gcc (GCC) 8.0.1 20180413 (experimental)
syz repro:  https://syzkaller.appspot.com/x/repro.syz?x=148d46d540
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=15c6a22540

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2182db487a523d86b...@syzkaller.appspotmail.com

[ cut here ]
DEBUG_LOCKS_WARN_ON(depth >= MAX_LOCK_DEPTH)
[ cut here ]
kernel BUG at mm/slab.c:4425!
invalid opcode:  [#1] PREEMPT SMP KASAN
CPU: 0 PID: -642842048 Comm: ksoftirqd/0 Not tainted 4.20.0-rc2+ #294
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011

RIP: 0010:__check_heap_object+0xa7/0xb5 mm/slab.c:4450
Code: 48 c7 c7 15 73 12 89 e8 97 e3 0a 00 5d c3 41 8b 91 04 01 00 00 48 29  
c7 48 39 d7 77 be 48 01 d0 48 29 c8 48 39 f0 72 b3 5d c3 <0f> 0b 48 c7 c7  
15 73 12 89 e8 fd eb 0a 00 44 89 e9 48 c7 c7 d0 73

RSP: 0018:8881d9af0030 EFLAGS: 00010093
RAX: 000a57eb RBX: 11103b35e00d RCX: 000c
RDX: 8881d9af0240 RSI: 0002 RDI: 8881d9af01d8
RBP: 8881d9af0030 R08: 8881d9af0240 R09: 8881da970180
R10: 4afd69e7 R11:  R12: 8881d9af01d8
R13: 0002 R14: ea000766bc00 R15: 0001
FS:  () GS:8881dae0() knlGS:
CS:  0010 DS:  ES:  CR0: 80050033
CR2: 0068 CR3: 0001bb987000 CR4: 001406f0
Call Trace:
Modules linked in:
---[ end trace 1c9eb38e9e38ee03 ]---
RIP: 0010:__check_heap_object+0xa7/0xb5 mm/slab.c:4450
Code: 48 c7 c7 15 73 12 89 e8 97 e3 0a 00 5d c3 41 8b 91 04 01 00 00 48 29  
c7 48 39 d7 77 be 48 01 d0 48 29 c8 48 39 f0 72 b3 5d c3 <0f> 0b 48 c7 c7  
15 73 12 89 e8 fd eb 0a 00 44 89 e9 48 c7 c7 d0 73

RSP: 0018:8881d9af0030 EFLAGS: 00010093
RAX: 000a57eb RBX: 11103b35e00d RCX: 000c
RDX: 8881d9af0240 RSI: 0002 RDI: 8881d9af01d8
RBP: 8881d9af0030 R08: 8881d9af0240 R09: 8881da970180
R10: 4afd69e7 R11:  R12: 8881d9af01d8
R13: 0002 R14: ea000766bc00 R15: 0001
FS:  () GS:8881dae0() knlGS:
CS:  0010 DS:  ES:  CR0: 80050033
CR2: 0068 CR3: 0001bb987000 CR4: 001406f0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkal...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with  
syzbot.

syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches