blob: 8735779ac0f1fc857b6d51ca0439e6afcf586272 [file] [log] [blame]
TITLE: BUG: unable to handle kernel NULL pointer dereference in sock_poll
[ 27.294614] random: sshd: uninitialized urandom read (32 bytes read)
[ 27.396136] BUG: unable to handle kernel NULL pointer dereference at 0000000000000000
[ 27.404160] PGD 1b5d9f067 P4D 1b5d9f067 PUD 1affb3067 PMD 0
[ 27.409971] Oops: 0010 [#1] SMP KASAN
[ 27.413759] CPU: 1 PID: 4557 Comm: syz-executor307 Not tainted 4.17.0+ #89
[ 27.420761] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
[ 27.430112] RIP: 0010: (null)
[ 27.433977] Code: Bad RIP value.
[ 27.437337] RSP: 0018:ffff8801afb4f3a0 EFLAGS: 00010246
[ 27.442687] RAX: 0000000000000000 RBX: ffff8801d96f3800 RCX: 1ffffffff10ea5ed
[ 27.449978] RDX: ffff8801afb4fc00 RSI: ffff8801aba65600 RDI: ffff8801b0621080
[ 27.457271] RBP: ffff8801afb4f510 R08: ffff8801afab4cf8 R09: 0000000000000006
[ 27.464557] R10: ffff8801afab44c0 R11: 0000000000000000 R12: 1ffff10035f69e79
[ 27.471838] R13: ffff8801afb4fc00 R14: ffff8801d96f3812 R15: ffff8801d96f3c58
[ 27.479093] FS: 0000000001d2b880(0000) GS:ffff8801daf00000(0000) knlGS:0000000000000000
[ 27.487391] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 27.493252] CR2: ffffffffffffffd6 CR3: 00000001b5858000 CR4: 00000000001406e0
[ 27.500516] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 27.507765] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[ 27.515016] Call Trace:
[ 27.517597] ? smc_poll+0x211/0xdd0
[ 27.521220] ? __smc_connect+0xa90/0xa90
[ 27.525261] ? save_stack+0x43/0xd0
[ 27.528881] ? kasan_kmalloc+0xc4/0xe0
[ 27.532748] ? kasan_slab_alloc+0x12/0x20
[ 27.536880] ? kmem_cache_alloc+0x12e/0x760
[ 27.541185] ? ep_insert+0x270/0x1c00
[ 27.544974] ? __x64_sys_epoll_ctl+0xef1/0x10f0
[ 27.549631] ? do_syscall_64+0x1b1/0x800
[ 27.553676] ? entry_SYSCALL_64_after_hwframe+0x49/0xbe
[ 27.559040] ? graph_lock+0x170/0x170
[ 27.562825] ? debug_check_no_locks_freed+0x310/0x310
[ 27.567995] ? handle_mm_fault+0x53a/0xc70
[ 27.572218] ? find_held_lock+0x36/0x1c0
[ 27.576271] ? print_usage_bug+0xc0/0xc0
[ 27.580316] sock_poll+0x1d1/0x710
[ 27.583839] ? __smc_connect+0xa90/0xa90
[ 27.587885] ? sock_get_poll_head+0x460/0x460
[ 27.592380] ? sock_get_poll_head+0x460/0x460
[ 27.596873] vfs_poll+0x77/0x2a0
[ 27.600226] ep_item_poll.isra.15+0x2c1/0x390
[ 27.604705] ? rcu_read_lock_sched_held+0x108/0x120
[ 27.609701] ? ep_eventpoll_poll+0x1f0/0x1f0
[ 27.614092] ? ep_insert+0x270/0x1c00
[ 27.617873] ep_insert+0x6b8/0x1c00
[ 27.621485] ? ep_send_events_proc+0xee0/0xee0
[ 27.626053] ? lock_release+0xa10/0xa10
[ 27.630009] ? check_same_owner+0x320/0x320
[ 27.634318] ? rcu_note_context_switch+0x710/0x710
[ 27.639247] ? __might_sleep+0x95/0x190
[ 27.643206] ? kasan_check_write+0x14/0x20
[ 27.647439] ? __mutex_lock+0x7d9/0x17f0
[ 27.651485] ? __x64_sys_epoll_ctl+0x518/0x10f0
[ 27.656137] ? find_held_lock+0x36/0x1c0
[ 27.660181] ? mutex_trylock+0x2a0/0x2a0
[ 27.664221] ? trace_hardirqs_on_caller+0x421/0x5c0
[ 27.669220] ? graph_lock+0x170/0x170
[ 27.673004] ? lockdep_init_map+0x9/0x10
[ 27.677054] ? debug_mutex_init+0x2d/0x60
[ 27.681181] ? pud_val+0x80/0xf0
[ 27.684539] ? pmd_val+0xf0/0xf0
[ 27.687889] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20
[ 27.693410] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20
[ 27.698929] ? __handle_mm_fault+0x93a/0x4310
[ 27.703425] ? find_held_lock+0x36/0x1c0
[ 27.707473] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20
[ 27.713011] ? __fget_light+0x2ef/0x430
[ 27.716991] ? fget_raw+0x20/0x20
[ 27.720433] ? find_held_lock+0x36/0x1c0
[ 27.724502] ? __might_sleep+0x95/0x190
[ 27.728458] ? clear_tfile_check_list+0x380/0x380
[ 27.733282] ? __sanitizer_cov_trace_switch+0x53/0x90
[ 27.738455] __x64_sys_epoll_ctl+0xef1/0x10f0
[ 27.742968] ? __ia32_sys_epoll_create+0x70/0x70
[ 27.747732] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20
[ 27.753253] ? __do_page_fault+0x441/0xe40
[ 27.757481] ? mm_fault_error+0x380/0x380
[ 27.761614] ? __ia32_sys_fallocate+0xf0/0xf0
[ 27.766097] ? do_syscall_64+0x92/0x800
[ 27.770076] do_syscall_64+0x1b1/0x800
[ 27.773952] ? syscall_return_slowpath+0x5c0/0x5c0
[ 27.778863] ? syscall_return_slowpath+0x30f/0x5c0
[ 27.783776] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20
[ 27.789301] ? retint_user+0x18/0x18
[ 27.793001] ? trace_hardirqs_off_thunk+0x1a/0x1c
[ 27.797832] entry_SYSCALL_64_after_hwframe+0x49/0xbe
[ 27.803007] RIP: 0033:0x43fcc9
[ 27.806199] Code: 18 89 d0 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 6b 45 00 00 c3 66 2e 0f 1f 84 00 00 00 00
[ 27.825321] RSP: 002b:00007ffdf746b148 EFLAGS: 00000217 ORIG_RAX: 00000000000000e9
[ 27.833031] RAX: ffffffffffffffda RBX: 00000000004002c8 RCX: 000000000043fcc9
[ 27.840297] RDX: 0000000000000003 RSI: 0000000000000001 RDI: 0000000000000004
[ 27.847550] RBP: 00000000006ca018 R08: 00000000004002c8 R09: 00000000004002c8
[ 27.854800] R10: 0000000020000000 R11: 0000000000000217 R12: 00000000004015f0
[ 27.862059] R13: 0000000000401680 R14: 0000000000000000 R15: 0000000000000000
[ 27.869311] Modules linked in:
[ 27.872492] Dumping ftrace buffer:
[ 27.876013] (ftrace buffer empty)
[ 27.879706] CR2: 0000000000000000
[ 27.883769] ---[ end trace 64c0103aec0131a5 ]---
[ 27.888586] RIP: 0010: (null)
[ 27.892502] Code: Bad RIP value.
[ 27.895905] RSP: 0018:ffff8801afb4f3a0 EFLAGS: 00010246
[ 27.901308] RAX: 0000000000000000 RBX: ffff8801d96f3800 RCX: 1ffffffff10ea5ed
[ 27.908601] RDX: ffff8801afb4fc00 RSI: ffff8801aba65600 RDI: ffff8801b0621080
[ 27.915888] RBP: ffff8801afb4f510 R08: ffff8801afab4cf8 R09: 0000000000000006
[ 27.923184] R10: ffff8801afab44c0 R11: 0000000000000000 R12: 1ffff10035f69e79
[ 27.930483] R13: ffff8801afb4fc00 R14: ffff8801d96f3812 R15: ffff8801d96f3c58
[ 27.937781] FS: 0000000001d2b880(0000) GS:ffff8801daf00000(0000) knlGS:0000000000000000
[ 27.946039] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 27.951941] CR2: ffffffffffffffd6 CR3: 00000001b5858000 CR4: 00000000001406e0
[ 27.959240] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 27.966563] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[ 27.973863] Kernel panic - not syncing: Fatal exception
[ 27.979760] Dumping ftrace buffer:
[ 27.983289] (ftrace buffer empty)
[ 27.986979] Kernel Offset: disabled
[ 27.990589] Rebooting in 86400 seconds..