| TITLE: BUG: unable to handle kernel paging request in lookup_object |
| CORRUPTED: Y |
| |
| [ 946.951230] BUG: unable to handle kernel paging request at 000000fe840fc4b9 |
| [ 946.958357] #PF error: [normal kernel read fault] |
| [ 946.963182] PGD 216999067 P4D 216999067 PUD 0 |
| [ 946.967748] Oops: 0000 [#1] PREEMPT SMP |
| [ 946.967891] PANIC: double fault, error_code: 0x0 |
| [ 946.971713] CPU: 1 PID: 5429 Comm: syz-fuzzer Not tainted 4.20.0+ #139 |
| [ 946.976452] CPU: 0 PID: 0 Comm: swapper/0 Not tainted 4.20.0+ #139 |
| [ 946.983088] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 |
| [ 946.989383] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 |
| [ 946.998723] RIP: 0010:lookup_object+0x11/0x80 |
| [ 947.008055] RIP: 0010:__udp6_lib_lookup+0x10e/0x3e0 |
| [ 947.012528] Code: fd ff 5b 41 5c 41 5d 41 5e 41 5f 5d c3 48 89 f3 eb c2 0f 1f 80 00 00 00 00 48 8b 05 d9 b0 17 03 55 48 89 e5 53 48 85 c0 74 12 <48> 8b 50 30 48 39 fa 76 11 48 8b 40 10 48 85 c0 75 ee 31 db 48 89 |
| [ 947.017522] Code: ff ff 75 20 45 89 e0 4c 89 f1 44 89 fa 44 8b 4d c4 48 8b 75 c8 23 58 10 48 8b 7d d0 48 c1 e3 04 48 03 58 08 8b 45 10 53 41 55 <50> e8 ec e8 ff ff 48 83 c4 20 48 85 c0 48 89 c3 0f 84 1e 01 00 00 |
| [ 947.036399] RSP: 0018:ffffc90001c53c50 EFLAGS: 00010002 |
| [ 947.055277] RSP: 0018:ffff888216f8c000 EFLAGS: 00010282 |
| [ 947.060618] RAX: 000000fe840fc489 RBX: ffff88821cb1bc08 RCX: 3f512e31455ff834 |
| [ 947.065957] RAX: 0000000000000000 RBX: ffffc90002e83540 RCX: ffff8881e73d0050 |
| [ 947.073201] RDX: b60f4100004dd3e8 RSI: 0000000000000001 RDI: ffffea000531bc08 |
| [ 947.080446] RDX: 0000000000000000 RSI: ffff8881e73d0060 RDI: ffff8881da440280 |
| [ 947.087694] RBP: ffffc90001c53c58 R08: ffffffff83e9f520 R09: 0000000000000000 |
| [ 947.094943] RBP: ffff888216f8c068 R08: 0000000000008919 R09: 0000000000000004 |
| [ 947.102190] R10: 0000000000000000 R11: 0000000000000000 R12: ffff88821cb1bff9 |
| [ 947.109434] R10: 0000000000000000 R11: ffff8881e73d0048 R12: 0000000000008919 |
| [ 947.116679] R13: ffff888217cc7500 R14: ffff88821fe00000 R15: 0000000000000000 |
| [ 947.123929] R13: 0000000000000000 R14: ffff8881e73d0050 R15: 0000000000000000 |
| [ 947.131178] FS: 000000c420088768(0000) GS:ffff888218300000(0000) knlGS:0000000000000000 |
| [ 947.138422] FS: 0000000000000000(0000) GS:ffff888218200000(0000) knlGS:0000000000000000 |
| [ 947.146626] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 |
| [ 947.154820] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 |
| [ 947.160681] CR2: 000000fe840fc4b9 CR3: 000000020d5df000 CR4: 00000000001406e0 |
| [ 947.166540] CR2: ffff888216f8bff8 CR3: 000000020d5df000 CR4: 00000000001406f0 |
| [ 947.173789] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 |
| [ 947.181032] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 |
| [ 947.188281] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 |
| [ 947.195529] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 |
| [ 947.202775] Call Trace: |
| [ 947.210019] Call Trace: |
| [ 947.212587] scan_block+0x7f/0x100 |
| [ 947.215140] Kernel panic - not syncing: Machine halted. |
| [ 947.218655] scan_gray_list+0xee/0x160 |
| [ 947.227856] kmemleak_scan+0x2d1/0x560 |
| [ 947.231725] kmemleak_write+0x317/0x39a |
| [ 947.235682] ? rcu_is_watching+0x11/0x40 |
| [ 947.239724] ? refcount_inc_not_zero_checked+0x48/0xb0 |
| [ 947.244983] full_proxy_write+0x6e/0xa0 |
| [ 947.248936] ? full_proxy_poll+0x90/0x90 |
| [ 947.252980] __vfs_write+0x54/0x2a0 |
| [ 947.256586] ? check_preemption_disabled+0x35/0x120 |
| [ 947.261581] ? __this_cpu_preempt_check+0x1c/0x20 |
| [ 947.266402] vfs_write+0xd9/0x210 |
| [ 947.269835] ksys_write+0x62/0xf0 |
| [ 947.273266] __x64_sys_write+0x1e/0x30 |
| [ 947.277137] do_syscall_64+0x7c/0x170 |
| [ 947.280923] entry_SYSCALL_64_after_hwframe+0x44/0xa9 |
| [ 947.286093] RIP: 0033:0x47fc44 |
| [ 947.289270] Code: ff ff cc cc cc cc e8 9b 41 fb ff 48 8b 7c 24 10 48 8b 74 24 18 48 8b 54 24 20 45 31 d2 45 31 c0 45 31 c9 48 8b 44 24 08 0f 05 <48> 3d 01 f0 ff ff 76 20 48 c7 44 24 28 ff ff ff ff 48 c7 44 24 30 |
| [ 947.308155] RSP: 002b:000000c4202c3498 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 |
| [ 947.315845] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 000000000047fc44 |
| [ 947.323098] RDX: 0000000000000004 RSI: 000000c4202c3650 RDI: 0000000000000024 |
| [ 947.330351] RBP: 000000c4202c34e8 R08: 0000000000000000 R09: 0000000000000000 |
| [ 947.337604] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 |
| [ 947.344862] R13: 00000000000000f3 R14: 0000000000000033 R15: 0000000000000002 |
| [ 947.352114] Modules linked in: |
| [ 947.355291] CR2: 000000fe840fc4b9 |
| [ 947.358723] ---[ end trace d847ed588e530688 ]--- |
| [ 947.363464] RIP: 0010:lookup_object+0x11/0x80 |
| [ 947.367939] Code: fd ff 5b 41 5c 41 5d 41 5e 41 5f 5d c3 48 89 f3 eb c2 0f 1f 80 00 00 00 00 48 8b 05 d9 b0 17 03 55 48 89 e5 53 48 85 c0 74 12 <48> 8b 50 30 48 39 fa 76 11 48 8b 40 10 48 85 c0 75 ee 31 db 48 89 |
| [ 947.386824] RSP: 0018:ffffc90001c53c50 EFLAGS: 00010002 |
| [ 947.392169] RAX: 000000fe840fc489 RBX: ffff88821cb1bc08 RCX: 3f512e31455ff834 |
| [ 947.399421] RDX: b60f4100004dd3e8 RSI: 0000000000000001 RDI: ffffea000531bc08 |
| [ 947.406673] RBP: ffffc90001c53c58 R08: ffffffff83e9f520 R09: 0000000000000000 |
| [ 947.413925] R10: 0000000000000000 R11: 0000000000000000 R12: ffff88821cb1bff9 |
| [ 947.421178] R13: ffff888217cc7500 R14: ffff88821fe00000 R15: 0000000000000000 |
| [ 947.428430] FS: 000000c420088768(0000) GS:ffff888218300000(0000) knlGS:0000000000000000 |
| [ 947.436643] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 |
| [ 947.442504] CR2: 000000fe840fc4b9 CR3: 000000020d5df000 CR4: 00000000001406e0 |
| [ 947.449769] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 |
| [ 947.457023] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 |
| [ 947.698208] PANIC: double fault, error_code: 0x0 |
| [ 947.702971] CPU: 1 PID: 5429 Comm: syz-fuzzer Tainted: G D 4.20.0+ #139 |
| [ 947.710994] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 |
| [ 947.720467] RIP: 0010:__sanitizer_cov_trace_pc+0x4/0x50 |
| [ 947.725810] Code: 00 00 48 c7 c7 80 a4 e8 83 e8 48 96 cb 01 e8 03 08 ff ff 5b 41 5c 41 5d 41 5e 5d c3 90 90 90 90 90 90 90 90 90 90 55 48 89 e5 <48> 8b 75 08 65 48 8b 04 25 80 5c 01 00 65 8b 15 98 3d d3 7e 81 e2 |
| [ 947.744691] RSP: 0018:ffffc90001c53918 EFLAGS: 00010093 |
| [ 947.750034] RAX: ffff888216401000 RBX: 0000000000000000 RCX: 0000000000000001 |
| [ 947.757285] RDX: 0000000000000000 RSI: ffffffff811f8e19 RDI: ffffffff83a4aaab |
| [ 947.764533] RBP: ffffc90001c53918 R08: 0000000000000400 R09: 0000000000000041 |
| [ 947.771782] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001 |
| [ 947.779031] R13: ffffc90001c53b00 R14: ffffffff83a4aaab R15: ffffc90001c53a10 |
| [ 947.786286] FS: 000000c420088768(0000) GS:ffff888218300000(0000) knlGS:0000000000000000 |
| [ 947.794489] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 |
| [ 947.800357] CR2: ffffc90001c53908 CR3: 000000020d5df000 CR4: 00000000001406e0 |
| [ 947.807611] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 |
| [ 947.814871] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 |
| [ 947.822119] Call Trace: |
| [ 947.824701] general protection fault: 0000 [#2] PREEMPT SMP |
| [ 947.830491] CPU: 1 PID: 5429 Comm: syz-fuzzer Tainted: G D 4.20.0+ #139 |
| [ 947.838532] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 |
| [ 947.847875] RIP: 0010:vmalloc_fault+0x21c/0x380 |
| [ 947.852530] Code: f8 0f 1f 40 00 41 81 e7 80 00 00 00 48 89 45 d0 49 bf 00 00 00 c0 ff ff 0f 00 4d 0f 44 fd e8 fb 99 1c 00 4c 23 7d d0 4d 01 fc <4f> 8b 24 34 49 f7 c4 9f ff ff ff 0f 84 30 01 00 00 e8 de 99 1c 00 |
| [ 947.871415] RSP: 0018:fffffe0000031c30 EFLAGS: 00010002 |
| [ 947.876757] RAX: ffff888216401000 RBX: ffffc90001c53920 RCX: ffffffff830009b7 |
| [ 947.884038] RDX: 0000000000000000 RSI: ffffffff81118465 RDI: ffff888217caf098 |
| [ 947.891284] RBP: fffffe0000031c60 R08: 0000000000000000 R09: 0000000000000000 |
| [ 947.898535] R10: 0000000000000000 R11: 0000000000000000 R12: 000f888200000070 |
| [ 947.905790] R13: 000ffffffffff000 R14: ffff888000000000 R15: 000f888200000000 |
| [ 947.913044] FS: 000000c420088768(0000) GS:ffff888218300000(0000) knlGS:0000000000000000 |
| [ 947.921251] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 |
| [ 947.927115] CR2: ffffc90001c53920 CR3: 000000020d5df000 CR4: 00000000001406e0 |
| [ 947.934367] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 |
| [ 947.941617] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 |
| [ 947.948872] Call Trace: |
| [ 947.951434] <#DF> |
| [ 947.953572] __do_page_fault+0x23f/0x630 |
| [ 947.957613] ? _raw_spin_unlock_irqrestore+0x33/0x50 |
| [ 947.962702] ? up+0x2d/0x50 |
| [ 947.965619] do_page_fault+0x4e/0x16d |
| [ 947.969407] page_fault+0x1e/0x30 |
| [ 947.972842] RIP: 0010:update_stack_state+0xe7/0x160 |
| [ 947.977837] Code: f6 0f 84 84 00 00 00 4d 89 77 50 49 c7 47 38 00 00 00 00 41 f6 86 88 00 00 00 03 75 64 49 83 ee 80 65 48 8b 04 25 80 5c 01 00 <49> 8b 06 49 89 47 48 48 85 d2 b8 01 00 00 00 75 15 49 89 5f 40 48 |
| [ 947.996718] RSP: 0018:fffffe0000031dc0 EFLAGS: 00010046 |
| [ 948.002059] RAX: ffff888216401000 RBX: ffffc90001c53918 RCX: ffffc90001c54000 |
| [ 948.009312] RDX: 0000000000000000 RSI: ffffc90001c53900 RDI: fffffe0000031e68 |
| [ 948.016564] RBP: fffffe0000031df8 R08: 0000000000000400 R09: 000000000000000b |
| [ 948.023812] R10: 0000000000000000 R11: 0000000000000000 R12: ffffc90001c53928 |
| [ 948.031061] R13: ffffc90001c53918 R14: ffffc90001c53920 R15: fffffe0000031e68 |
| [ 948.038324] __unwind_start+0x4d/0xc0 |
| [ 948.042103] show_trace_log_lvl+0x98/0x296 |
| [ 948.046319] show_regs.cold.16+0x1a/0x1f |
| [ 948.050363] df_debug+0x1c/0x2a |
| [ 948.053630] do_double_fault+0xb5/0x120 |
| [ 948.057588] double_fault+0x1e/0x30 |
| [ 948.061196] RIP: 0010:__sanitizer_cov_trace_pc+0x4/0x50 |
| [ 948.066544] Code: 00 00 48 c7 c7 80 a4 e8 83 e8 48 96 cb 01 e8 03 08 ff ff 5b 41 5c 41 5d 41 5e 5d c3 90 90 90 90 90 90 90 90 90 90 55 48 89 e5 <48> 8b 75 08 65 48 8b 04 25 80 5c 01 00 65 8b 15 98 3d d3 7e 81 e2 |
| [ 948.085424] RSP: 0018:ffffc90001c53918 EFLAGS: 00010093 |
| [ 948.090765] RAX: ffff888216401000 RBX: 0000000000000000 RCX: 0000000000000001 |
| [ 948.098016] RDX: 0000000000000000 RSI: ffffffff811f8e19 RDI: ffffffff83a4aaab |
| [ 948.105268] RBP: ffffc90001c53918 R08: 0000000000000400 R09: 0000000000000041 |
| [ 948.112524] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001 |
| [ 948.119773] R13: ffffc90001c53b00 R14: ffffffff83a4aaab R15: ffffc90001c53a10 |
| [ 948.127035] ? panic_smp_self_stop+0x9/0x60 |
| [ 948.131347] general protection fault: 0000 [#3] PREEMPT SMP |
| [ 948.137041] CPU: 1 PID: 5429 Comm: syz-fuzzer Tainted: G D 4.20.0+ #139 |
| [ 948.145070] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 |
| [ 948.154412] RIP: 0010:vmalloc_fault+0x21c/0x380 |
| [ 948.159060] Code: f8 0f 1f 40 00 41 81 e7 80 00 00 00 48 89 45 d0 49 bf 00 00 00 c0 ff ff 0f 00 4d 0f 44 fd e8 fb 99 1c 00 4c 23 7d d0 4d 01 fc <4f> 8b 24 34 49 f7 c4 9f ff ff ff 0f 84 30 01 00 00 e8 de 99 1c 00 |
| [ 948.177944] RSP: 0018:fffffe0000031800 EFLAGS: 00010002 |
| [ 948.183285] RAX: ffff888216401000 RBX: ffffc90001c53920 RCX: ffffffff830009b7 |
| [ 948.190538] RDX: 0000000000000000 RSI: ffffffff81118465 RDI: ffff888217caf098 |
| [ 948.197791] RBP: fffffe0000031830 R08: 0000000000000000 R09: 0000000000000000 |
| [ 948.205041] R10: 0000000000000000 R11: 0000000000000000 R12: 000f888200000070 |
| [ 948.212293] R13: 000ffffffffff000 R14: ffff888000000000 R15: 000f888200000000 |
| [ 948.219545] FS: 000000c420088768(0000) GS:ffff888218300000(0000) knlGS:0000000000000000 |
| [ 948.227752] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 |
| [ 948.233616] CR2: ffffc90001c53920 CR3: 000000020d5df000 CR4: 00000000001406e0 |
| [ 948.240872] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 |
| [ 948.248125] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 |
| [ 948.255375] Call Trace: |
| [ 948.257940] <#DF> |
| [ 948.260077] __do_page_fault+0x23f/0x630 |
| [ 948.264125] ? _raw_spin_unlock_irqrestore+0x33/0x50 |
| [ 948.269214] ? up+0x2d/0x50 |
| [ 948.272128] do_page_fault+0x4e/0x16d |
| [ 948.275912] page_fault+0x1e/0x30 |