[BUG] general protection fault in m5602_stop_transfer

From: Farhad Alemi

Date: Fri Sep 11 2026 - 02:04:39 EST


Hello,

We are reporting the following crash (reproducer attached and a
proposed patch forthcoming):
Linux version 7.3.0-rc2 50d05c7c76c96b90462f24debacca971d2e86713
Build Config: UpstreamAppArmorKASAN (KASAN + UBSAN, panic_on_warn=1)

[ 52.671675][ T9483] Oops: general protection fault, probably for
non-canonical address 0xdffffc0000000009: 0000 [#1] SMP KASAN NOPTI
[ 52.826702][ T9483] KASAN: null-ptr-deref in range
[0x0000000000000048-0x000000000000004f]
[ 52.827517][ T9483] CPU: 0 UID: 0 PID: 9483 Comm: repro Not tainted
7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 52.828543][ T9483] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 52.829635][ T9483] RIP: 0010:m5602_stop_transfer+0x46/0x90
[ 52.830190][ T9483] Code: 8d b3 28 0d 00 00 4c 89 f0 48 c1 e8 03 42
80 3c 38 00 74 08 4c 89 f7 e8 18 7b 00 fa 4d 8b 36 49 83 c6 48 4c 89
f0 48 c1 e8 03 <42> 80 3c 38 00 74 08 4c 89 f7 e8 fb 7a 00 fa 4d 8b 36
4d 85 f6 74
[ 52.831934][ T9483] RSP: 0018:ffffc9000828fb58 EFLAGS: 00010206
[ 52.832509][ T9483] RAX: 0000000000000009 RBX: ffff8881124a4000
RCX: ffff888024528000
[ 52.833304][ T9483] RDX: 0000000000000000 RSI: 0000000000000002
RDI: ffff8881124a4000
[ 52.834093][ T9483] RBP: dffffc0000000000 R08: ffffffff90563d7f
R09: 1ffffffff20ac7af
[ 52.834877][ T9483] R10: dffffc0000000000 R11: ffffffff88371ac0
R12: dffffc0000000000
[ 52.835657][ T9483] R13: 1ffff11022494976 R14: 0000000000000048
R15: dffffc0000000000
[ 52.836454][ T9483] FS: 0000000005e01400(0000)
GS:ffff8880d7388000(0000) knlGS:0000000000000000
[ 52.837331][ T9483] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 52.837981][ T9483] CR2: 000056177bfecf78 CR3: 0000000024331000
CR4: 0000000000752ef0
[ 52.838744][ T9483] PKRU: 55555554
[ 52.839089][ T9483] Call Trace:
[ 52.839491][ T9483] <TASK>
[ 52.839782][ T9483] ? __pfx_m5602_stop_transfer+0x10/0x10
[ 52.840315][ T9483] gspca_stream_off+0xb7/0x400
[ 52.840769][ T9483] gspca_stop_streaming+0x48/0x1e0
[ 52.841235][ T9483] ? ima_file_free+0x16b/0x5d0
[ 52.841686][ T9483] ? __pfx_gspca_stop_streaming+0x10/0x10
[ 52.842243][ T9483] __vb2_queue_cancel+0xba/0xdb0
[ 52.842742][ T9483] ? __asan_memset+0x22/0x50
[ 52.843194][ T9483] ? __fsnotify_parent+0x267/0x620
[ 52.843695][ T9483] __vb2_cleanup_fileio+0x4e/0x1f0
[ 52.844187][ T9483] vb2_core_queue_release+0x27/0x150
[ 52.844698][ T9483] vb2_fop_release+0x16e/0x200
[ 52.845137][ T9483] v4l2_release+0x250/0x370
[ 52.845566][ T9483] ? __pfx_v4l2_release+0x10/0x10
[ 52.846023][ T9483] __fput+0x44f/0xa60
[ 52.846404][ T9483] fput_close_sync+0x11f/0x240
[ 52.846846][ T9483] ? __pfx_fput_close_sync+0x10/0x10
[ 52.847349][ T9483] __x64_sys_close+0x7e/0x110
[ 52.847817][ T9483] do_syscall_64+0x155/0x510
[ 52.848287][ T9483] ? trace_irq_disable+0x3b/0x140
[ 52.848862][ T9483] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 52.849551][ T9483] ? clear_bhb_loop+0x30/0x80
[ 52.850003][ T9483] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 52.850602][ T9483] RIP: 0033:0x456ed6
[ 52.850997][ T9483] Code: 47 ba 04 00 00 00 48 c7 c0 f0 ff ff ff 64
89 10 48 c7 c2 ff ff ff ff c9 48 89 d0 c3 0f 1f 84 00 00 00 00 00 48
8b 45 10 0f 05 <48> 89 c2 48 3d 00 f0 ff ff 77 0f c9 48 89 d0 c3 66 2e
0f 1f 84 00
[ 52.852863][ T9483] RSP: 002b:00007ffd18c13250 EFLAGS: 00000202
ORIG_RAX: 0000000000000003
[ 52.853659][ T9483] RAX: ffffffffffffffda RBX: 0000000000000001
RCX: 0000000000456ed6
[ 52.854415][ T9483] RDX: 0000000000000000 RSI: 0000000000000000
RDI: 0000000000000003
[ 52.855261][ T9483] RBP: 00007ffd18c13260 R08: 0000000000000000
R09: 0000000000000000
[ 52.856254][ T9483] R10: 0000000000000000 R11: 0000000000000202
R12: 00007ffd18c15668
[ 52.857009][ T9483] R13: 00007ffd18c15678 R14: 0000000000000002
R15: 00000000004b3100
[ 52.857784][ T9483] </TASK>
[ 52.858096][ T9483] Modules linked in:
[ 52.858690][ T9483] ---[ end trace 0000000000000000 ]---
[ 52.859988][ T9483] RIP: 0010:m5602_stop_transfer+0x46/0x90
[ 52.860003][ T9483] Code: 8d b3 28 0d 00 00 4c 89 f0 48 c1 e8 03 42
80 3c 38 00 74 08 4c 89 f7 e8 18 7b 00 fa 4d 8b 36 49 83 c6 48 4c 89
f0 48 c1 e8 03 <42> 80 3c 38 00 74 08 4c 89 f7 e8 fb 7a 00 fa 4d 8b 36
4d 85 f6 74
[ 52.860008][ T9483] RSP: 0018:ffffc9000828fb58 EFLAGS: 00010206
[ 52.860015][ T9483] RAX: 0000000000000009 RBX: ffff8881124a4000
RCX: ffff888024528000
[ 52.860020][ T9483] RDX: 0000000000000000 RSI: 0000000000000002
RDI: ffff8881124a4000
[ 52.860024][ T9483] RBP: dffffc0000000000 R08: ffffffff90563d7f
R09: 1ffffffff20ac7af
[ 52.860029][ T9483] R10: dffffc0000000000 R11: ffffffff88371ac0
R12: dffffc0000000000
[ 52.860034][ T9483] R13: 1ffff11022494976 R14: 0000000000000048
R15: dffffc0000000000
[ 52.860038][ T9483] FS: 0000000005e01400(0000)
GS:ffff8880d7388000(0000) knlGS:0000000000000000
[ 52.860052][ T9483] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 52.860056][ T9483] CR2: 00007f66069c6dc0 CR3: 0000000024331000
CR4: 0000000000752ef0
[ 52.860063][ T9483] PKRU: 55555554
[ 52.860071][ T9483] Kernel panic - not syncing: Fatal exception
[ 52.870715][ T9483] Kernel Offset: disabled
[ 52.871260][ T9483] Rebooting in 86400 seconds..

Regards,
SEFCOM Lab @ ASU

Attachment: reproducer.c
Description: Binary data