[BUG] KASAN: slab-use-after-free Read in msi2500_stop_streaming
From: Farhad Alemi
Date: Fri Sep 11 2026 - 13:48:37 EST
Hello,
We are reporting the following crash (reproducer attached):
Linux version 7.3.0-rc2 50d05c7c76c96b90462f24debacca971d2e86713
Build Config: UpstreamAppArmorKASAN (KASAN + UBSAN, panic_on_warn=1)
[ 45.449899][ T9488] BUG: KASAN: slab-use-after-free in
msi2500_stop_streaming+0x144/0x290
[ 45.453118][ T9488] Read of size 8 at addr ffff8881179bc8a8 by task
repro/9488
[ 45.453146][ T9488]
[ 45.453188][ T9488] CPU: 1 UID: 0 PID: 9488 Comm: repro Not tainted
7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 45.453228][ T9488] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 45.453264][ T9488] Call Trace:
[ 45.453294][ T9488] <TASK>
[ 45.453344][ T9488] dump_stack_lvl+0xe8/0x150
[ 45.453386][ T9488] print_address_description+0x55/0x1e0
[ 45.453422][ T9488] ? msi2500_stop_streaming+0x144/0x290
[ 45.453463][ T9488] print_report+0x58/0x70
[ 45.453493][ T9488] kasan_report+0x117/0x150
[ 45.453541][ T9488] ? msi2500_stop_streaming+0x144/0x290
[ 45.453589][ T9488] msi2500_stop_streaming+0x144/0x290
[ 45.453630][ T9488] ? __pfx_msi2500_stop_streaming+0x10/0x10
[ 45.453674][ T9488] __vb2_queue_cancel+0xba/0xdb0
[ 45.453724][ T9488] ? __vb2_cleanup_fileio+0x134/0x1f0
[ 45.453758][ T9488] vb2_core_queue_release+0x2f/0x150
[ 45.453792][ T9488] vb2_fop_release+0x16e/0x200
[ 45.453825][ T9488] v4l2_release+0x250/0x370
[ 45.453854][ T9488] ? __pfx_v4l2_release+0x10/0x10
[ 45.453884][ T9488] __fput+0x44f/0xa60
[ 45.453937][ T9488] fput_close_sync+0x11f/0x240
[ 45.453983][ T9488] ? __pfx_fput_close_sync+0x10/0x10
[ 45.454036][ T9488] __x64_sys_close+0x7e/0x110
[ 45.454066][ T9488] do_syscall_64+0x155/0x510
[ 45.454112][ T9488] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 45.454145][ T9488] ? clear_bhb_loop+0x30/0x80
[ 45.454180][ T9488] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 45.454212][ T9488] RIP: 0033:0x46ff26
[ 45.454257][ T9488] Code: 47 ba 04 00 00 00 48 c7 c0 f0 ff ff ff 64
89 10 48 c7 c2 ff ff ff ff c9 48 89 d0 c3 0f 1f 84 00 00 00 00 00 48
8b 45 10 0f 05 <48> 89 c2 48 3d 00 f0 ff ff 77 0f c9 48 89 d0 c3 66 2e
0f 1f 84 00
[ 45.454293][ T9488] RSP: 002b:00007ffdffa12750 EFLAGS: 00000202
ORIG_RAX: 0000000000000003
[ 45.454353][ T9488] RAX: ffffffffffffffda RBX: 0000000000000001
RCX: 000000000046ff26
[ 45.454377][ T9488] RDX: 0000000000000000 RSI: 0000000000000000
RDI: 0000000000000004
[ 45.454396][ T9488] RBP: 00007ffdffa12760 R08: 0000000000000000
R09: 0000000000000000
[ 45.454416][ T9488] R10: 0000000000000000 R11: 0000000000000202
R12: 00007ffdffa128e8
[ 45.454437][ T9488] R13: 00007ffdffa128f8 R14: 0000000000000002
R15: 00000000004d4100
[ 45.454470][ T9488] </TASK>
[ 45.454482][ T9488]
[ 45.454498][ T9488] Allocated by task 991:
[ 45.454514][ T9488] kasan_save_track+0x3e/0x80
[ 45.454552][ T9488] __kasan_kmalloc+0x93/0xb0
[ 45.454590][ T9488] __kmalloc_cache_noprof+0x325/0x610
[ 45.454625][ T9488] msi001_probe+0x5e/0x400
[ 45.454658][ T9488] really_probe+0x267/0xaf0
[ 45.456219][ T9488] __driver_probe_device+0x1e2/0x350
[ 45.456250][ T9488] driver_probe_device+0x4f/0x240
[ 45.456282][ T9488] __device_attach_driver+0x270/0x410
[ 45.456330][ T9488] bus_for_each_drv+0x258/0x2f0
[ 45.456370][ T9488] __device_attach+0x2c5/0x450
[ 45.456398][ T9488] device_initial_probe+0xa1/0xd0
[ 45.456428][ T9488] bus_probe_device+0x12a/0x220
[ 45.456466][ T9488] device_add+0x7ec/0xb90
[ 45.456491][ T9488] __spi_add_device+0xd3f/0x1240
[ 45.456529][ T9488] spi_new_device+0x332/0x500
[ 45.456565][ T9488] v4l2_spi_new_subdev+0x7e/0x1e0
[ 45.456601][ T9488] msi2500_probe+0x5b6/0x9f0
[ 45.456637][ T9488] usb_probe_interface+0x71f/0xe00
[ 45.456676][ T9488] really_probe+0x267/0xaf0
[ 45.456707][ T9488] __driver_probe_device+0x1e2/0x350
[ 45.456737][ T9488] driver_probe_device+0x4f/0x240
[ 45.456769][ T9488] __device_attach_driver+0x270/0x410
[ 45.456801][ T9488] bus_for_each_drv+0x258/0x2f0
[ 45.456843][ T9488] __device_attach+0x2c5/0x450
[ 45.456862][ T9488] device_initial_probe+0xa1/0xd0
[ 45.456882][ T9488] bus_probe_device+0x12a/0x220
[ 45.456907][ T9488] device_add+0x7ec/0xb90
[ 45.456924][ T9488] usb_set_configuration+0x1a87/0x2110
[ 45.456949][ T9488] usb_generic_driver_probe+0x8d/0x150
[ 45.456972][ T9488] usb_probe_device+0x1c4/0x3b0
[ 45.456997][ T9488] really_probe+0x267/0xaf0
[ 45.457017][ T9488] __driver_probe_device+0x1e2/0x350
[ 45.457037][ T9488] driver_probe_device+0x4f/0x240
[ 45.457058][ T9488] __device_attach_driver+0x270/0x410
[ 45.457080][ T9488] bus_for_each_drv+0x258/0x2f0
[ 45.457105][ T9488] __device_attach+0x2c5/0x450
[ 45.457124][ T9488] device_initial_probe+0xa1/0xd0
[ 45.457144][ T9488] bus_probe_device+0x12a/0x220
[ 45.457169][ T9488] device_add+0x7ec/0xb90
[ 45.457185][ T9488] usb_new_device+0xa14/0x1720
[ 45.457205][ T9488] hub_event+0x2a1c/0x4f30
[ 45.457227][ T9488] process_scheduled_works+0xc99/0x1900
[ 45.457260][ T9488] worker_thread+0xa53/0xfc0
[ 45.457277][ T9488] kthread+0x38b/0x480
[ 45.457300][ T9488] ret_from_fork+0x514/0xb70
[ 45.457330][ T9488] ret_from_fork_asm+0x1a/0x30
[ 45.457356][ T9488]
[ 45.457361][ T9488] Freed by task 991:
[ 45.457372][ T9488] kasan_save_track+0x3e/0x80
[ 45.457398][ T9488] kasan_save_free_info+0x46/0x50
[ 45.457418][ T9488] __kasan_slab_free+0x5c/0x80
[ 45.457442][ T9488] kfree+0x1c5/0x650
[ 45.457462][ T9488] device_release_driver_internal+0x46f/0x870
[ 45.457484][ T9488] bus_remove_device+0x455/0x570
[ 45.457509][ T9488] device_del+0x527/0x8f0
[ 45.457527][ T9488] spi_unregister_device+0x127/0x1c0
[ 45.457553][ T9488] __unregister+0x15/0x20
[ 45.457568][ T9488] device_for_each_child+0x10b/0x1a0
[ 45.457588][ T9488] spi_unregister_controller+0x234/0x630
[ 45.457617][ T9488] msi2500_disconnect+0xcc/0x190
[ 45.457641][ T9488] usb_unbind_interface+0x26e/0x910
[ 45.457666][ T9488] device_release_driver_internal+0x4d9/0x870
[ 45.457688][ T9488] bus_remove_device+0x455/0x570
[ 45.457713][ T9488] device_del+0x527/0x8f0
[ 45.457731][ T9488] usb_disable_device+0x3d4/0x8d0
[ 45.457753][ T9488] usb_disconnect+0x32f/0x990
[ 45.457772][ T9488] hub_event+0x1cc9/0x4f30
[ 45.457794][ T9488] process_scheduled_works+0xc99/0x1900
[ 45.457823][ T9488] worker_thread+0xa53/0xfc0
[ 45.457840][ T9488] kthread+0x38b/0x480
[ 45.457862][ T9488] ret_from_fork+0x514/0xb70
[ 45.457883][ T9488] ret_from_fork_asm+0x1a/0x30
[ 45.457905][ T9488]
[ 45.457910][ T9488] The buggy address belongs to the object at
ffff8881179bc800
[ 45.457910][ T9488] which belongs to the cache kmalloc-1k of size 1024
[ 45.457935][ T9488] The buggy address is located 168 bytes inside of
[ 45.457935][ T9488] freed 1024-byte region [ffff8881179bc800,
ffff8881179bcc00)
[ 45.457957][ T9488]
[ 45.457963][ T9488] The buggy address belongs to the physical page:
[ 45.457987][ T9488] page: refcount:0 mapcount:0
mapping:0000000000000000 index:0x0 pfn:0x1179b8
[ 45.458007][ T9488] head: order:3 mapcount:0 entire_mapcount:0
nr_pages_mapped:0 pincount:0
[ 45.458025][ T9488] flags:
0x57ff00000000040(head|node=1|zone=2|lastcpupid=0x7ff)
[ 45.458060][ T9488] page_type: f5(slab)
[ 45.458088][ T9488] raw: 057ff00000000040 ffff88801b041dc0
dead000000000100 dead000000000122
[ 45.458106][ T9488] raw: 0000000000000000 0000000000100010
00000000f5000000 0000000000000000
[ 45.458125][ T9488] head: 057ff00000000040 ffff88801b041dc0
dead000000000100 dead000000000122
[ 45.458142][ T9488] head: 0000000000000000 0000000000100010
00000000f5000000 0000000000000000
[ 45.458160][ T9488] head: 057ff00000000003 fffffffffffffe01
00000000ffffffff 00000000ffffffff
[ 45.458177][ T9488] head: ffffffffffffffff 0000000000000000
00000000ffffffff 0000000000000008
[ 45.458188][ T9488] page dumped because: kasan: bad access detected
[ 45.458205][ T9488] page_owner tracks the page as allocated
[ 45.458213][ T9488] page last allocated via order 3, migratetype
Unmovable, gfp_mask
0xd20c0(__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC),
pid 5495, tgid 5495 ((udev-worker)), ts 21220333223
[ 45.458250][ T9488] post_alloc_hook+0x1f9/0x250
[ 45.458273][ T9488] get_page_from_freelist+0x235a/0x23e0
[ 45.458298][ T9488] __alloc_frozen_pages_noprof+0x217/0x5a0
[ 45.458335][ T9488] allocate_slab+0x7d/0x610
[ 45.458352][ T9488] refill_objects+0x2d6/0x350
[ 45.458369][ T9488] __pcs_replace_empty_main+0x2c9/0x6c0
[ 45.458400][ T9488] __kmalloc_node_track_caller_noprof+0x552/0x730
[ 45.458424][ T9488] __alloc_skb+0x2c5/0x7d0
[ 45.458447][ T9488] netlink_sendmsg+0x5d4/0xb40
[ 45.458465][ T9488] sock_sendmsg_nosec+0x13a/0x180
[ 45.458484][ T9488] ____sys_sendmsg+0x589/0x8c0
[ 45.458510][ T9488] ___sys_sendmsg+0x2a5/0x360
[ 45.458535][ T9488] __x64_sys_sendmsg+0x1b1/0x290
[ 45.458561][ T9488] do_syscall_64+0x155/0x510
[ 45.458589][ T9488] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 45.458609][ T9488] page last free pid 991 tgid 991 ts 21211839794
stack trace:
[ 45.458624][ T9488] free_pages_prepare+0xa03/0xb00
[ 45.458644][ T9488] __free_contig_range_common+0x174/0x340
[ 45.458672][ T9488] free_pages_bulk+0x48/0x120
[ 45.458695][ T9488] vfree+0x231/0x470
[ 45.458713][ T9488] delayed_vfree_work+0x55/0x80
[ 45.458735][ T9488] process_scheduled_works+0xc99/0x1900
[ 45.458764][ T9488] worker_thread+0xa53/0xfc0
[ 45.458782][ T9488] kthread+0x38b/0x480
[ 45.458803][ T9488] ret_from_fork+0x514/0xb70
[ 45.458824][ T9488] ret_from_fork_asm+0x1a/0x30
[ 45.458847][ T9488]
[ 45.458852][ T9488] Memory state around the buggy address:
[ 45.458864][ T9488] ffff8881179bc780: fc fc fc fc fc fc fc fc fc
fc fc fc fc fc fc fc
[ 45.458878][ T9488] ffff8881179bc800: fa fb fb fb fb fb fb fb fb
fb fb fb fb fb fb fb
[ 45.458892][ T9488] >ffff8881179bc880: fb fb fb fb fb fb fb fb fb
fb fb fb fb fb fb fb
[ 45.458902][ T9488] ^
[ 45.458913][ T9488] ffff8881179bc900: fb fb fb fb fb fb fb fb fb
fb fb fb fb fb fb fb
[ 45.458926][ T9488] ffff8881179bc980: fb fb fb fb fb fb fb fb fb
fb fb fb fb fb fb fb
[ 45.458937][ T9488]
==================================================================
[ 45.458962][ T9488] Kernel panic - not syncing: KASAN: panic_on_warn set ...
[ 45.553634][ T9488] CPU: 1 UID: 0 PID: 9488 Comm: repro Not tainted
7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 45.554573][ T9488] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 45.555525][ T9488] Call Trace:
[ 45.555831][ T9488] <TASK>
[ 45.556103][ T9488] vpanic+0x56d/0xa60
[ 45.556480][ T9488] ? __pfx_vpanic+0x10/0x10
[ 45.556898][ T9488] panic+0xc5/0xd0
[ 45.557244][ T9488] ? __pfx_panic+0x10/0x10
[ 45.557657][ T9488] ? msi2500_stop_streaming+0x144/0x290
[ 45.558162][ T9488] ? rcu_is_watching+0x16/0xb0
[ 45.558610][ T9488] ? msi2500_stop_streaming+0x144/0x290
[ 45.559114][ T9488] check_panic_on_warn+0x89/0xb0
[ 45.559637][ T9488] ? msi2500_stop_streaming+0x144/0x290
[ 45.560157][ T9488] end_report+0x73/0x170
[ 45.560554][ T9488] ? msi2500_stop_streaming+0x144/0x290
[ 45.561060][ T9488] kasan_report+0x128/0x150
[ 45.561481][ T9488] ? msi2500_stop_streaming+0x144/0x290
[ 45.561984][ T9488] msi2500_stop_streaming+0x144/0x290
[ 45.562477][ T9488] ? __pfx_msi2500_stop_streaming+0x10/0x10
[ 45.563012][ T9488] __vb2_queue_cancel+0xba/0xdb0
[ 45.563470][ T9488] ? __vb2_cleanup_fileio+0x134/0x1f0
[ 45.563955][ T9488] vb2_core_queue_release+0x2f/0x150
[ 45.564437][ T9488] vb2_fop_release+0x16e/0x200
[ 45.564873][ T9488] v4l2_release+0x250/0x370
[ 45.565287][ T9488] ? __pfx_v4l2_release+0x10/0x10
[ 45.565749][ T9488] __fput+0x44f/0xa60
[ 45.566122][ T9488] fput_close_sync+0x11f/0x240
[ 45.566565][ T9488] ? __pfx_fput_close_sync+0x10/0x10
[ 45.567048][ T9488] __x64_sys_close+0x7e/0x110
[ 45.567483][ T9488] do_syscall_64+0x155/0x510
[ 45.567909][ T9488] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 45.568461][ T9488] ? clear_bhb_loop+0x30/0x80
[ 45.568891][ T9488] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 45.569499][ T9488] RIP: 0033:0x46ff26
[ 45.569860][ T9488] Code: 47 ba 04 00 00 00 48 c7 c0 f0 ff ff ff 64
89 10 48 c7 c2 ff ff ff ff c9 48 89 d0 c3 0f 1f 84 00 00 00 00 00 48
8b 45 10 0f 05 <48> 89 c2 48 3d 00 f0 ff ff 77 0f c9 48 89 d0 c3 66 2e
0f 1f 84 00
[ 45.571588][ T9488] RSP: 002b:00007ffdffa12750 EFLAGS: 00000202
ORIG_RAX: 0000000000000003
[ 45.572340][ T9488] RAX: ffffffffffffffda RBX: 0000000000000001
RCX: 000000000046ff26
[ 45.573052][ T9488] RDX: 0000000000000000 RSI: 0000000000000000
RDI: 0000000000000004
[ 45.573763][ T9488] RBP: 00007ffdffa12760 R08: 0000000000000000
R09: 0000000000000000
[ 45.574473][ T9488] R10: 0000000000000000 R11: 0000000000000202
R12: 00007ffdffa128e8
[ 45.575180][ T9488] R13: 00007ffdffa128f8 R14: 0000000000000002
R15: 00000000004d4100
[ 45.575893][ T9488] </TASK>
[ 45.576438][ T9488] Kernel Offset: disabled
[ 45.576986][ T9488] Rebooting in 86400 seconds..
Regards,
Attachment:
reproducer.c
Description: Binary data