[BUG] KASAN: slab-out-of-bounds Write in uvc_video_encode_isoc
From: Farhad Alemi
Date: Fri Sep 11 2026 - 14:00:00 EST
Hello,
We are reporting the following crash (reproducer attached):
Linux version 7.3.0-rc2 50d05c7c76c96b90462f24debacca971d2e86713
Build Config: UpstreamAppArmorKASAN (KASAN + UBSAN, panic_on_warn=1)
[ 55.172497][ T56] BUG: KASAN: slab-out-of-bounds in
uvc_video_encode_isoc+0x166/0x540
[ 55.174693][ T56] Write of size 1016 at addr ffff88802c0ca008 by
task kworker/u12:0/56
[ 55.174700][ T56]
[ 55.174713][ T56] CPU: 0 UID: 0 PID: 56 Comm: kworker/u12:0 Not
tainted 7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 55.174722][ T56] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 55.174727][ T56] Workqueue: uvcgadget uvcg_video_pump
[ 55.174742][ T56] Call Trace:
[ 55.174747][ T56] <TASK>
[ 55.174753][ T56] dump_stack_lvl+0xe8/0x150
[ 55.174763][ T56] print_address_description+0x55/0x1e0
[ 55.174771][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.174777][ T56] print_report+0x58/0x70
[ 55.174783][ T56] kasan_report+0x117/0x150
[ 55.174795][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.174802][ T56] kasan_check_range+0x264/0x2c0
[ 55.174812][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.174818][ T56] __asan_memcpy+0x40/0x70
[ 55.174827][ T56] uvc_video_encode_isoc+0x166/0x540
[ 55.174835][ T56] uvcg_video_pump+0x2cc/0x6f0
[ 55.174843][ T56] ? process_scheduled_works+0x94e/0x1900
[ 55.174855][ T56] process_scheduled_works+0xc99/0x1900
[ 55.174865][ T56] ? __lock_acquire+0x74c/0x2db0
[ 55.174878][ T56] ? __pfx_process_scheduled_works+0x10/0x10
[ 55.174888][ T56] ? assign_work+0x3d5/0x5e0
[ 55.174898][ T56] worker_thread+0xa53/0xfc0
[ 55.174908][ T56] kthread+0x38b/0x480
[ 55.174917][ T56] ? __pfx_worker_thread+0x10/0x10
[ 55.174923][ T56] ? __pfx_kthread+0x10/0x10
[ 55.174930][ T56] ret_from_fork+0x514/0xb70
[ 55.174939][ T56] ? __pfx_ret_from_fork+0x10/0x10
[ 55.174947][ T56] ? __switch_to+0xc79/0x1410
[ 55.174954][ T56] ? __pfx_kthread+0x10/0x10
[ 55.174961][ T56] ret_from_fork_asm+0x1a/0x30
[ 55.174972][ T56] </TASK>
[ 55.174975][ T56]
[ 55.174979][ T56] Allocated by task 9491:
[ 55.174983][ T56] kasan_save_track+0x3e/0x80
[ 55.174991][ T56] __kasan_kmalloc+0x93/0xb0
[ 55.174998][ T56] __kmalloc_noprof+0x36f/0x720
[ 55.175006][ T56] uvcg_video_enable+0x582/0x1000
[ 55.175012][ T56] uvc_v4l2_streamon+0x7e/0x110
[ 55.175021][ T56] __video_do_ioctl+0xadb/0xca0
[ 55.175027][ T56] video_usercopy+0x876/0x1450
[ 55.175032][ T56] v4l2_ioctl+0x18d/0x1e0
[ 55.175037][ T56] __se_sys_ioctl+0xfc/0x170
[ 55.175045][ T56] do_syscall_64+0x155/0x510
[ 55.175053][ T56] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 55.175060][ T56]
[ 55.175061][ T56] The buggy address belongs to the object at
ffff88802c0ca000
[ 55.175061][ T56] which belongs to the cache kmalloc-512 of size 512
[ 55.175071][ T56] The buggy address is located 8 bytes inside of
[ 55.175071][ T56] allocated 300-byte region [ffff88802c0ca000,
ffff88802c0ca12c)
[ 55.175079][ T56]
[ 55.175080][ T56] The buggy address belongs to the physical page:
[ 55.175089][ T56] page: refcount:0 mapcount:0
mapping:0000000000000000 index:0x0 pfn:0x2c0c8
[ 55.175096][ T56] head: order:2 mapcount:0 entire_mapcount:0
nr_pages_mapped:0 pincount:0
[ 55.175101][ T56] flags:
0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff)
[ 55.175113][ T56] page_type: f5(slab)
[ 55.175123][ T56] raw: 00fff00000000040 ffff88801b041c80
dead000000000100 dead000000000122
[ 55.175128][ T56] raw: 0000000000000000 0000000000100010
00000000f5000000 0000000000000000
[ 55.175134][ T56] head: 00fff00000000040 ffff88801b041c80
dead000000000100 dead000000000122
[ 55.175139][ T56] head: 0000000000000000 0000000000100010
00000000f5000000 0000000000000000
[ 55.175145][ T56] head: 00fff00000000002 ffffffffffffff01
00000000ffffffff 00000000ffffffff
[ 55.175150][ T56] head: ffffffffffffffff 0000000000000000
00000000ffffffff 0000000000000004
[ 55.175154][ T56] page dumped because: kasan: bad access detected
[ 55.175160][ T56] page_owner tracks the page as allocated
[ 55.175163][ T56] page last allocated via order 2, migratetype
Unmovable, gfp_mask
0xd20c0(__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC),
pid 1, tgid 1 (swapper/0), ts 5924167611
[ 55.175174][ T56] post_alloc_hook+0x1f9/0x250
[ 55.175182][ T56] get_page_from_freelist+0x235a/0x23e0
[ 55.175189][ T56] __alloc_frozen_pages_noprof+0x217/0x5a0
[ 55.175197][ T56] allocate_slab+0x7d/0x610
[ 55.175202][ T56] refill_objects+0x2d6/0x350
[ 55.175207][ T56] __pcs_replace_empty_main+0x2c9/0x6c0
[ 55.175216][ T56] __kmalloc_cache_noprof+0x3a5/0x610
[ 55.175223][ T56] device_add+0xbe/0xb90
[ 55.176284][ T56] __video_register_device+0x3b6e/0x4ae0
[ 55.176293][ T56] vivid_create_devnodes+0x1622/0x2bf0
[ 55.176300][ T56] vivid_probe+0x5109/0x7290
[ 55.176305][ T56] platform_probe+0xf9/0x190
[ 55.176311][ T56] really_probe+0x267/0xaf0
[ 55.176317][ T56] __driver_probe_device+0x1e2/0x350
[ 55.176324][ T56] driver_probe_device+0x4f/0x240
[ 55.176330][ T56] __driver_attach+0x33c/0x600
[ 55.176336][ T56] page_owner free stack trace missing
[ 55.176339][ T56]
[ 55.176341][ T56] Memory state around the buggy address:
[ 55.176344][ T56] ffff88802c0ca000: 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
[ 55.176349][ T56] ffff88802c0ca080: 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
[ 55.176353][ T56] >ffff88802c0ca100: 00 00 00 00 00 04 fc fc fc
fc fc fc fc fc fc fc
[ 55.176356][ T56] ^
[ 55.176360][ T56] ffff88802c0ca180: fc fc fc fc fc fc fc fc fc
fc fc fc fc fc fc fc
[ 55.176364][ T56] ffff88802c0ca200: fc fc fc fc fc fc fc fc fc
fc fc fc fc fc fc fc
[ 55.176367][ T56]
==================================================================
[ 55.176376][ T56] Kernel panic - not syncing: KASAN: panic_on_warn set ...
[ 55.227013][ T56] CPU: 0 UID: 0 PID: 56 Comm: kworker/u12:0 Not
tainted 7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 55.228001][ T56] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 55.228955][ T56] Workqueue: uvcgadget uvcg_video_pump
[ 55.229455][ T56] Call Trace:
[ 55.229769][ T56] <TASK>
[ 55.230042][ T56] vpanic+0x56d/0xa60
[ 55.230466][ T56] ? __pfx_vpanic+0x10/0x10
[ 55.230911][ T56] panic+0xc5/0xd0
[ 55.231284][ T56] ? __pfx_panic+0x10/0x10
[ 55.231700][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.232197][ T56] ? rcu_is_watching+0x16/0xb0
[ 55.232643][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.233141][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.233639][ T56] check_panic_on_warn+0x89/0xb0
[ 55.234095][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.234595][ T56] end_report+0x73/0x170
[ 55.234990][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.235489][ T56] kasan_report+0x128/0x150
[ 55.235971][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.236467][ T56] kasan_check_range+0x264/0x2c0
[ 55.236928][ T56] ? uvc_video_encode_isoc+0x166/0x540
[ 55.237423][ T56] __asan_memcpy+0x40/0x70
[ 55.237837][ T56] uvc_video_encode_isoc+0x166/0x540
[ 55.238323][ T56] uvcg_video_pump+0x2cc/0x6f0
[ 55.238765][ T56] ? process_scheduled_works+0x94e/0x1900
[ 55.239287][ T56] process_scheduled_works+0xc99/0x1900
[ 55.239795][ T56] ? __lock_acquire+0x74c/0x2db0
[ 55.240253][ T56] ? __pfx_process_scheduled_works+0x10/0x10
[ 55.240818][ T56] ? assign_work+0x3d5/0x5e0
[ 55.241244][ T56] worker_thread+0xa53/0xfc0
[ 55.241674][ T56] kthread+0x38b/0x480
[ 55.242050][ T56] ? __pfx_worker_thread+0x10/0x10
[ 55.242520][ T56] ? __pfx_kthread+0x10/0x10
[ 55.242944][ T56] ret_from_fork+0x514/0xb70
[ 55.243371][ T56] ? __pfx_ret_from_fork+0x10/0x10
[ 55.243844][ T56] ? __switch_to+0xc79/0x1410
[ 55.244277][ T56] ? __pfx_kthread+0x10/0x10
[ 55.244704][ T56] ret_from_fork_asm+0x1a/0x30
[ 55.245145][ T56] </TASK>
[ 55.246077][ T56] Kernel Offset: disabled
[ 55.246629][ T56] Rebooting in 86400 seconds..
Regards,
Attachment:
reproducer.c
Description: Binary data