[BUG] general protection fault in gspca_input_create_urb
From: Farhad Alemi
Date: Fri Sep 11 2026 - 19:33:31 EST
Hello,
We are reporting the following crash (reproducer attached):
Linux version 7.3.0-rc2 50d05c7c76c96b90462f24debacca971d2e86713
Build Config: UpstreamAppArmorKASAN (KASAN + UBSAN, panic_on_warn=1)
[ 44.796212][ T9513] Oops: general protection fault, probably for
non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI
[ 44.797809][ T9513] KASAN: null-ptr-deref in range
[0x0000000000000008-0x000000000000000f]
[ 44.798630][ T9513] CPU: 1 UID: 0 PID: 9513 Comm: repro Not tainted
7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 44.799614][ T9513] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 44.800565][ T9513] RIP: 0010:gspca_input_create_urb+0x134/0x7e0
[ 44.801144][ T9513] Code: 04 28 84 c0 0f 85 27 05 00 00 4c 8d bc 24
80 00 00 00 41 0f b6 34 24 e8 6a c1 31 ff 49 89 c4 49 83 c4 08 4c 89
e0 48 c1 e8 03 <42> 80 3c 28 00 74 08 4c 89 e7 e8 dd cb 15 fa 49 8b 3c
24 31 f6 31
[ 44.802855][ T9513] RSP: 0018:ffffc90002caf0c0 EFLAGS: 00010202
[ 44.803410][ T9513] RAX: 0000000000000001 RBX: 1ffff92000595e24
RCX: ffff88810c2fcc80
[ 44.804122][ T9513] RDX: 0000000000000000 RSI: 0000000000000000
RDI: ffff88802885d000
[ 44.804830][ T9513] RBP: ffffc90002caf1b0 R08: ffffc90002caef47
R09: 1ffff92000595de8
[ 44.805544][ T9513] R10: dffffc0000000000 R11: fffff52000595de9
R12: 0000000000000008
[ 44.806254][ T9513] R13: dffffc0000000000 R14: 1ffff110051758ec
R15: ffffc90002caf140
[ 44.806964][ T9513] FS: 00007f14db81d6c0(0000)
GS:ffff8881da588000(0000) knlGS:0000000000000000
[ 44.807755][ T9513] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 44.808405][ T9513] CR2: 00005623cbf48b30 CR3: 0000000027a85000
CR4: 0000000000752ef0
[ 44.809118][ T9513] PKRU: 55555554
[ 44.809444][ T9513] Call Trace:
[ 44.809751][ T9513] <TASK>
[ 44.810030][ T9513] ? lockdep_hardirqs_on+0x7b/0x110
[ 44.810507][ T9513] ? __pfx__printk+0x10/0x10
[ 44.810934][ T9513] ? kfree+0x1c5/0x650
[ 44.811309][ T9513] ? __pfx_gspca_input_create_urb+0x10/0x10
[ 44.811845][ T9513] ? __pfx_sd_stopN+0x10/0x10
[ 44.812278][ T9513] ? gspca_stream_off+0x305/0x400
[ 44.812737][ T9513] gspca_init_transfer+0x2b53/0x3060
[ 44.813227][ T9513] ? __pfx_gspca_init_transfer+0x10/0x10
[ 44.813738][ T9513] ? __lock_acquire+0x74c/0x2db0
[ 44.814261][ T9513] ? __pfx___mutex_unlock_slowpath+0x10/0x10
[ 44.814851][ T9513] ? __pfx_do_raw_spin_lock+0x10/0x10
[ 44.815386][ T9513] ? __pfx_gspca_start_streaming+0x10/0x10
[ 44.815957][ T9513] gspca_start_streaming+0x6f/0x250
[ 44.816431][ T9513] ? _raw_spin_unlock_irqrestore+0x30/0x80
[ 44.816963][ T9513] ? __pfx_gspca_start_streaming+0x10/0x10
[ 44.817492][ T9513] vb2_start_streaming+0x128/0x460
[ 44.817961][ T9513] vb2_core_streamon+0x2e0/0x4f0
[ 44.818476][ T9513] __vb2_init_fileio+0xca2/0xff0
[ 44.818932][ T9513] vb2_core_poll+0x4c1/0x840
[ 44.819355][ T9513] vb2_fop_poll+0x193/0x310
[ 44.819770][ T9513] ? __fget_files+0x2a/0x420
[ 44.820195][ T9513] ? __pfx_vb2_fop_poll+0x10/0x10
[ 44.820652][ T9513] v4l2_poll+0x147/0x2c0
[ 44.821046][ T9513] ? __pfx_v4l2_poll+0x10/0x10
[ 44.821482][ T9513] do_sys_poll+0x96c/0x10e0
[ 44.821930][ T9513] ? do_sys_poll+0x761/0x10e0
[ 44.822358][ T9513] ? __pfx_do_sys_poll+0x10/0x10
[ 44.822807][ T9513] ? is_bpf_text_address+0x26/0x2b0
[ 44.823314][ T9513] ? kernel_text_address+0xa5/0xe0
[ 44.823780][ T9513] ? __kernel_text_address+0xd/0x30
[ 44.824258][ T9513] ? __pfx_pollwake+0x10/0x10
[ 44.824716][ T9513] ? __pfx_pollwake+0x10/0x10
[ 44.825212][ T9513] ? __pfx_timespec64_add_safe+0x10/0x10
[ 44.825763][ T9513] ? do_sys_openat2+0x14e/0x200
[ 44.826250][ T9513] __x64_sys_poll+0x190/0x350
[ 44.826715][ T9513] ? __pfx___x64_sys_poll+0x10/0x10
[ 44.827233][ T9513] do_syscall_64+0x155/0x510
[ 44.827704][ T9513] ? trace_irq_disable+0x3b/0x140
[ 44.828259][ T9513] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 44.828836][ T9513] ? clear_bhb_loop+0x30/0x80
[ 44.829292][ T9513] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 44.829837][ T9513] RIP: 0033:0x4744b2
[ 44.830204][ T9513] Code: 08 0f 85 d1 df ff ff 49 89 fb 48 89 f0 48
89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89
5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa
55 48 89 e5
[ 44.831983][ T9513] RSP: 002b:00007f14db81d158 EFLAGS: 00000246
ORIG_RAX: 0000000000000007
[ 44.832751][ T9513] RAX: ffffffffffffffda RBX: 00007f14db81d6c0
RCX: 00000000004744b2
[ 44.833461][ T9513] RDX: 00000000000003e8 RSI: 0000000000000001
RDI: 00007f14db81d1d0
[ 44.834169][ T9513] RBP: 00007f14db81d180 R08: 0000000000000000
R09: 0000000000000000
[ 44.834875][ T9513] R10: 0000000000000000 R11: 0000000000000246
R12: 00007f14db81d6c0
[ 44.835583][ T9513] R13: 00007ffdd918aae0 R14: 00007f14db81dce4
R15: 00007ffdd918abd7
[ 44.836294][ T9513] </TASK>
[ 44.836597][ T9513] Modules linked in:
[ 44.837113][ T9513] ---[ end trace 0000000000000000 ]---
[ 44.838145][ T9513] RIP: 0010:gspca_input_create_urb+0x134/0x7e0
[ 44.838157][ T9513] Code: 04 28 84 c0 0f 85 27 05 00 00 4c 8d bc 24
80 00 00 00 41 0f b6 34 24 e8 6a c1 31 ff 49 89 c4 49 83 c4 08 4c 89
e0 48 c1 e8 03 <42> 80 3c 28 00 74 08 4c 89 e7 e8 dd cb 15 fa 49 8b 3c
24 31 f6 31
[ 44.838162][ T9513] RSP: 0018:ffffc90002caf0c0 EFLAGS: 00010202
[ 44.838169][ T9513] RAX: 0000000000000001 RBX: 1ffff92000595e24
RCX: ffff88810c2fcc80
[ 44.838174][ T9513] RDX: 0000000000000000 RSI: 0000000000000000
RDI: ffff88802885d000
[ 44.838178][ T9513] RBP: ffffc90002caf1b0 R08: ffffc90002caef47
R09: 1ffff92000595de8
[ 44.838183][ T9513] R10: dffffc0000000000 R11: fffff52000595de9
R12: 0000000000000008
[ 44.838188][ T9513] R13: dffffc0000000000 R14: 1ffff110051758ec
R15: ffffc90002caf140
[ 44.838193][ T9513] FS: 00007f14db81d6c0(0000)
GS:ffff8881da588000(0000) knlGS:0000000000000000
[ 44.838199][ T9513] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 44.838203][ T9513] CR2: 00005623cbf48b30 CR3: 0000000027a85000
CR4: 0000000000752ef0
[ 44.838210][ T9513] PKRU: 55555554
[ 44.838216][ T9513] Kernel panic - not syncing: Fatal exception
[ 44.847920][ T9513] Kernel Offset: disabled
[ 44.848525][ T9513] Rebooting in 86400 seconds..
Regards,
Attachment:
reproducer.c
Description: Binary data