[....] Starting enhanced syslogd: rsyslogd[ 5.302041] audit: type=1400 audit(1513711406.788:5): avc: denied { syslog } for pid=2969 comm="rsyslogd" capability=34 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=1 [?25l[?1c7[ ok 8[?25h[?0c. [....] Starting periodic command scheduler: cron[?25l[?1c7[ ok 8[?25h[?0c. Starting mcstransd: [....] Starting file context maintaining daemon: restorecond[?25l[?1c7[ ok 8[?25h[?0c. [....] Starting OpenBSD Secure Shell server: sshd[?25l[?1c7[ ok 8[?25h[?0c. Debian GNU/Linux 7 syzkaller ttyS0 syzkaller login: [ 13.345626] audit: type=1400 audit(1513711414.832:6): avc: denied { map } for pid=3105 comm="bash" path="/bin/bash" dev="sda1" ino=1457 scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tcontext=system_u:object_r:file_t:s0 tclass=file permissive=1 Warning: Permanently added 'ci-upstream-next-kasan-gce-6,10.128.15.236' (ECDSA) to the list of known hosts. executing program [ 35.213819] audit: type=1400 audit(1513711436.700:7): avc: denied { map } for pid=3124 comm="syzkaller396275" path="/root/syzkaller396275826" dev="sda1" ino=16481 scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=1 [ 35.246283] ------------[ cut here ]------------ [ 35.251085] refcount_t: increment on 0; use-after-free. [ 35.256497] WARNING: CPU: 1 PID: 3125 at lib/refcount.c:153 refcount_inc+0x47/0x50 [ 35.264169] Kernel panic - not syncing: panic_on_warn set ... [ 35.264169] [ 35.271497] CPU: 1 PID: 3125 Comm: syzkaller396275 Not tainted 4.15.0-rc3-next-20171214+ #67 [ 35.280045] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 [ 35.289365] Call Trace: [ 35.291923] dump_stack+0xe9/0x14b [ 35.295429] ? refcount_inc+0x47/0x50 [ 35.299198] panic+0x10e/0x2f8 [ 35.302384] ? __warn+0x138/0x150 [ 35.305803] ? refcount_inc+0x47/0x50 [ 35.309576] __warn+0x14e/0x150 [ 35.312821] ? refcount_inc+0x47/0x50 [ 35.316590] report_bug+0x11e/0x1a0 [ 35.320189] fixup_bug.part.11+0x17/0x30 [ 35.324224] do_error_trap+0x14a/0x180 [ 35.328080] ? vprintk_emit+0x2eb/0x430 [ 35.332023] ? trace_hardirqs_off_thunk+0x1a/0x1c [ 35.336834] ? C_SYSC_mq_getsetattr+0x170/0x170 [ 35.341467] do_invalid_op+0x1b/0x20 [ 35.345147] invalid_op+0x22/0x40 [ 35.348566] RIP: 0010:refcount_inc+0x47/0x50 [ 35.352935] RSP: 0018:ffffc9000186bb90 EFLAGS: 00010282 [ 35.358262] RAX: 000000000000002b RBX: ffff880214e2f800 RCX: ffffffff8123dede [ 35.365495] RDX: 0000000000000000 RSI: ffff880214d5f018 RDI: 0000000000000293 [ 35.372729] RBP: ffffc9000186bb98 R08: 0000000000000000 R09: 0000000000000000 [ 35.379964] R10: ffffc9000186bb18 R11: 0000000000000000 R12: ffffffff8162ef10 [ 35.387196] R13: ffff8802156d2578 R14: ffff8802156d2600 R15: 0000000000000001 [ 35.394435] ? C_SYSC_mq_getsetattr+0x170/0x170 [ 35.399069] ? vprintk_func+0x5e/0xc0 [ 35.402837] mqueue_evict_inode+0x69/0x340 [ 35.407035] ? _raw_spin_unlock+0x22/0x30 [ 35.411147] ? C_SYSC_mq_getsetattr+0x170/0x170 [ 35.415781] evict+0x102/0x230 [ 35.418938] iput+0x32b/0x400 [ 35.422010] dentry_unlink_inode+0x1ab/0x1e0 [ 35.426382] __dentry_kill+0x12d/0x210 [ 35.430234] shrink_dentry_list+0x140/0x660 [ 35.434522] shrink_dcache_parent+0x2f/0x90 [ 35.438808] do_one_tree+0x15/0x50 [ 35.442313] shrink_dcache_for_umount+0x37/0xb0 [ 35.446949] generic_shutdown_super+0x2d/0x170 [ 35.451504] kill_litter_super+0x36/0x50 [ 35.455532] deactivate_locked_super+0x4d/0x80 [ 35.460081] deactivate_super+0x61/0x90 [ 35.464019] cleanup_mnt+0x49/0x90 [ 35.467524] __cleanup_mnt+0x16/0x20 [ 35.471204] task_work_run+0xa3/0xe0 [ 35.474882] do_exit+0x3e6/0x1050 [ 35.478301] ? putname+0x8a/0xa0 [ 35.481632] ? do_sys_open+0x1c7/0x340 [ 35.485486] do_group_exit+0x60/0x100 [ 35.489253] SyS_exit_group+0x18/0x20 [ 35.493016] entry_SYSCALL_64_fastpath+0x1f/0x96 [ 35.497733] RIP: 0033:0x4406f9 [ 35.500886] RSP: 002b:00007ffde12b8798 EFLAGS: 00000206 ORIG_RAX: 00000000000000e7 [ 35.508558] RAX: ffffffffffffffda RBX: 0030656c69662f2e RCX: 00000000004406f9 [ 35.515793] RDX: 00000000004406f9 RSI: 00000000004406f9 RDI: 0000000000000001 [ 35.523026] RBP: 00000000006cb018 R08: 0000000000000000 R09: 00000000004002c8 [ 35.530261] R10: 0000000000000000 R11: 0000000000000206 R12: 0000000000401bc0 [ 35.537497] R13: 0000000000401c50 R14: 0000000000000000 R15: 0000000000000000 [ 35.544872] Dumping ftrace buffer: [ 35.548404] (ftrace buffer empty) [ 35.552080] Kernel Offset: disabled [ 35.555673] Rebooting in 86400 seconds..