Re: [syzbot] [kernel?] KASAN: slab-use-after-free Write in bus_for_each_drv
From: syzbot
Date: Sun Aug 23 2026 - 21:20:11 EST
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
-0x00000000b8600000] (64MB)
[ 11.599912][ T1] ACPI: bus type thunderbolt registered
[ 11.742383][ T1] RAPL PMU: API unit is 2^-32 Joules, 0 fixed counters, 10737418240 ms ovfl timer
[ 11.808342][ T70] kworker/u8:3 (70) used greatest stack depth: 28424 bytes left
[ 11.808482][ T71] kworker/u8:5 (71) used greatest stack depth: 27728 bytes left
[ 11.908721][ T1] kvm_amd: CPU 1 isn't AMD or Hygon
[ 11.908764][ T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
[ 11.909880][ T1] clocksource: Switched to clocksource tsc
[ 11.959472][ T73] kworker/u8:5 (73) used greatest stack depth: 27312 bytes left
[ 12.004111][ T75] kworker/u8:5 (75) used greatest stack depth: 26680 bytes left
[ 12.171591][ T1] Initialise system trusted keyrings
[ 12.188484][ T1] workingset: timestamp_bits=40 (anon: 35) max_order=21 bucket_order=0 (anon: 0)
[ 12.232071][ T1] DLM installed
[ 12.270720][ T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 12.310924][ T1] NFS: Registering the id_resolver key type
[ 12.311151][ T1] Key type id_resolver registered
[ 12.311167][ T1] Key type id_legacy registered
[ 12.311698][ T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[ 12.311932][ T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[ 12.349827][ T1] smbdirect: subsystem loading...
[ 12.473464][ T1] smbdirect: subsystem loaded
[ 12.556036][ T1] Key type cifs.spnego registered
[ 12.557192][ T1] Key type cifs.idmap registered
[ 12.612279][ T1] ntfs3: Enabled Linux POSIX ACLs support
[ 12.612296][ T1] ntfs3: Read-only LZX/Xpress compression included
[ 12.613918][ T1] jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
[ 12.707150][ T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[ 12.710929][ T1] QNX4 filesystem 0.2.3 registered.
[ 12.728727][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 12.777345][ T1] fuse: init (API version 7.45)
[ 12.813692][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 12.827109][ T1] orangefs_init: module version upstream loaded
[ 12.832698][ T1] JFS: nTxBlock = 8192, nTxLock = 65536
[ 12.902685][ T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[ 12.939665][ T1] 9p: Installing v9fs 9p2000 file system support
[ 12.942832][ T1] NILFS version 2 loaded
[ 12.942854][ T1] befs: version: 0.9.3
[ 12.946918][ T1] ocfs2: Registered cluster interface o2cb
[ 12.958238][ T1] ocfs2: Registered cluster interface user
[ 12.979796][ T1] OCFS2 User DLM kernel interface loaded
[ 13.137006][ T1] gfs2: GFS2 installed
[ 13.186192][ T1] ceph: loaded (mds proto 32)
[ 13.239816][ T1] NET: Registered PF_ALG protocol family
[ 13.241279][ T1] async_tx: api initialized (async)
[ 13.241362][ T1] Key type asymmetric registered
[ 13.241613][ T1] Asymmetric key parser 'x509' registered
[ 13.241642][ T1] Asymmetric key parser 'pkcs8' registered
[ 13.241663][ T1] Key type pkcs7_test registered
[ 13.244006][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 13.247405][ T1] io scheduler mq-deadline registered
[ 13.247428][ T1] io scheduler kyber registered
[ 13.251382][ T1] io scheduler bfq registered
[ 13.274291][ T1] raid6: skipped pq benchmark and selected avx2x4
[ 13.482571][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 13.514265][ T1] ACPI: button: Power Button [PWRF]
[ 13.537302][ T1] input: Sleep Button as /devices/platform/LNXSLPBN:00/input/input1
[ 13.568912][ T1] ACPI: button: Sleep Button [SLPF]
[ 13.662280][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 13.795622][ T10] ACPI: \_SB_.LNKC: Enabled at IRQ 11
[ 13.796273][ T10] virtio-pci 0000:00:03.0: virtio_pci: leaving for legacy driver
[ 13.911245][ T10] ACPI: \_SB_.LNKD: Enabled at IRQ 10
[ 13.911473][ T10] virtio-pci 0000:00:04.0: virtio_pci: leaving for legacy driver
[ 14.036923][ T10] ACPI: \_SB_.LNKB: Enabled at IRQ 10
[ 14.037334][ T10] virtio-pci 0000:00:06.0: virtio_pci: leaving for legacy driver
[ 14.134871][ T10] virtio-pci 0000:00:07.0: virtio_pci: leaving for legacy driver
[ 14.455961][ T276] kworker/u8:3 (276) used greatest stack depth: 26536 bytes left
[ 16.547826][ T1] N_HDLC line discipline registered with maxframe=4096
[ 16.550769][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 16.605843][ T1] 00:02: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 16.671871][ T1] 00:03: ttyS1 at I/O 0x2f8 (irq = 3, base_baud = 115200) is a 16550A
[ 16.730076][ T1] 00:04: ttyS2 at I/O 0x3e8 (irq = 6, base_baud = 115200) is a 16550A
[ 16.805136][ T1] 00:05: ttyS3 at I/O 0x2e8 (irq = 7, base_baud = 115200) is a 16550A
[ 16.949551][ T1] Non-volatile memory driver v1.3
[ 17.132363][ T1] usbcore: registered new interface driver xillyusb
[ 17.183391][ T1] ACPI: bus type drm_connector registered
[ 17.243108][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 17.314892][ T1] ------------[ cut here ]------------
[ 17.314909][ T1] [PLANE:35:plane-0] pixel format with alpha exposed but blend mode not setup
[ 17.314933][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6d/0x1e60, CPU#0: swapper/0/1
[ 17.315009][ T1] Modules linked in:
[ 17.315074][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 17.315098][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
[ 17.315123][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 17.315929][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 5a d7 af fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 56 4a 44 fc 49 bd 00 00 00 00 00 fc ff df
[ 17.315949][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 17.315969][ T1] RAX: 1ffff11004bcd808 RBX: dffffc0000000000 RCX: ffff88801c6b5dc0
[ 17.315986][ T1] RDX: ffff888025a56980 RSI: 0000000000000023 RDI: ffffffff8fbcf300
[ 17.316002][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 17.316015][ T1] R10: dffffc0000000000 R11: fffffbfff1f63828 R12: dffffc0000000000
[ 17.316031][ T1] R13: ffffffff8fbcf300 R14: ffff888025e6c040 R15: ffff888025e6c030
[ 17.316047][ T1] FS: 0000000000000000(0000) GS:ffff888125be6000(0000) knlGS:0000000000000000
[ 17.316065][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 17.316079][ T1] CR2: ffff88823ffff000 CR3: 000000000dfb0000 CR4: 00000000003526f0
[ 17.316098][ T1] Call Trace:
[ 17.316108][ T1] <TASK>
[ 17.316128][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 17.316273][ T1] drm_dev_register+0x7f/0xd80
[ 17.316310][ T1] vkms_create+0x40d/0x4f0
[ 17.316337][ T1] ? __pfx_vkms_init+0x10/0x10
[ 17.316373][ T1] vkms_init+0x57/0x80
[ 17.316402][ T1] do_one_initcall+0x250/0x870
[ 17.316445][ T1] ? __pfx_vkms_init+0x10/0x10
[ 17.316473][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 17.316511][ T1] ? kvm_clock_get_cycles+0x49/0x60
[ 17.316543][ T1] ? __pfx___schedule+0x10/0x10
[ 17.316576][ T1] ? clockevents_program_event+0x491/0x630
[ 17.316607][ T1] ? __hrtimer_rearm_deferred+0x99/0x4d0
[ 17.318440][ T1] ? irqentry_exit+0x218/0x910
[ 17.318510][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 17.318545][ T1] ? irqentry_exit+0x218/0x910
[ 17.318575][ T1] ? trace_irq_disable+0x3b/0x140
[ 17.318624][ T1] ? next_arg+0x4a0/0x5e0
[ 17.318660][ T1] ? parameq+0x14d/0x170
[ 17.318690][ T1] ? parse_args+0x9c3/0xad0
[ 17.318747][ T1] ? rcu_is_watching+0x16/0xb0
[ 17.318786][ T1] do_initcall_level+0x10a/0x1a0
[ 17.318830][ T1] ? kernel_init+0x22/0x1d0
[ 17.318867][ T1] do_initcalls+0x59/0xa0
[ 17.318908][ T1] kernel_init_freeable+0x29d/0x3e0
[ 17.318947][ T1] ? __pfx_kernel_init+0x10/0x10
[ 17.318987][ T1] kernel_init+0x22/0x1d0
[ 17.319029][ T1] ? __pfx_kernel_init+0x10/0x10
[ 17.319065][ T1] ret_from_fork+0x514/0xb70
[ 17.319106][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 17.321040][ T1] ? __switch_to+0xc89/0x1420
[ 17.321120][ T1] ? __pfx_kernel_init+0x10/0x10
[ 17.321163][ T1] ret_from_fork_asm+0x1a/0x30
[ 17.321202][ T1] </TASK>
[ 17.321228][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 17.321250][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 17.321274][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
[ 17.321288][ T1] Call Trace:
[ 17.321298][ T1] <TASK>
[ 17.321307][ T1] vpanic+0x56d/0xa60
[ 17.321329][ T1] ? __pfx__printk+0x10/0x10
[ 17.321354][ T1] ? __pfx_vpanic+0x10/0x10
[ 17.321372][ T1] ? is_bpf_text_address+0x292/0x2b0
[ 17.321401][ T1] ? is_bpf_text_address+0x26/0x2b0
[ 17.321437][ T1] panic+0xc5/0xd0
[ 17.321457][ T1] ? __pfx_panic+0x10/0x10
[ 17.321487][ T1] ? ret_from_fork_asm+0x1a/0x30
[ 17.321513][ T1] __warn+0x315/0x4c0
[ 17.321532][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 17.321568][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 17.321596][ T1] __report_bug+0x276/0x570
[ 17.321625][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 17.321656][ T1] ? __pfx___report_bug+0x10/0x10
[ 17.322207][ T1] ? _raw_spin_unlock_irqrestore+0x30/0x80
[ 17.322248][ T1] ? rt_mutex_slowunlock+0x4ee/0xa30
[ 17.322275][ T1] report_bug_entry+0x19b/0x290
[ 17.322306][ T1] ? drm_mode_config_validate+0x1cae/0x1e60
[ 17.322338][ T1] ? drm_mode_config_validate+0x1cb3/0x1e60
[ 17.322982][ T1] handle_bug+0xce/0x200
[ 17.323038][ T1] exc_invalid_op+0x1a/0x50
[ 17.323075][ T1] asm_exc_invalid_op+0x1a/0x20
[ 17.323101][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 17.323142][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 5a d7 af fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 56 4a 44 fc 49 bd 00 00 00 00 00 fc ff df
[ 17.323163][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 17.323186][ T1] RAX: 1ffff11004bcd808 RBX: dffffc0000000000 RCX: ffff88801c6b5dc0
[ 17.323205][ T1] RDX: ffff888025a56980 RSI: 0000000000000023 RDI: ffffffff8fbcf300
[ 17.323222][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 17.323237][ T1] R10: dffffc0000000000 R11: fffffbfff1f63828 R12: dffffc0000000000
[ 17.323388][ T1] R13: ffffffff8fbcf300 R14: ffff888025e6c040 R15: ffff888025e6c030
[ 17.323437][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 17.323476][ T1] drm_dev_register+0x7f/0xd80
[ 17.323517][ T1] vkms_create+0x40d/0x4f0
[ 17.323548][ T1] ? __pfx_vkms_init+0x10/0x10
[ 17.323582][ T1] vkms_init+0x57/0x80
[ 17.323617][ T1] do_one_initcall+0x250/0x870
[ 17.323655][ T1] ? __pfx_vkms_init+0x10/0x10
[ 17.323687][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 17.323731][ T1] ? kvm_clock_get_cycles+0x49/0x60
[ 17.324961][ T1] ? __pfx___schedule+0x10/0x10
[ 17.325015][ T1] ? clockevents_program_event+0x491/0x630
[ 17.325058][ T1] ? __hrtimer_rearm_deferred+0x99/0x4d0
[ 17.325107][ T1] ? irqentry_exit+0x218/0x910
[ 17.325950][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 17.325977][ T1] ? irqentry_exit+0x218/0x910
[ 17.325999][ T1] ? trace_irq_disable+0x3b/0x140
[ 17.326037][ T1] ? next_arg+0x4a0/0x5e0
[ 17.326399][ T1] ? parameq+0x14d/0x170
[ 17.326436][ T1] ? parse_args+0x9c3/0xad0
[ 17.326488][ T1] ? rcu_is_watching+0x16/0xb0
[ 17.326530][ T1] do_initcall_level+0x10a/0x1a0
[ 17.326576][ T1] ? kernel_init+0x22/0x1d0
[ 17.326615][ T1] do_initcalls+0x59/0xa0
[ 17.326656][ T1] kernel_init_freeable+0x29d/0x3e0
[ 17.326695][ T1] ? __pfx_kernel_init+0x10/0x10
[ 17.326972][ T1] kernel_init+0x22/0x1d0
[ 17.327019][ T1] ? __pfx_kernel_init+0x10/0x10
[ 17.327052][ T1] ret_from_fork+0x514/0xb70
[ 17.327090][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 17.327123][ T1] ? __switch_to+0xc89/0x1420
[ 17.327166][ T1] ? __pfx_kernel_init+0x10/0x10
[ 17.327206][ T1] ret_from_fork_asm+0x1a/0x30
[ 17.327246][ T1] </TASK>
[ 17.327972][ T1] Kernel Offset: disabled
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build3418809368=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs-2/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at d4abbeacd53
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d4abbeacd53add822a563e66a8ca9e64929b96ab -X github.com/google/syzkaller/prog.gitRevisionDate=20260804-103143" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d4abbeacd53add822a563e66a8ca9e64929b96ab -X github.com/google/syzkaller/prog.gitRevisionDate=20260804-103143" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d4abbeacd53add822a563e66a8ca9e64929b96ab -X github.com/google/syzkaller/prog.gitRevisionDate=20260804-103143" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"d4abbeacd53add822a563e66a8ca9e64929b96ab\"
/usr/bin/ld: /tmp/ccSFcTDt.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=12f43549580000
Tested on:
commit: 4352b8ae Merge tag 'i3c/for-7.3' of git://git.kernel.o..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=c01bf1b5895f71b2
dashboard link: https://syzkaller.appspot.com/bug?extid=9cb1ac7fce4944ba9165
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=10c13179580000