Thread (20 messages) flat view 20 messages, 4 authors, 2017-12-11

general protection fault in blkcipher_walk_done

From: syzbot <hidden>
Date: 2017-11-27 18:56:56
Also in: lkml

Hello,

syzkaller hit the following crash on  
1ea8d039f9edcfefb20d8ddfe136930f6e551529
git://git.cmpxchg.org/linux-mmots.git/master
compiler: gcc (GCC) 7.1.1 20170620
.config is attached
Raw console output is attached.
C reproducer is attached
syzkaller reproducer is attached. See https://goo.gl/kgGztJ
for information about syzkaller reproducers


kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] SMP KASAN
Dumping ftrace buffer:
    (ftrace buffer empty)
Modules linked in:
CPU: 0 PID: 3459 Comm: syzkaller843837 Not tainted 4.14.0-mm1+ #25
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011
task: ffff8801bfe7e0c0 task.stack: ffff8801c01f8000
RIP: 0010:scatterwalk_start include/crypto/scatterwalk.h:86 [inline]
RIP: 0010:scatterwalk_pagedone include/crypto/scatterwalk.h:111 [inline]
RIP: 0010:scatterwalk_done include/crypto/scatterwalk.h:119 [inline]
RIP: 0010:blkcipher_walk_done+0x447/0xde0 crypto/blkcipher.c:125
RSP: 0018:ffff8801c01ff6f0 EFLAGS: 00010202
RAX: 0000000000000000 RBX: 00000000000003ef RCX: ffff8801c01ff7e0
RDX: dffffc0000000000 RSI: 0000000000000001 RDI: 0000000000000008
RBP: ffff8801c01ff740 R08: ffffed00372e1e02 R09: 0000000000000010
R10: 0000000000000000 R11: ffffed00372e1e01 R12: ffff8801c01ff8b8
R13: ffff8801c01ff7a0 R14: ffff8801c01ff7e8 R15: ffff8801c0189110
FS:  00007f4f6c774700(0000) GS:ffff8801db400000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020c13000 CR3: 00000001d9ef0000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
  skcipher_null_crypt+0x1da/0x2d0 crypto/crypto_null.c:91
  skcipher_crypt_blkcipher crypto/skcipher.c:619 [inline]
  skcipher_encrypt_blkcipher+0x213/0x310 crypto/skcipher.c:628
  crypto_skcipher_encrypt include/crypto/skcipher.h:445 [inline]
  crypto_aead_copy_sgl crypto/algif_aead.c:90 [inline]
  _aead_recvmsg crypto/algif_aead.c:210 [inline]
  aead_recvmsg+0x7db/0x1970 crypto/algif_aead.c:313
  aead_recvmsg_nokey+0x60/0x80 crypto/algif_aead.c:431
  sock_recvmsg_nosec net/socket.c:805 [inline]
  sock_recvmsg+0xc9/0x110 net/socket.c:812
  ___sys_recvmsg+0x29b/0x630 net/socket.c:2207
  __sys_recvmsg+0xe2/0x210 net/socket.c:2252
  SYSC_recvmsg net/socket.c:2264 [inline]
  SyS_recvmsg+0x2d/0x50 net/socket.c:2259
  entry_SYSCALL_64_fastpath+0x1f/0x96
RIP: 0033:0x4463e9
RSP: 002b:00007f4f6c773dc8 EFLAGS: 00000202 ORIG_RAX: 000000000000002f
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00000000004463e9
RDX: 0000000000002103 RSI: 0000000020709fc8 RDI: 0000000000000008
RBP: 0000000000000086 R08: 00007f4f6c774700 R09: 00007f4f6c774700
R10: 00007f4f6c774700 R11: 0000000000000202 R12: 0000000000000000
R13: 00007ffd952b0bbf R14: 00007f4f6c7749c0 R15: 0000000000000000
Code: c8 48 89 f7 48 c1 ef 03 80 3c 17 00 0f 85 53 08 00 00 48 8d 78 08 48  
ba 00 00 00 00 00 fc ff df 49 89 45 38 48 89 fe 48 c1 ee 03 <0f> b6 14 16  
84 d2 74 09 80 fa 03 0f 8e 37 07 00 00 48 89 ca 44
RIP: scatterwalk_start include/crypto/scatterwalk.h:86 [inline] RSP:  
ffff8801c01ff6f0
RIP: scatterwalk_pagedone include/crypto/scatterwalk.h:111 [inline] RSP:  
ffff8801c01ff6f0
RIP: scatterwalk_done include/crypto/scatterwalk.h:119 [inline] RSP:  
ffff8801c01ff6f0
RIP: blkcipher_walk_done+0x447/0xde0 crypto/blkcipher.c:125 RSP:  
ffff8801c01ff6f0
---[ end trace b86792643e54649a ]---
kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#2] SMP KASAN
Dumping ftrace buffer:
    (ftrace buffer empty)
Modules linked in:
CPU: 1 PID: 3585 Comm: syzkaller843837 Tainted: G      D           
4.14.0-mm1+ #25
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011
task: ffff8801ca904240 task.stack: ffff8801cb1f8000
RIP: 0010:scatterwalk_start include/crypto/scatterwalk.h:86 [inline]
RIP: 0010:scatterwalk_pagedone include/crypto/scatterwalk.h:111 [inline]
RIP: 0010:scatterwalk_done include/crypto/scatterwalk.h:119 [inline]
RIP: 0010:blkcipher_walk_done+0x447/0xde0 crypto/blkcipher.c:125
RSP: 0018:ffff8801cb1ff6f0 EFLAGS: 00010202
RAX: 0000000000000000 RBX: 00000000000003ef RCX: ffff8801cb1ff7e0
RDX: dffffc0000000000 RSI: 0000000000000001 RDI: 0000000000000008
RBP: ffff8801cb1ff740 R08: ffffed00374e1e02 R09: 0000000000000010
R10: 0000000000000000 R11: ffffed00374e1e01 R12: ffff8801cb1ff8b8
R13: ffff8801cb1ff7a0 R14: ffff8801cb1ff7e8 R15: ffff8801cad38ad0
FS:  00007f4f6075c700(0000) GS:ffff8801db500000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f4f67769e78 CR3: 00000001d83fb000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
  skcipher_null_crypt+0x1da/0x2d0 crypto/crypto_null.c:91
  skcipher_crypt_blkcipher crypto/skcipher.c:619 [inline]
  skcipher_encrypt_blkcipher+0x213/0x310 crypto/skcipher.c:628
  crypto_skcipher_encrypt include/crypto/skcipher.h:445 [inline]
  crypto_aead_copy_sgl crypto/algif_aead.c:90 [inline]
  _aead_recvmsg crypto/algif_aead.c:210 [inline]
  aead_recvmsg+0x7db/0x1970 crypto/algif_aead.c:313
  aead_recvmsg_nokey+0x60/0x80 crypto/algif_aead.c:431
  sock_recvmsg_nosec net/socket.c:805 [inline]
  sock_recvmsg+0xc9/0x110 net/socket.c:812
  ___sys_recvmsg+0x29b/0x630 net/socket.c:2207
  __sys_recvmsg+0xe2/0x210 net/socket.c:2252
  SYSC_recvmsg net/socket.c:2264 [inline]
  SyS_recvmsg+0x2d/0x50 net/socket.c:2259
  entry_SYSCALL_64_fastpath+0x1f/0x96
RIP: 0033:0x4463e9
RSP: 002b:00007f4f6075bdc8 EFLAGS: 00000202 ORIG_RAX: 000000000000002f
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00000000004463e9
RDX: 0000000000002103 RSI: 0000000020709fc8 RDI: 000000000000000e
RBP: 00007ffd952b0bc0 R08: 00007f4f6075c700 R09: 00007f4f6075c700
R10: 00007f4f6075c700 R11: 0000000000000202 R12: 0000000000000000
R13: 00007ffd952b0bbf R14: 00007f4f6075c9c0 R15: 0000000000000000
Code: c8 48 89 f7 48 c1 ef 03 80 3c 17 00 0f 85 53 08 00 00 48 8d 78 08 48  
ba 00 00 00 00 00 fc ff df 49 89 45 38 48 89 fe 48 c1 ee 03 <0f> b6 14 16  
84 d2 74 09 80 fa 03 0f 8e 37 07 00 00 48 89 ca 44
RIP: scatterwalk_start include/crypto/scatterwalk.h:86 [inline] RSP:  
ffff8801cb1ff6f0
RIP: scatterwalk_pagedone include/crypto/scatterwalk.h:111 [inline] RSP:  
ffff8801cb1ff6f0
RIP: scatterwalk_done include/crypto/scatterwalk.h:119 [inline] RSP:  
ffff8801cb1ff6f0
RIP: blkcipher_walk_done+0x447/0xde0 crypto/blkcipher.c:125 RSP:  
ffff8801cb1ff6f0
---[ end trace b86792643e54649b ]---


---
This bug is generated by a dumb bot. It may contain errors.
See https://goo.gl/tpsmEJ for details.
Direct all questions to syzkaller@googlegroups.com.
Please credit me with: Reported-by: syzbot [off-list ref]

syzbot will keep track of this bug report.
Once a fix for this bug is committed, please reply to this email with:
#syz fix: exact-commit-title
If you want to test a patch for this bug, please reply with:
#syz test: git://repo/address.git branch
and provide the patch inline or as an attachment.
To mark this as a duplicate of another syzbot report, please reply with:
#syz dup: exact-subject-of-another-report
If it's a one-off invalid bug report, please reply with:
#syz invalid
Note: if the crash happens again, it will cause creation of a new bug  
report.
Note: all commands must start from beginning of the line in the email body.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help