KASAN: use-after-free Read in pfifo_fast_enqueue

From: syzbot <hidden>
Date: 2018-01-16 18:29:08
Also in: lkml

Hello,

syzkaller hit the following crash on  
ce3c209f6733e2cff9335bb1b2ac847fa823410a
git://git.cmpxchg.org/linux-mmots.git/master
compiler: gcc (GCC) 7.1.1 20170620
.config is attached
Raw console output is attached.
Unfortunately, I don't have any reproducer for this bug yet.


IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+ed43b6903ab968b16f54@syzkaller.appspotmail.com
It will help syzbot understand when the bug is fixed. See footer for  
details.
If you forward the report, please keep this part and the footer.

==================================================================
BUG: KASAN: use-after-free in qdisc_pkt_len include/net/sch_generic.h:577  
[inline]
BUG: KASAN: use-after-free in qdisc_qstats_cpu_backlog_inc  
include/net/sch_generic.h:679 [inline]
BUG: KASAN: use-after-free in pfifo_fast_enqueue+0x398/0x420  
net/sched/sch_generic.c:639
Read of size 4 at addr ffff8801bc753be8 by task syz-executor6/4865

CPU: 1 PID: 4865 Comm: syz-executor6 Not tainted 4.15.0-rc7-mm1+ #56
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011
Call Trace:
  <IRQ>
  __dump_stack lib/dump_stack.c:17 [inline]
  dump_stack+0x194/0x257 lib/dump_stack.c:53
  print_address_description+0x73/0x250 mm/kasan/report.c:256
  kasan_report_error mm/kasan/report.c:354 [inline]
  kasan_report+0x23b/0x360 mm/kasan/report.c:412
  __asan_report_load4_noabort+0x14/0x20 mm/kasan/report.c:432
  qdisc_pkt_len include/net/sch_generic.h:577 [inline]
  qdisc_qstats_cpu_backlog_inc include/net/sch_generic.h:679 [inline]
  pfifo_fast_enqueue+0x398/0x420 net/sched/sch_generic.c:639
  __dev_xmit_skb net/core/dev.c:3199 [inline]
  __dev_queue_xmit+0xb54/0x2b50 net/core/dev.c:3501
  dev_queue_xmit+0x17/0x20 net/core/dev.c:3566
  neigh_resolve_output+0x5e2/0xa00 net/core/neighbour.c:1350
  neigh_output include/net/neighbour.h:482 [inline]
  ip6_finish_output2+0xb4a/0x23a0 net/ipv6/ip6_output.c:120
  ip6_finish_output+0x698/0xaf0 net/ipv6/ip6_output.c:154
  NF_HOOK_COND include/linux/netfilter.h:277 [inline]
  ip6_output+0x1eb/0x840 net/ipv6/ip6_output.c:171
  dst_output include/net/dst.h:443 [inline]
  NF_HOOK include/linux/netfilter.h:288 [inline]
  mld_sendpack+0x739/0xe70 net/ipv6/mcast.c:1660
  mld_send_cr net/ipv6/mcast.c:1956 [inline]
  mld_ifc_timer_expire+0x3d9/0x770 net/ipv6/mcast.c:2453
  call_timer_fn+0x228/0x820 kernel/time/timer.c:1318
  expire_timers kernel/time/timer.c:1355 [inline]
  __run_timers+0x7ee/0xb70 kernel/time/timer.c:1658
  run_timer_softirq+0x4c/0x70 kernel/time/timer.c:1684
  __do_softirq+0x2d7/0xb85 kernel/softirq.c:285
  invoke_softirq kernel/softirq.c:365 [inline]
  irq_exit+0x1cc/0x200 kernel/softirq.c:405
  exiting_irq arch/x86/include/asm/apic.h:540 [inline]
  smp_apic_timer_interrupt+0x16b/0x700 arch/x86/kernel/apic/apic.c:1052
  apic_timer_interrupt+0xa9/0xb0 arch/x86/entry/entry_64.S:926
  </IRQ>
RIP: 0010:clear_page_erms+0x7/0x10 arch/x86/lib/clear_page_64.S:49
RSP: 0000:ffff8801a76bf6b0 EFLAGS: 00010246 ORIG_RAX: ffffffffffffff11
RAX: 0000000000000000 RBX: dffffc0000000000 RCX: 00000000000007c0
RDX: ffff8801d6d6e200 RSI: 0000160000000000 RDI: ffff88019e85a840
RBP: ffff8801a76bf700 R08: 000000000002f8d0 R09: 0000000000000000
R10: ffffffffffffffe8 R11: 0000000000000000 R12: ffffea00067a0000
R13: 000000000000003a R14: 000000000000001d R15: 000000000000005a
  __do_huge_pmd_anonymous_page mm/huge_memory.c:570 [inline]
  do_huge_pmd_anonymous_page+0x599/0x1b00 mm/huge_memory.c:728
  create_huge_pmd mm/memory.c:3856 [inline]
  __handle_mm_fault+0x1a0c/0x3ce0 mm/memory.c:4060
  handle_mm_fault+0x38f/0x930 mm/memory.c:4126
  __do_page_fault+0x5c9/0xc90 arch/x86/mm/fault.c:1429
  do_page_fault+0xee/0x720 arch/x86/mm/fault.c:1504
  page_fault+0x4c/0x60 arch/x86/entry/entry_64.S:1249
RIP: 0033:0x405a59
RSP: 002b:0000000000a2f900 EFLAGS: 00010246
RAX: 000000002001d000 RBX: 000000000071bea0 RCX: 0000000000000002
RDX: da87a31dca9dcacc RSI: 0000000000000000 RDI: 0000000002261848
RBP: 0000000000000006 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000a2f900 R11: 0000000000000206 R12: fffffffffffffffe
R13: ffffffffffffffff R14: 0000000000000001 R15: 0000000000000001

Allocated by task 4865:
  save_stack+0x43/0xd0 mm/kasan/kasan.c:447
  set_track mm/kasan/kasan.c:459 [inline]
  kasan_kmalloc+0xad/0xe0 mm/kasan/kasan.c:552
  kasan_slab_alloc+0x12/0x20 mm/kasan/kasan.c:489
  kmem_cache_alloc_node+0x144/0x760 mm/slab.c:3631
  __alloc_skb+0xf1/0x780 net/core/skbuff.c:193
  alloc_skb include/linux/skbuff.h:983 [inline]
  alloc_skb_with_frags+0x10d/0x750 net/core/skbuff.c:5151
  sock_alloc_send_pskb+0x787/0x9b0 net/core/sock.c:2088
  sock_alloc_send_skb+0x32/0x40 net/core/sock.c:2105
  mld_newpack+0x39a/0xaf0 net/ipv6/mcast.c:1585
  add_grhead.isra.24+0x29f/0x380 net/ipv6/mcast.c:1691
  add_grec+0xb89/0x10c0 net/ipv6/mcast.c:1822
  mld_send_cr net/ipv6/mcast.c:1948 [inline]
  mld_ifc_timer_expire+0x364/0x770 net/ipv6/mcast.c:2453
  call_timer_fn+0x228/0x820 kernel/time/timer.c:1318
  expire_timers kernel/time/timer.c:1355 [inline]
  __run_timers+0x7ee/0xb70 kernel/time/timer.c:1658
  run_timer_softirq+0x4c/0x70 kernel/time/timer.c:1684
  __do_softirq+0x2d7/0xb85 kernel/softirq.c:285

Freed by task 23:
  save_stack+0x43/0xd0 mm/kasan/kasan.c:447
  set_track mm/kasan/kasan.c:459 [inline]
  __kasan_slab_free+0x11a/0x170 mm/kasan/kasan.c:520
  kasan_slab_free+0xe/0x10 mm/kasan/kasan.c:527
  __cache_free mm/slab.c:3485 [inline]
  kmem_cache_free+0x86/0x2b0 mm/slab.c:3743
  kfree_skbmem+0x1a1/0x1d0 net/core/skbuff.c:582
  __kfree_skb net/core/skbuff.c:642 [inline]
  kfree_skb+0x165/0x4c0 net/core/skbuff.c:659
  ip_tunnel_xmit+0x709/0x3650 net/ipv4/ip_tunnel.c:796
  __gre_xmit+0x546/0x8b0 net/ipv4/ip_gre.c:461
  erspan_xmit+0x7eb/0x2430 net/ipv4/ip_gre.c:744
  __netdev_start_xmit include/linux/netdevice.h:4046 [inline]
  netdev_start_xmit include/linux/netdevice.h:4055 [inline]
  xmit_one net/core/dev.c:3020 [inline]
  dev_hard_start_xmit+0x24e/0xac0 net/core/dev.c:3036
  sch_direct_xmit+0x40d/0x1140 net/sched/sch_generic.c:327
  qdisc_restart net/sched/sch_generic.c:393 [inline]
  __qdisc_run+0x57d/0x19c0 net/sched/sch_generic.c:401
  __dev_xmit_skb net/core/dev.c:3200 [inline]
  __dev_queue_xmit+0xb62/0x2b50 net/core/dev.c:3501
  dev_queue_xmit+0x17/0x20 net/core/dev.c:3566
  neigh_resolve_output+0x5e2/0xa00 net/core/neighbour.c:1350
  neigh_output include/net/neighbour.h:482 [inline]
  ip6_finish_output2+0xb4a/0x23a0 net/ipv6/ip6_output.c:120
  ip6_finish_output+0x698/0xaf0 net/ipv6/ip6_output.c:154
  NF_HOOK_COND include/linux/netfilter.h:277 [inline]
  ip6_output+0x1eb/0x840 net/ipv6/ip6_output.c:171
  dst_output include/net/dst.h:443 [inline]
  NF_HOOK include/linux/netfilter.h:288 [inline]
  ndisc_send_skb+0xac4/0x1370 net/ipv6/ndisc.c:491
  ndisc_send_ns+0x38a/0x870 net/ipv6/ndisc.c:628
  addrconf_dad_work+0x980/0x12b0 net/ipv6/addrconf.c:3997
  process_one_work+0xbbf/0x1af0 kernel/workqueue.c:2112
  worker_thread+0x223/0x1990 kernel/workqueue.c:2246
  kthread+0x33c/0x400 kernel/kthread.c:238
  ret_from_fork+0x37/0x50 arch/x86/entry/entry_64.S:530

The buggy address belongs to the object at ffff8801bc753bc0
  which belongs to the cache skbuff_head_cache of size 232
The buggy address is located 40 bytes inside of
  232-byte region [ffff8801bc753bc0, ffff8801bc753ca8)
The buggy address belongs to the page:
page:ffffea0006f1d4c0 count:1 mapcount:0 mapping:ffff8801bc753080 index:0x0
flags: 0x2fffc0000000100(slab)
raw: 02fffc0000000100 ffff8801bc753080 0000000000000000 000000010000000c
raw: ffffea0006f271e0 ffffea0006f270a0 ffff8801d986ccc0 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
  ffff8801bc753a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
  ffff8801bc753b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc
ffff8801bc753b80: fc fc fc fc fc fc fc fc fb fb fb fb fb fb fb fb
                                                           ^
  ffff8801bc753c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
  ffff8801bc753c80: fb fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc
==================================================================


---
This bug is generated by a dumb bot. It may contain errors.
See https://goo.gl/tpsmEJ for details.
Direct all questions to syzkaller@googlegroups.com.

syzbot will keep track of this bug report.
If you forgot to add the Reported-by tag, once the fix for this bug is  
merged
into any tree, please reply to this email with:
#syz fix: exact-commit-title
To mark this as a duplicate of another syzbot report, please reply with:
#syz dup: exact-subject-of-another-report
If it's a one-off invalid bug report, please reply with:
#syz invalid
Note: if the crash happens again, it will cause creation of a new bug  
report.
Note: all commands must start from beginning of the line in the email body.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help