lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date:   Mon, 01 Jan 2018 22:13:01 -0800
From:   syzbot <syzbot+a8d726b19492f85fdb50@...kaller.appspotmail.com>
To:     alsa-devel-bounces@...a-project.org, alsa-devel@...a-project.org,
        linux-kernel@...r.kernel.org, mingo@...nel.org,
        o-takashi@...amocchi.jp, perex@...ex.cz,
        syzkaller-bugs@...glegroups.com, tiwai@...e.com
Subject: WARNING in snd_pcm_hw_param_last

syzkaller has found reproducer for the following crash on  
30a7acd573899fd8b8ac39236eff6468b195ac7d
git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/master
compiler: gcc (GCC) 7.1.1 20170620
.config is attached
Raw console output is attached.
C reproducer is attached
syzkaller reproducer is attached. See https://goo.gl/kgGztJ
for information about syzkaller reproducers


IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a8d726b19492f85fdb50@...kaller.appspotmail.com
It will help syzbot understand when the bug is fixed.

WARNING: CPU: 0 PID: 3647 at sound/core/pcm_lib.c:1681  
snd_pcm_hw_param_last+0x28b/0x670 sound/core/pcm_lib.c:1681
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 3647 Comm: syzkaller312889 Not tainted 4.15.0-rc6+ #245
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011
Call Trace:
  __dump_stack lib/dump_stack.c:17 [inline]
  dump_stack+0x194/0x257 lib/dump_stack.c:53
  panic+0x1e4/0x41c kernel/panic.c:183
  __warn+0x1dc/0x200 kernel/panic.c:547
  report_bug+0x211/0x2d0 lib/bug.c:184
  fixup_bug.part.11+0x37/0x80 arch/x86/kernel/traps.c:178
  fixup_bug arch/x86/kernel/traps.c:247 [inline]
  do_error_trap+0x2d7/0x3e0 arch/x86/kernel/traps.c:296
  do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:315
  invalid_op+0x22/0x40 arch/x86/entry/entry_64.S:1079
RIP: 0010:snd_pcm_hw_param_last+0x28b/0x670 sound/core/pcm_lib.c:1681
RSP: 0000:ffff8801d0597340 EFLAGS: 00010293
RAX: ffff8801be9526c0 RBX: ffff8801bf6b1b40 RCX: ffffffff841bb75b
RDX: 0000000000000000 RSI: 00000000ffffffea RDI: ffffed003a0b2e60
RBP: ffff8801d0597388 R08: ffffed003a0b2d97 R09: ffff8801d0596cb0
R10: 0000000000000001 R11: ffffed003a0b2d96 R12: 000000000000000f
R13: 00000000ffffffea R14: 0000000000000007 R15: 0000000000008000
  snd_pcm_hw_param_near.constprop.27+0x6f5/0x9a0 sound/core/oss/pcm_oss.c:455
  snd_pcm_oss_change_params+0x1833/0x3720 sound/core/oss/pcm_oss.c:973
  snd_pcm_oss_make_ready+0xaa/0x130 sound/core/oss/pcm_oss.c:1128
  snd_pcm_oss_sync+0x34b/0x830 sound/core/oss/pcm_oss.c:1578
  snd_pcm_oss_release+0x20b/0x280 sound/core/oss/pcm_oss.c:2431
  __fput+0x327/0x7e0 fs/file_table.c:210
  ____fput+0x15/0x20 fs/file_table.c:244
  task_work_run+0x199/0x270 kernel/task_work.c:113
  exit_task_work include/linux/task_work.h:22 [inline]
  do_exit+0x9bb/0x1ad0 kernel/exit.c:865
  do_group_exit+0x149/0x400 kernel/exit.c:968
  SYSC_exit_group kernel/exit.c:979 [inline]
  SyS_exit_group+0x1d/0x20 kernel/exit.c:977
  entry_SYSCALL_64_fastpath+0x23/0x9a
RIP: 0033:0x444509
RSP: 002b:00007ffc1a9636b8 EFLAGS: 00000206 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000444509
RDX: 0000000000400eb0 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 000000000000896d R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000206 R12: 0000000000000000
R13: 0000000000401e10 R14: 0000000000000000 R15: 0000000000000000
Dumping ftrace buffer:
    (ftrace buffer empty)
Kernel Offset: disabled
Rebooting in 86400 seconds..


View attachment "config.txt" of type "text/plain" (134059 bytes)

Download attachment "raw.log" of type "application/octet-stream" (9779 bytes)

View attachment "repro.txt" of type "text/plain" (470 bytes)

Download attachment "repro.c" of type "application/octet-stream" (2848 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ