[....] Starting enhanced syslogd: rsyslogd[?25l[?1c7[ ok 8[?25h[?0c. Starting mcstransd: [....] Starting periodic command scheduler: cron[?25l[?1c7[ ok 8[?25h[?0c. [....] Starting file context maintaining daemon: restorecond[?25l[?1c7[ ok 8[?25h[?0c. [....] Starting OpenBSD Secure Shell server: sshd[?25l[?1c7[ ok 8[?25h[?0c. Debian GNU/Linux 7 syzkaller ttyS0 syzkaller login: [ 18.970954] audit: type=1400 audit(1517932463.114:6): avc: denied { map } for pid=3977 comm="bash" path="/bin/bash" dev="sda1" ino=1457 scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tcontext=system_u:object_r:file_t:s0 tclass=file permissive=1 [ 19.002707] sshd (3974) used greatest stack depth: 16704 bytes left Warning: Permanently added '10.128.0.9' (ECDSA) to the list of known hosts. net.ipv6.conf.syz0.accept_dad = 0 net.ipv6.conf.syz0.router_solicitations = 0 [ 40.286638] audit: type=1400 audit(1517932484.430:7): avc: denied { map } for pid=3994 comm="syzkaller552561" path="/root/syzkaller552561746" dev="sda1" ino=16481 scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=1 RTNETLINK answers: Operation not supported RTNETLINK answers: No buffer space available RTNETLINK answers: Operation not supported [ 40.553826] IPv6: ADDRCONF(NETDEV_UP): bridge0: link is not ready RTNETLINK answers: Operation not supported RTNETLINK answers: Operation not supported RTNETLINK answers: Operation not supported RTNETLINK answers: Invalid argument RTNETLINK answers: Invalid argument RTNETLINK answers: Invalid argument executing program [ 40.882539] ------------[ cut here ]------------ [ 40.887358] Bad or missing usercopy whitelist? Kernel memory exposure attempt detected from SLAB object 'skbuff_head_cache' (offset 64, size 16)! [ 40.900635] WARNING: CPU: 0 PID: 3994 at mm/usercopy.c:81 usercopy_warn+0xdb/0x100 [ 40.908315] Kernel panic - not syncing: panic_on_warn set ... [ 40.908315] [ 40.915652] CPU: 0 PID: 3994 Comm: syzkaller552561 Not tainted 4.15.0+ #210 [ 40.922723] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 [ 40.932057] Call Trace: [ 40.934623] dump_stack+0x194/0x257 [ 40.938225] ? arch_local_irq_restore+0x53/0x53 [ 40.942873] ? vsnprintf+0x1ed/0x1900 [ 40.946652] panic+0x1e4/0x41c [ 40.949819] ? refcount_error_report+0x214/0x214 [ 40.954556] ? show_regs_print_info+0x18/0x18 [ 40.959028] ? __warn+0x1c1/0x200 [ 40.962457] ? usercopy_warn+0xdb/0x100 [ 40.966413] __warn+0x1dc/0x200 [ 40.969666] ? usercopy_warn+0xdb/0x100 [ 40.973615] report_bug+0x211/0x2d0 [ 40.977223] fixup_bug.part.11+0x37/0x80 [ 40.981269] do_error_trap+0x2d7/0x3e0 [ 40.985135] ? vprintk_default+0x28/0x30 [ 40.989179] ? math_error+0x400/0x400 [ 40.992951] ? printk+0xaa/0xca [ 40.996201] ? show_regs_print_info+0x18/0x18 [ 41.000676] ? trace_hardirqs_off_thunk+0x1a/0x1c [ 41.005496] do_invalid_op+0x1b/0x20 [ 41.009183] invalid_op+0x22/0x40 [ 41.012609] RIP: 0010:usercopy_warn+0xdb/0x100 [ 41.017162] RSP: 0018:ffff8801cf3873f0 EFLAGS: 00010286 [ 41.022500] RAX: dffffc0000000008 RBX: ffffffff86801907 RCX: ffffffff815a585e [ 41.029743] RDX: 0000000000000000 RSI: 1ffff10039e70e2e RDI: 1ffff10039e70e03 [ 41.036988] RBP: ffff8801cf387448 R08: 0000000000000000 R09: 0000000000000000 [ 41.044230] R10: 0000000000000866 R11: 0000000000000000 R12: ffffffff86403180 [ 41.051474] R13: ffffffff85f2d4c0 R14: 0000000000000040 R15: 0000000000000010 [ 41.058731] ? vprintk_func+0x5e/0xc0 [ 41.062608] __check_heap_object+0x89/0xc0 [ 41.066815] __check_object_size+0x272/0x530 [ 41.071196] ? retint_kernel+0x10/0x10 [ 41.075058] ? usercopy_abort+0xd0/0xd0 [ 41.079012] ? copy_user_generic_unrolled+0x89/0xc0 [ 41.084001] ? _copy_to_user+0xa2/0xc0 [ 41.087864] put_cmsg_compat+0x724/0xa50 [ 41.091905] ? cmsghdr_from_user_compat_to_kern+0x650/0x650 [ 41.097598] ? rcu_read_lock_sched_held+0x108/0x120 [ 41.102588] ? skb_copy_datagram_iter+0x212/0xac0 [ 41.107412] put_cmsg+0x33a/0x3f0 [ 41.110836] ? __sk_queue_drop_skb+0x1d0/0x1d0 [ 41.115406] ? __scm_send+0x11a0/0x11a0 [ 41.119355] ? sock_dequeue_err_skb+0x2b1/0x420 [ 41.124001] sock_recv_errqueue+0x200/0x3e0 [ 41.128300] packet_recvmsg+0xb2e/0x17a0 [ 41.132339] ? packet_getname_spkt+0x2b0/0x2b0 [ 41.136898] ? _copy_from_user+0x99/0x110 [ 41.141025] ? selinux_socket_recvmsg+0x36/0x40 [ 41.145664] ? security_socket_recvmsg+0x91/0xc0 [ 41.150393] ? packet_getname_spkt+0x2b0/0x2b0 [ 41.154955] sock_recvmsg+0xc9/0x110 [ 41.158640] ? __sock_recv_wifi_status+0x210/0x210 [ 41.163550] ___sys_recvmsg+0x2a4/0x640 [ 41.167508] ? ___sys_sendmsg+0x8b0/0x8b0 [ 41.171636] ? _raw_spin_unlock+0x22/0x30 [ 41.175759] ? __handle_mm_fault+0x80e/0x3ce0 [ 41.180229] ? __pmd_alloc+0x4e0/0x4e0 [ 41.184090] ? check_noncircular+0x20/0x20 [ 41.188301] ? __fget_light+0x2b2/0x3c0 [ 41.192246] ? fget_raw+0x20/0x20 [ 41.195675] ? handle_mm_fault+0x2a0/0x930 [ 41.199884] ? find_held_lock+0x35/0x1d0 [ 41.203932] __sys_recvmsg+0xe2/0x210 [ 41.207704] ? __sys_recvmsg+0xe2/0x210 [ 41.211654] ? SyS_sendmmsg+0x60/0x60 [ 41.215434] ? handle_mm_fault+0x476/0x930 [ 41.219651] ? __handle_mm_fault+0x3ce0/0x3ce0 [ 41.224203] ? vmacache_find+0x5f/0x280 [ 41.228169] compat_SyS_recvmsg+0x2a/0x40 [ 41.232287] ? compat_SyS_sendmmsg+0x40/0x40 [ 41.236668] do_fast_syscall_32+0x3ee/0xfa1 [ 41.240966] ? do_int80_syscall_32+0x9d0/0x9d0 [ 41.245528] ? trace_hardirqs_on_thunk+0x1a/0x1c [ 41.250256] ? syscall_return_slowpath+0x550/0x550 [ 41.255157] ? syscall_return_slowpath+0x2ac/0x550 [ 41.260058] ? prepare_exit_to_usermode+0x350/0x350 [ 41.265048] ? retint_user+0x18/0x18 [ 41.268747] ? trace_hardirqs_off_thunk+0x1a/0x1c [ 41.273569] entry_SYSENTER_compat+0x54/0x63 [ 41.277949] RIP: 0023:0xf7f45c79 [ 41.281284] RSP: 002b:00000000fffebddc EFLAGS: 00000217 ORIG_RAX: 0000000000000174 [ 41.288963] RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 0000000020006fc8 [ 41.296301] RDX: 0000000000002000 RSI: 0000000000000004 RDI: 0000000000000004 [ 41.303551] RBP: 0000000020000fe6 R08: 0000000000000000 R09: 0000000000000000 [ 41.310791] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000 [ 41.318034] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 [ 41.325811] Dumping ftrace buffer: [ 41.329401] (ftrace buffer empty) [ 41.333086] Kernel Offset: disabled [ 41.336689] Rebooting in 86400 seconds..