lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <87o6lwa0fl.ffs@tglx>
Date: Tue, 10 Feb 2026 20:00:30 +0100
From: Thomas Gleixner <tglx@...nel.org>
To: syzbot <syzbot+237b5b985b78c1da9600@...kaller.appspotmail.com>,
 andrealmeid@...lia.com, dave@...olabs.net, dvhart@...radead.org,
 linux-kernel@...r.kernel.org, mingo@...hat.com, peterz@...radead.org,
 syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [kernel?] WARNING in __mmdrop (2)

On Mon, Feb 09 2026 at 20:08, syzbot wrote:
> HEAD commit:    05f7e89ab973 Linux 6.19
> git tree:       upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=1153465a580000
> kernel config:  https://syzkaller.appspot.com/x/.config?x=df890e720d1bb80
> dashboard link: https://syzkaller.appspot.com/bug?extid=237b5b985b78c1da9600
> compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
> syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=105297fa580000
> C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=120c12e6580000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/ea9f39c5175d/disk-05f7e89a.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/734edeebfa32/vmlinux-05f7e89a.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/a2cb36d849f0/bzImage-05f7e89a.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+237b5b985b78c1da9600@...kaller.appspotmail.com

Futexes are just a red herring here. The bug is a double mmput()
introduced by:

  b5cbacd7f86f ("procfs: avoid fetching build ID while holding VMA lock")

See
        https://lore.kernel.org/all/87qzqsa1br.ffs@tglx/

Thanks,

        tglx

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ