2022-03-21 01:19:33

by Pavel Skripkin

[permalink] [raw]
Subject: Re: [syzbot] divide error in dbNextAG

On 3/19/22 21:07, syzbot wrote:
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 09688c0166e7 Linux 5.17-rc8
> git tree: upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=163e5015700000
> kernel config: https://syzkaller.appspot.com/x/.config?x=70f75a89c7a0e6bc
> dashboard link: https://syzkaller.appspot.com/bug?extid=46f5c25af73eb8330eb6
> compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=132c1d61700000
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: [email protected]
>
> divide error: 0000 [#1] PREEMPT SMP KASAN
> CPU: 1 PID: 3622 Comm: syz-executor.0 Not tainted 5.17.0-rc8-syzkaller #0
> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
> RIP: 0010:dbNextAG+0xfc/0x5f0 fs/jfs/jfs_dmap.c:602

Looks like malicious fs image with bmp->db_numag == 0.

#syz test:
git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master




With regards,
Pavel Skripkin


Attachments:
ph (752.00 B)

2022-03-21 22:36:43

by syzbot

[permalink] [raw]
Subject: Re: [syzbot] divide error in dbNextAG

Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-and-tested-by: [email protected]

Tested on:

commit: 34e047aa Merge tag 'arm64-fixes' of git://git.kernel.o..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=70f75a89c7a0e6bc
dashboard link: https://syzkaller.appspot.com/bug?extid=46f5c25af73eb8330eb6
compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2
patch: https://syzkaller.appspot.com/x/patch.diff?x=14c2cd33700000

Note: testing is done by a robot and is best-effort only.