Received: by 2002:a05:6358:c692:b0:131:369:b2a3 with SMTP id fe18csp4842557rwb; Mon, 31 Jul 2023 13:11:47 -0700 (PDT) X-Google-Smtp-Source: APBJJlHTxfmBFhMHSZDRtlNAj2lUuGqF+Vq9GYUPRl0FDvVza4OUw7OQxEo3nxB+szFBL1bQRAL9 X-Received: by 2002:a05:6a20:8e09:b0:137:26b9:f403 with SMTP id y9-20020a056a208e0900b0013726b9f403mr12194105pzj.49.1690834307462; Mon, 31 Jul 2023 13:11:47 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1690834307; cv=none; d=google.com; s=arc-20160816; b=vXCPOWnmDCah+yzuuFIjT0ZY9Sz765tn2adzOlUm2ffQhswYTaZf2jbrZ4E4IfeVi2 Z00dOYr+27Rww8/XSQJuh400ewjrOYU7Arln06QNx9BZP971zavtNfBIxjJZ7lSwPKKu iAeUe0AmLzDW9fK4CP/eEDGLLswruYe0eM9nzr7k0hbWYkrInTSoO6OlCgsaNOOboREI cJxUaCDj4oF853D5rrV2rdNa63+CueG4hOIhXhul+sbrWaYt9GokaY/h/cgvNrgQrwTX 89H8Yf9ZCk2UVRe24hfPpS/v7UIRDVgLZyh0PtGTzSH8NHaFzkXemPbzfGdycsxuothB Xvqg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:to:from:subject:message-id:date:mime-version; bh=cm3XSjN6H7r/ng7NKyK3iKnYCBzx9MyxBE9I8DFsmyY=; fh=Dbvr5b8+tHGtqqZHWVUAlJem427/B7iCozFNPHNvl4w=; b=WJlA+ix72nUblqKJA1OgsopGDGnfgvGD2RmieSWs7/yGGlxGzBRQtLkZFwD5LCjx5o 7Cj4vpQzjAlLheibpo+mBBJ3SN2JzoyTemUCPoWeEJ9KSw9VhMwgbDB3RqDfd12WKg6t C4d89vUgPlpZBWMKmAFOjcSGeoHN2x5kfCdxNC960799ueUimZkwFC4dj0B93sVBcmmO VkU2lpBol1iyWqV3K4l7Xu+dHgDLqEVARdBw7VfIxJ21jtkRz9gmjDav691hfyRwr2wi kXiLn4TMFP9W2r/qDV7eTB7PESEBsAo8HI835rvre5eToIKTbXNM32ijfzx0VUAeEcCr pA8A== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id v71-20020a63894a000000b005574480a875si7680561pgd.898.2023.07.31.13.11.35; Mon, 31 Jul 2023 13:11:47 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230048AbjGaTjy (ORCPT + 99 others); Mon, 31 Jul 2023 15:39:54 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60852 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229767AbjGaTjx (ORCPT ); Mon, 31 Jul 2023 15:39:53 -0400 Received: from mail-oa1-f80.google.com (mail-oa1-f80.google.com [209.85.160.80]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 3160D199E for ; Mon, 31 Jul 2023 12:39:52 -0700 (PDT) Received: by mail-oa1-f80.google.com with SMTP id 586e51a60fabf-1befca4fdfaso1276795fac.2 for ; Mon, 31 Jul 2023 12:39:52 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1690832391; x=1691437191; h=to:from:subject:message-id:date:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=cm3XSjN6H7r/ng7NKyK3iKnYCBzx9MyxBE9I8DFsmyY=; b=Yyg2RQ9/QyFI5JiWxUIuQz1lvz2Ie8hYL1/2ZCHYtW/vDATfZrWya+2fhUzYKqfmR+ B2OhtdBaWAelhTVX4MT/mrcBpuR830rbEUSW5FtEJUXyYdhdRb16t+HETNIkwAlTyms5 W6T48kr5VsqikJULkqLBYt8iwH9vid6ZUnNr1w1VKgND7Qg6H38IXCdZEr9onvb7jRem W0q2OqOnW/1ZLN6dJ2ckxwwXMck9FVaV+2G7WNXx4kdIK9VuJS3A4w4GxBu1aZ2/AJEq oqZc990AnqIhBUs7DYribqNU4dPHKYH69UyJzYU+Rd5b9KRAvnLLkOBp+hV1cO5PaD6L llpQ== X-Gm-Message-State: ABy/qLYrQPTdGDt+m1pXii3+E7pxEey2sHehMy/KBTNyI4lOkXEjT43D fRmE7L/lCME0htkj2WUhKn/dtJMurCQeuY4U+5UDbVMU5fLo MIME-Version: 1.0 X-Received: by 2002:a05:6870:d884:b0:1b7:6077:bef1 with SMTP id dv4-20020a056870d88400b001b76077bef1mr13454830oab.0.1690832391361; Mon, 31 Jul 2023 12:39:51 -0700 (PDT) Date: Mon, 31 Jul 2023 12:39:51 -0700 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <0000000000000fdc630601cd9825@google.com> Subject: [syzbot] [udf?] UBSAN: array-index-out-of-bounds in udf_process_sequence From: syzbot To: jack@suse.com, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-1.7 required=5.0 tests=BAYES_00,FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hello, syzbot found the following issue on: HEAD commit: 0a8db05b571a Merge tag 'platform-drivers-x86-v6.5-3' of gi.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=145f2726a80000 kernel config: https://syzkaller.appspot.com/x/.config?x=5d10d93e1ae1f229 dashboard link: https://syzkaller.appspot.com/bug?extid=abb7222a58e4ebc930ad compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40 Unfortunately, I don't have any reproducer for this issue yet. Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/58a518a693f4/disk-0a8db05b.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/22cc85e51a4d/vmlinux-0a8db05b.xz kernel image: https://storage.googleapis.com/syzbot-assets/daeac90304b9/bzImage-0a8db05b.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+abb7222a58e4ebc930ad@syzkaller.appspotmail.com ================================================================================ UBSAN: array-index-out-of-bounds in fs/udf/super.c:1365:9 index 4 is out of range for type '__le32[4]' (aka 'unsigned int[4]') CPU: 0 PID: 10089 Comm: syz-executor.0 Not tainted 6.5.0-rc3-syzkaller-00044-g0a8db05b571a #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2023 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106 ubsan_epilogue lib/ubsan.c:217 [inline] __ubsan_handle_out_of_bounds+0x11c/0x150 lib/ubsan.c:348 udf_load_sparable_map fs/udf/super.c:1365 [inline] udf_load_logicalvol fs/udf/super.c:1457 [inline] udf_process_sequence+0x300d/0x4e70 fs/udf/super.c:1773 udf_load_sequence fs/udf/super.c:1820 [inline] udf_check_anchor_block+0x2a6/0x550 fs/udf/super.c:1855 udf_scan_anchors fs/udf/super.c:1909 [inline] udf_load_vrs+0xa71/0x1100 fs/udf/super.c:1969 udf_fill_super+0x95d/0x23a0 fs/udf/super.c:2147 mount_bdev+0x276/0x3b0 fs/super.c:1391 legacy_get_tree+0xef/0x190 fs/fs_context.c:611 vfs_get_tree+0x8c/0x270 fs/super.c:1519 do_new_mount+0x28f/0xae0 fs/namespace.c:3335 do_mount fs/namespace.c:3675 [inline] __do_sys_mount fs/namespace.c:3884 [inline] __se_sys_mount+0x2d9/0x3c0 fs/namespace.c:3861 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd RIP: 0033:0x7f838747e22a Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb a6 e8 de 09 00 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f838819eee8 EFLAGS: 00000202 ORIG_RAX: 00000000000000a5 RAX: ffffffffffffffda RBX: 00007f838819ef80 RCX: 00007f838747e22a RDX: 0000000020000100 RSI: 0000000020000200 RDI: 00007f838819ef40 RBP: 0000000020000100 R08: 00007f838819ef80 R09: 0000000000214856 R10: 0000000000214856 R11: 0000000000000202 R12: 0000000020000200 R13: 00007f838819ef40 R14: 0000000000000c1d R15: 0000000020000240 ================================================================================ --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the bug is already fixed, let syzbot know by replying with: #syz fix: exact-commit-title If you want to change bug's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the bug is a duplicate of another bug, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup