Received: by 2002:a05:6a10:1287:0:0:0:0 with SMTP id d7csp283543pxv; Wed, 21 Jul 2021 23:12:40 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzWzvr1uyK1zyihGMr6UHNIp+LD5Fbh9aPf2N+QmlnHeHKHtWc+4RHdF0vvk07shtUzg+Z/ X-Received: by 2002:a05:6638:58e:: with SMTP id a14mr29419960jar.81.1626934360150; Wed, 21 Jul 2021 23:12:40 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1626934360; cv=none; d=google.com; s=arc-20160816; b=bxNBm3t99no/lmPpKOR2fKIrIPDigZiwn/ufYGaN2hIj1DPSPcv7pjrYoe2c0+SSbk sTt/nzRqLmbc3QIiHWwZL79IsE9mO2/nq1V681uNtZUrrq01TzhRD/+OocApvrq3t3ot weskVbSciuIZIvFQUGujEcEIFdMAgAM4732KIvmoqRrRDTJLHMayHCdvbTN1sKN4I0Zl pBL2HmAWHsORPxxSgHHcdYEeFYnIM7uEpQT/g+i+JFzaNyAM+s/H+b/nJd4E8OVR/7bO ztERblHZJx1cbmU5Y2ZDJEW2v2DaVatpHmF20i9sZIW+oTyn8HYydixnEs/2tkOC/rE1 PzDA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:to:from:subject:message-id:date:mime-version; bh=zd5EMJMxH832+tT0bxAQpl6QF9px5miSg1moPe7RgLE=; b=VNHI8xlvdk0Q1bR1sRfEWO5fstoJ1C7GyV9Is5I9qNBFkfmjdJvaxt/eVUi0gCr0hJ uKO6L2JSEj0+NVSTYwRoBGcrRCRpKHNwLDQEwxYwrWinYpi2fDkdE3jT0DLodq/wFUJU u2yyrpxIojuaxvbv+xCzNJ23FNqXdvqETS8sx/yGgRfOuJFLqzccUfRd1SPnYeoyNl0u 8thtABIMRdb7hHG3QmOQiSts2OhQsz9bUK6uw4eRnvA66hkRm7QMUIoqJTocDc8wc7ln ND07V9aqmKTHUYHseryDrorA3BjHNUPDRvDKnV3+z0n/bxuW6ojBGB7iLEv346NXLhN1 G0bA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id u26si31052381jam.87.2021.07.21.23.12.23; Wed, 21 Jul 2021 23:12:40 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230445AbhGVFbm (ORCPT + 99 others); Thu, 22 Jul 2021 01:31:42 -0400 Received: from mail-il1-f198.google.com ([209.85.166.198]:49794 "EHLO mail-il1-f198.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229931AbhGVFbm (ORCPT ); Thu, 22 Jul 2021 01:31:42 -0400 Received: by mail-il1-f198.google.com with SMTP id f13-20020a056e0204cdb02902087dbca2b6so2942827ils.16 for ; Wed, 21 Jul 2021 23:12:17 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:message-id:subject:from:to; bh=zd5EMJMxH832+tT0bxAQpl6QF9px5miSg1moPe7RgLE=; b=r45kVX7lWgdj8QpWsMl5hqjD0h7qaIZPAt7ovh6GwsbYbzb1SggRdYHza5lX+vSZjX cEfWxI9kEfGaBsdPZgiQqoU88qztxbOBerhH1HqEHl2Cvzl10VSOfpq8mogZEbfl8ITi 0sytvHU4uYJZpdgoK3hQ8rlOcqeripV338WIaqNbOjnVk2PTZO44533kGJjbR4Lv/QIZ PNKQPzciTKXtNs+CHltLrYJTdDxcOE2kUZBVq+ZVfGjzGpzDO3bKkCvjT4PGf7kKCOuR yZVpyjgCk8zvS5R+w26p7zYNtbYPjhkhumuJ50l1ilbYKG2a1a7SnPA0vp/Pk7x8O0yM 1xlw== X-Gm-Message-State: AOAM532S7oZtfuxyZ9T/cqPr3vPldxBwU07CZRyAEy7/95n1Eev7n0y9 sqwdUV1lUVMQBsF+Rb1oIz3mgtZyGZ6pzZLmh7+DbDxSry87 MIME-Version: 1.0 X-Received: by 2002:a92:1942:: with SMTP id e2mr27746119ilm.4.1626934337416; Wed, 21 Jul 2021 23:12:17 -0700 (PDT) Date: Wed, 21 Jul 2021 23:12:17 -0700 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <00000000000041351c05c7b02b15@google.com> Subject: [syzbot] memory leak in reg_copy_regd From: syzbot To: davem@davemloft.net, johannes@sipsolutions.net, kuba@kernel.org, linux-kernel@vger.kernel.org, linux-wireless@vger.kernel.org, netdev@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org Hello, syzbot found the following issue on: HEAD commit: d980cc0620ae Merge tag 'devicetree-fixes-for-5.14-1' of gi.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=142c634a300000 kernel config: https://syzkaller.appspot.com/x/.config?x=7280943fd0476e5a dashboard link: https://syzkaller.appspot.com/bug?extid=1638e7c770eef6b6c0d0 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=131de45a300000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=118cea5c300000 IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+1638e7c770eef6b6c0d0@syzkaller.appspotmail.com BUG: memory leak unreferenced object 0xffff888111969200 (size 512): comm "syz-executor817", pid 8828, jiffies 4294955311 (age 19.340s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 05 00 00 00 39 39 00 00 00 00 00 00 d0 a6 24 00 ....99........$. backtrace: [] kmalloc include/linux/slab.h:596 [inline] [] kzalloc include/linux/slab.h:721 [inline] [] reg_copy_regd+0x30/0x120 net/wireless/reg.c:444 [] wiphy_apply_custom_regulatory+0x101/0x1a0 net/wireless/reg.c:2582 [] mac80211_hwsim_new_radio+0x897/0x1300 drivers/net/wireless/mac80211_hwsim.c:3344 [] hwsim_new_radio_nl+0x425/0x5f0 drivers/net/wireless/mac80211_hwsim.c:3924 [] genl_family_rcv_msg_doit+0x113/0x180 net/netlink/genetlink.c:739 [] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline] [] genl_rcv_msg+0x174/0x2c0 net/netlink/genetlink.c:800 [] netlink_rcv_skb+0x87/0x1d0 net/netlink/af_netlink.c:2504 [] genl_rcv+0x24/0x40 net/netlink/genetlink.c:811 [] netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline] [] netlink_unicast+0x392/0x4c0 net/netlink/af_netlink.c:1340 [] netlink_sendmsg+0x36b/0x6b0 net/netlink/af_netlink.c:1929 [] sock_sendmsg_nosec net/socket.c:703 [inline] [] sock_sendmsg+0x56/0x80 net/socket.c:723 [] ____sys_sendmsg+0x36c/0x390 net/socket.c:2392 [] ___sys_sendmsg+0x8b/0xd0 net/socket.c:2446 [] __sys_sendmsg+0x88/0x100 net/socket.c:2475 [] do_syscall_x64 arch/x86/entry/common.c:50 [inline] [] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 [] entry_SYSCALL_64_after_hwframe+0x44/0xae --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. syzbot can test patches for this issue, for details see: https://goo.gl/tpsmEJ#testing-patches