Re: BUG: unable to handle kernel NULL pointer dereference in __syscall_return_slowpath

From: Eric Biggers
Date: Mon Jun 29 2020 - 17:07:23 EST


On Mon, Jun 29, 2020 at 09:31:16AM -0700, syzbot wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit: 4e99b321 Merge tag 'nfs-for-5.8-2' of git://git.linux-nfs...
> git tree: upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=116abdd3100000
> kernel config: https://syzkaller.appspot.com/x/.config?x=bf3aec367b9ab569
> dashboard link: https://syzkaller.appspot.com/bug?extid=95910cea1a7ad8850a0f
> compiler: gcc (GCC) 10.1.0-syz 20200507
> userspace arch: i386
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17020755100000

Looks like ioctl$FBIOPUT_VSCREENINFO on /dev/fb0 striking again. There are like
20-30 open syzbot reports for this.

See https://lkml.kernel.org/lkml/000000000000ff323f05a053100c@xxxxxxxxxx/T/#u
for some previous discussion.

#syz dup: general protection fault in syscall_return_slowpath