WARNING in sta_info_insert_rcu

From: Hao Sun
Date: Tue Sep 14 2021 - 22:16:49 EST


Hello,

When using Healer to fuzz the latest Linux kernel, the following crash
was triggered.

HEAD commit: 6880fa6c5660 Linux 5.15-rc1
git tree: upstream
console output:
https://drive.google.com/file/d/1JAoHNesGqAqeOvuCFuKXI-F9pBTcwDNo/view?usp=sharing
kernel config: https://drive.google.com/file/d/1rUzyMbe5vcs6khA3tL9EHTLJvsUdWcgB/view?usp=sharing

Sorry, I don't have a reproducer for this crash, hope the symbolized
report can help.
If you fix this issue, please add the following tag to the commit:
Reported-by: Hao Sun <sunhao.th@xxxxxxxxx>

------------[ cut here ]------------
WARNING: CPU: 3 PID: 7312 at net/mac80211/sta_info.c:546
sta_info_insert_check net/mac80211/sta_info.c:545 [inline]
WARNING: CPU: 3 PID: 7312 at net/mac80211/sta_info.c:546
sta_info_insert_rcu+0xa3/0x1130 net/mac80211/sta_info.c:723
Modules linked in:
CPU: 3 PID: 7312 Comm: kworker/u8:4 Not tainted 5.15.0-rc1 #16
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
rel-1.12.0-59-gc9ba5276e321-prebuilt.qemu.org 04/01/2014
Workqueue: phy4 ieee80211_iface_work
RIP: 0010:sta_info_insert_check net/mac80211/sta_info.c:545 [inline]
RIP: 0010:sta_info_insert_rcu+0xa3/0x1130 net/mac80211/sta_info.c:723
Code: 16 00 00 8b 90 a8 16 00 00 44 31 f9 44 31 e2 0f b7 c1 09 c2 74
0f e8 dc c0 43 fd 41 f6 c4 01 0f 84 b2 00 00 00 e8 cd c0 43 fd <0f> 0b
41 bc ea ff ff ff e8 c0 c0 43 fd 48 89 de 4c 89 f7 e8 35 fe
RSP: 0018:ffffc90005b8bc98 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff88810ce08000 RCX: 0000000000000000
RDX: ffff88810cdda240 RSI: ffffffff83f3d133 RDI: 0000000000000000
RBP: ffffc90005b8bd18 R08: ffffffff83f3d0d6 R09: 0000000000000000
R10: ffffc90005b8bc98 R11: 0000000000000003 R12: 00000000000ecf85
R13: ffff88810ce49708 R14: ffff88810ce48d60 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88813dd00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000001b52c48 CR3: 000000010c909000 CR4: 0000000000750ee0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
PKRU: 55555554
Call Trace:
ieee80211_ibss_finish_sta+0xbc/0x170 net/mac80211/ibss.c:585
ieee80211_ibss_work+0x13f/0x7d0 net/mac80211/ibss.c:1693
ieee80211_iface_work+0x43a/0x5f0 net/mac80211/iface.c:1515
process_one_work+0x359/0x850 kernel/workqueue.c:2297
worker_thread+0x41/0x4d0 kernel/workqueue.c:2444
kthread+0x178/0x1b0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295