Re: [syzbot] BUG: unable to handle kernel NULL pointer dereference in io_do_iopoll

From: Jens Axboe
Date: Tue May 17 2022 - 14:34:08 EST


On 5/17/22 12:13 PM, syzbot wrote:
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 42226c989789 Linux 5.18-rc7
> git tree: upstream
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=125b807ef00000
> kernel config: https://syzkaller.appspot.com/x/.config?x=902c5209311d387c
> dashboard link: https://syzkaller.appspot.com/bug?extid=1a0a53300ce782f8b3ad
> compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=149eb59ef00000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17cc57c6f00000
>
> The issue was bisected to:
>
> commit 3f1d52abf098c85b177b8c6f5b310e8347d1bc42
> Author: Jens Axboe <axboe@xxxxxxxxx>
> Date: Tue Mar 29 16:43:56 2022 +0000
>
> io_uring: defer msg-ring file validity check until command issue

#syz test git://git.kernel.dk/linux-block io_uring-5.18

--
Jens Axboe