From nobody Mon Sep 28 18:36:01 2026 Received: from mail-pg1-f175.google.com (mail-pg1-f175.google.com [209.85.215.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6120C47F783 for ; Wed, 19 Aug 2026 15:54:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787154862; cv=none; b=m5kn530ImG4NbOHQtAHad64bbvXOiL4YpCWMD+HG4vNBJnC6j4NjTA1AkOIG2e35nUbbhpj9cP8MiD6XwUI8IMtLYL55rtN0lxMbI90VmSSq/8xpQaFIOMiWdVF6kCoyrJQ+pP+PowmpTrjJO9Ztwww13czJrbLqtdAONn0Gy24= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787154862; c=relaxed/simple; bh=12a99CZooZeh/6Zr18YkATcXoZorOGreI5XGbpZ6hCQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=BfO8XGY7rQT8YotuyBSsdBGhs+SxT0i7QX7tvexACXnrYZjO5cW/3gHuNM4iouQuh2jigl3XK7qigX+MD50+cHPT5aDSqMrKHcxCwjhieMAbqUsCF+51el50d01Bzhtq3t0TuOKGvMy9xI90XCgO7ji8RVSXRW43gPNCl+G8Dek= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr; spf=pass smtp.mailfrom=snu.ac.kr; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b=WLhbtjEm; arc=none smtp.client-ip=209.85.215.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b="WLhbtjEm" Received: by mail-pg1-f175.google.com with SMTP id 41be03b00d2f7-cbee846deecso1216063a12.1 for ; Wed, 19 Aug 2026 08:54:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snu.ac.kr; s=google; t=1787154857; x=1787759657; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=KUQjv6WFeC4LVm2DLMuaaoqz/KN+oBl4j8XX94n8WlQ=; b=WLhbtjEmH5E+ddO5Szs40pFqxQd1YnYSWL5FilCO7aiCWIGLfxsHKcPqrFTS0lJyWa roEJjgfm8mNVKgOwGgWESCoMvsScfAs0PnvrJu6bMqNhbYe8w1EI4aQMsYCZ9+EU4/M5 ZG4JiNGnywYncc5nGc3DvUOXb2OP24tv/w+8E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787154857; x=1787759657; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KUQjv6WFeC4LVm2DLMuaaoqz/KN+oBl4j8XX94n8WlQ=; b=mGKG2uUEomW8J57hudyHRhsJ3Acs7voeOIEqhIznfnDyBJB0zjGox4h2JEsI83Fvev nrQNwjytYNchiUYqDQbO0k+vi+ic2AIyMYywoDuE5iKAA0QdTV5wFE5iuQooDYidYHFS buZrYwEGO3TZYb5Uv8rEge/mrV2YGW3qKUyFO0TIdQEioHaGxdJqEdxm4ttVL/rz3abq rANrOSu6bRKn3gLMlHj/fiYtFyhC1qICSCTl8mh/ycWM8pGVcpztSe4rsVdl23+EMSsf XA+4eFa2LYH1yldPMvmQPW9drz2RFZnpqaycgZuqu1U8+DcBn/LtjkkjRZ6/39f2Mi7j GESQ== X-Forwarded-Encrypted: i=1; AHgh+Rp5/Ty4e49nyxq6t5eaEfZHfoywWOIwAemykqS/6bGyUeadfMqQ+QcDBBOK2lcSclMm48M61YSIohi4VuM=@vger.kernel.org X-Gm-Message-State: AOJu0Yy0Crb++zfiKaC/9hyoSymnJAgIqXQ0cEN9zu3HjPzw9PMYSd5l pdsapyUw023SLsHQldT78s50GAUOEFEfO8W+EMkNc3L4iB0OFio4rgzmFq8p1IjJS8s= X-Gm-Gg: AR+sD10+Nq567nUxxEqTHQ6EOq33xlsWB5IZ9H2u728lv/AGlciuyDpSZd21VFpPWU5 kDxpihx9rHTYg+nH5vs+1SmuKdg5OeKsslEdrfDyA2PuyX9aZiHzHX4YVJzPC3UpNKbWM6+ABWP 90KaJP6Kt8WE5EeWinMjtna/3DB3n0ZhUVDQueSJMJNzvIEIKtbFU/RlHC2Gx2CZiVcRzu3lwIx vUXaHu4pPRg+06wzNPr/1UZPhPoWfYRnRQmgQvh2h3+MDjCSBCmDLnmOLhJpo0lj7hIvwaVDgPg VbD8YDscOrZHwim8o1CluAgHMuHxzMB+lIZwA1QAHHsvuvEGF0YS9ELatQUn79HOMrPHhYndg9h bibuKbuaIO3r0uVM2PUJHPf+fmSQZUlYRLz75UwGYkd+vTHtAHMQhbccc9m8ZWn6/a59v228lBl Y+eST7alPg2p0sS2AfKOzUlLmK09rCE9ebwzk2C+5wSTikVueWnd4lhrew6fRvIk41wzxX0HbFA td14mmDvrWZrKRSfBFa58diQaVdcefUcWJ7XDYxWYPb8DzX5Y/gJH7E+cGVbHUgRcHvDzCqKyAn 3pgq2l4g/L1Q4q/ooLll03VESV0H5Me7CNNl+vQTQw6VJ3UkSADRiA== X-Received: by 2002:a05:6a20:9d90:b0:3c3:b57b:6285 with SMTP id adf61e73a8af0-3cd011b1b55mr11597196637.13.1787154856560; Wed, 19 Aug 2026 08:54:16 -0700 (PDT) Received: from leesin ([147.46.121.37]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cc1593060e8sm679663a12.32.2026.08.19.08.54.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 08:54:15 -0700 (PDT) From: Jaeyoung Chung To: davem@davemloft.net, edumazet@google.com, herbert@gondor.apana.org.au, kuba@kernel.org, netdev@vger.kernel.org, pabeni@redhat.com, steffen.klassert@secunet.com Cc: horms@kernel.org, linux-kernel@vger.kernel.org, eulgyukim@snu.ac.kr Subject: [BUG] general protection fault in espintcp_sendmsg Date: Thu, 20 Aug 2026 00:53:47 +0900 Message-ID: <20260819155349.3555804-1-jjy600901@snu.ac.kr> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Hello, We found a "general protection fault in espintcp_sendmsg" on Linux v7.2. The issue was found by our own race fuzzer. We have not analyzed the root cause, so we do not have a proposed fix to offer. To reproduce the race reliably, we applied the delay patch below to the kernel and ran the C reproducer as root inside an x86_64 QEMU guest. The crash log we observed, the delay patch and the reproducer are all included below. The following kernel config options are required to reproduce the issue: CONFIG_XFRM=3Dy CONFIG_XFRM_USER=3Dy CONFIG_INET_ESP=3Dy CONFIG_INET_ESPINTCP=3Dy CONFIG_KASAN=3Dy We hope this report is useful. Please let us know if any further information would help. Reported-by: Eulgyu Kim Reported-by: Jaeyoung Chung Kernel delay patch: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D diff --git a/net/xfrm/espintcp.c b/net/xfrm/espintcp.c index 374e1b964438..333760567aa8 100644 --- a/net/xfrm/espintcp.c +++ b/net/xfrm/espintcp.c @@ -8,6 +8,8 @@ #include #include #include +#include +#include =20 static void handle_nonesp(struct espintcp_ctx *ctx, struct sk_buff *skb, struct sock *sk) @@ -478,6 +480,9 @@ static int espintcp_init_sk(struct sock *sk) sk->sk_data_ready =3D espintcp_data_ready; sk->sk_write_space =3D espintcp_write_space; sk->sk_destruct =3D espintcp_destruct; + if (strncmp(current->comm, "syzrepro0", 9) =3D=3D 0) { + mdelay(100); + } rcu_assign_pointer(icsk->icsk_ulp_data, ctx); INIT_WORK(&ctx->work, espintcp_tx_work); =20 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D C reproducer: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D #define _GNU_SOURCE #include #include #include #include #include #include #include #include #define SYSCHK(x) ({ long __r =3D (long)(x); if (__r =3D=3D -1L) { perror(#= x); exit(1); } __r; }) #define TCP_ULP 31 static volatile int g_fd =3D -1; static volatile int g_stop; static void *writer_fn(void *idx) { unsigned char payload =3D 0xf7; char name[16]; int fd; snprintf(name, sizeof(name), "syzrepro%ld", (long)idx); prctl(PR_SET_NAME, name, 0, 0, 0); while (!g_stop) { fd =3D g_fd; if (fd < 0) { usleep(200); continue; } write(fd, &payload, 1); } return NULL; } int main(void) { pthread_t th[3]; long i; int it, fd; signal(SIGPIPE, SIG_IGN); prctl(PR_SET_NAME, "syzrepro0", 0, 0, 0); for (i =3D 0; i < 3; i++) pthread_create(&th[i], NULL, writer_fn, (void *)(i + 1)); for (it =3D 0; it < 200; it++) { fd =3D SYSCHK(socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)); g_fd =3D fd; usleep(3000); setsockopt(fd, IPPROTO_TCP, TCP_ULP, "espintcp", sizeof("espintcp")); g_fd =3D -1; usleep(1000); close(fd); } g_stop =3D 1; for (i =3D 0; i < 3; i++) pthread_join(th[i], NULL); return 0; } =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Crash log: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Oops: general protection fault, probably for non-canonical address 0xdffffc= 0000000080: 0000 [#1] SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000400-0x0000000000000407] CPU: 1 UID: 0 PID: 415 Comm: syzrepro1 Not tainted 7.2.0-dirty #4 PREEMPT=20 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1= .1 04/01/2014 RIP: 0010:espintcp_sendmsg+0x1de/0x5d0 net/xfrm/espintcp.c:331 Code: 00 48 8b 44 24 10 8b 30 83 e6 40 4c 89 ff e8 99 f6 ff ff 85 c0 0f 88 = ce 00 00 00 4d 8d bc 24 04 04 00 00 4d 89 fc 49 c1 ec 03 <41> 0f b6 04 1c 8= 4 c0 0f 85 2b 03 00 00 c7 44 24 0c 97 ff ff ff 41 RSP: 0018:ffff888103e679c0 EFLAGS: 00010203 RAX: 0000000000000000 RBX: dffffc0000000000 RCX: 1ffff110207ccf14 RDX: 0000000000000001 RSI: 0000000000000000 RDI: dffffc0000000000 RBP: ffff888103e67b38 R08: 0000000000000003 R09: 0000000000000004 R10: dffffc0000000000 R11: ffffed10207cceec R12: 0000000000000080 R13: ffff888103e67ab0 R14: 1ffff110207ccf44 R15: 0000000000000404 FS: 00007be5667d06c0(0000) GS:ffff88818c759000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007be5668cc340 CR3: 000000010caea000 CR4: 00000000000006f0 Call Trace: sock_sendmsg_nosec net/socket.c:775 [inline] __sock_sendmsg+0x157/0x1a0 net/socket.c:790 sock_write_iter+0x1d3/0x2c0 net/socket.c:1241 new_sync_write fs/read_write.c:595 [inline] vfs_write+0x4c8/0xa50 fs/read_write.c:687 ksys_write fs/read_write.c:739 [inline] __do_sys_write fs/read_write.c:750 [inline] __se_sys_write fs/read_write.c:747 [inline] __x64_sys_write+0x153/0x220 fs/read_write.c:747 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf7/0x370 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7be5668cc38f Code: 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 a9 d4 f8 ff 48 8b 54 24 18 = 48 8b 74 24 10 41 89 c0 8b 7c 24 08 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff f= f 77 31 44 89 c7 48 89 44 24 08 e8 fc d4 f8 ff 48 RSP: 002b:00007be5667cfe70 EFLAGS: 00000293 ORIG_RAX: 0000000000000001 RAX: ffffffffffffffda RBX: 00007be5667cfeaf RCX: 00007be5668cc38f RDX: 0000000000000001 RSI: 00007be5667cfeaf RDI: 0000000000000003 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000064 R10: 0000000000000000 R11: 0000000000000293 R12: ffffffffffffff80 R13: 0000000000000000 R14: 00007ffe83852980 R15: 00007be565fd0000 Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:espintcp_sendmsg+0x1de/0x5d0 net/xfrm/espintcp.c:331 Code: 00 48 8b 44 24 10 8b 30 83 e6 40 4c 89 ff e8 99 f6 ff ff 85 c0 0f 88 = ce 00 00 00 4d 8d bc 24 04 04 00 00 4d 89 fc 49 c1 ec 03 <41> 0f b6 04 1c 8= 4 c0 0f 85 2b 03 00 00 c7 44 24 0c 97 ff ff ff 41 RSP: 0018:ffff888103e679c0 EFLAGS: 00010203 RAX: 0000000000000000 RBX: dffffc0000000000 RCX: 1ffff110207ccf14 RDX: 0000000000000001 RSI: 0000000000000000 RDI: dffffc0000000000 RBP: ffff888103e67b38 R08: 0000000000000003 R09: 0000000000000004 R10: dffffc0000000000 R11: ffffed10207cceec R12: 0000000000000080 R13: ffff888103e67ab0 R14: 1ffff110207ccf44 R15: 0000000000000404 FS: 00007be5667d06c0(0000) GS:ffff88818c759000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007823930e8b58 CR3: 000000010caea000 CR4: 00000000000006f0 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D