From nobody Mon Sep 28 16:23:43 2026 Received: from mail-pg1-f176.google.com (mail-pg1-f176.google.com [209.85.215.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D10F148A8B2 for ; Wed, 19 Aug 2026 17:46:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787161592; cv=none; b=oxBYrFnblCU3inTzlNL7JzGFMzXGyD1XiKOOytre1Dkc0OI9NbJO8pIAo5wO/txJ+9qYSkHXRBhlGhAf+bnQhHrIS9KF+dowGC8inDUlgsKJ8NI9diW+Tfq86ogrU3WDyHYq6pBTqlUXI9NoQ4CO7ZvuJ8LJ+NsHiKvz8YDJ9so= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787161592; c=relaxed/simple; bh=/SzrfRSKqdR7kVJbzOnPwFB9zkErbyXs3iZo5hIXQdA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=FDo7fIJK1iJ82ehfwORh4N1r/Fmf1NPTA7djRVdgdt0UaAqCA5fyM/qd2keGUU7hriqbawbh816TTYj6TfW16tBXLQ3BBkjAslsTlFg6R4wZnExm7NdgZj7R4DIHabkmFaOlZ+Eo/RflefZRHm9hYUliBH7tcgQBs5WvL/LOVII= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr; spf=pass smtp.mailfrom=snu.ac.kr; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b=HGukmjaU; arc=none smtp.client-ip=209.85.215.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b="HGukmjaU" Received: by mail-pg1-f176.google.com with SMTP id 41be03b00d2f7-cc11a905ba5so783151a12.2 for ; Wed, 19 Aug 2026 10:46:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snu.ac.kr; s=google; t=1787161584; x=1787766384; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=zX3reAKnLViu7SpeDvyK4H7lOCJxP9Pze8YZOO/drio=; b=HGukmjaUMIKQVaH5nO6V/mWiOiMdnpwsOyYi6sD8ZIUv+hU0JcjuTVqMNnenhVzBI4 M9TFEZv1P7r+z2Uu7eaKZAArx5dbXkQkMZYnkElOW9ROY2A+vUUhoYBU2izL6tNDg4vL G4HQ/0rBWsarHlhfk82JVgLa3AmBqea6eMnAM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787161584; x=1787766384; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zX3reAKnLViu7SpeDvyK4H7lOCJxP9Pze8YZOO/drio=; b=HZSRAs/wJV+GisIh/64/ncp1xbX4Tl1Q/bSuIV4sPmEdFtAv2vxZITBdijMJYVV5wx My0HIB0g+tBv4lwDUyeE5dGQd9gQM4f+rvebMPVjRrbSivI2TaCf9v9Qjzcf09vtnoad r2/RwaNj/SucxyMWbPmOcL3ZdKqgigoKmHns9KYr/eN0HRE0QJSByKKeX+wSV31Uxjmf bii1NIbgyszHy9tn1f21+LsvIB6c4ggNQuPgYxYZ7I/wE4E3NbkgGwiXJDL+KC6II/gQ U6P9KBtU9EK8dSYm0EMHau4xCsH+/WGZ32nbgzxnYxwMj6SNFNsZwCq0sOp4Gj9AXeoz a21g== X-Forwarded-Encrypted: i=1; AHgh+RpDjh3w/RmLCWlDetHrmh4dDwJQ2rdyp2w8woAJg9hTXaW8Vm1j3J1GLekTuEh1FfxRcjekbq7k+7BMpk8=@vger.kernel.org X-Gm-Message-State: AFuF++mDj4Mr0tVotnhzfXmDJw/ZZDBrgIDwoOgi6msYGlwOzBDROHZN Dhy3dRP58FcuEQ6+eLOo8H14GM+p1BeG3CvmYmGGwAm8840c4MK9yiJKVaRq2+9ldsM= X-Gm-Gg: AR+sD12MXjO9nC/sjfJ1yJvW1pHbAUq8KiudSSOZ04r3dITB0ZQ0Cj8EiWtep7/lbt9 fbkMVJLcSYGmLKse2nuPxLl/lkotLA5qECez8cSZRPAS8ESAgYHTEwLdHaPeOIeeQ7Zfal/DoMu STND0HvM5RSkRGCQZnITVhBdPSCnrMWexcPoJjJAkJ1TTjxO0s8NdEowh4DyNsuf1JZsyJPWuzZ KlEP9rG9QI6G6YzVwCja3Jv1V+X1QYjgQRx/TQVuLejk/nf6mPGnSGQIkiSrU3BDoq42U47JrNM oe8OCNcYDZ89Lg61PQD0FLlOYfNWmotMX7ciMiqQz2xflNL8L3gzCsi3fp/qw71QvGA2GSloX06 8I0cVeIJ1+0LopzOsvFOordHodbCxMru8zS+6ajaW+/QFuD4zjlI6ykRg6q9kXSLYiDjEuEYHAD hQlPVAbhm2lrCcekCYzvjpBaLC0UVGSnHx+pP4doutZ2O+nybu3GUL1FRjaR5ndyxGaJEUdshTT 6OdEMUlR12nN6QW5uAycCZSMPRjmcn7LOJ+J2eH0UzxR4eEoo1Xu1+vMBVb/r7H1p/Hb6gSQnR0 5lj/6dQ4JyD71p+5/MxMXG8cPKJ5DRZqMa2L4ilElCCXINn1l8vecA== X-Received: by 2002:a17:90b:3145:b0:395:5f43:4ec4 with SMTP id 98e67ed59e1d1-39580ab3df7mr10933608a91.0.1787161584305; Wed, 19 Aug 2026 10:46:24 -0700 (PDT) Received: from leesin ([147.46.121.37]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3957fb87174sm3406970a91.12.2026.08.19.10.46.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 10:46:23 -0700 (PDT) From: Jaeyoung Chung To: abbotti@mev.co.uk, hsweeten@visionengravers.com, linux-kernel@vger.kernel.org Cc: gregkh@linuxfoundation.org, n.zhandarovich@fintech.ru, eulgyukim@snu.ac.kr, jjy600901@snu.ac.kr Subject: [BUG] KASAN: slab-use-after-free Read in comedi_poll Date: Thu, 20 Aug 2026 02:46:00 +0900 Message-ID: <20260819174614.3857878-1-jjy600901@snu.ac.kr> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Hello, We found a "KASAN: slab-use-after-free Read in comedi_poll" on Linux v7.2. The issue was found by our own race fuzzer. We have not analyzed the root c= ause, so we do not have a proposed fix to offer. To reproduce the race reliably, we applied the delay patch below to the kernel and ran the C reproducer as root inside an x86_64 QEMU guest. The crash log we observed, the delay patch and the reproducer are all included below. The reproducer opens /dev/comedi3, which exists if the kernel is booted with comedi.comedi_num_legacy_minors=3D4. The following kernel config options are required to reproduce the issue: CONFIG_ISA_BUS=3Dy CONFIG_COMEDI=3Dy CONFIG_COMEDI_MISC_DRIVERS=3Dy CONFIG_COMEDI_ISA_DRIVERS=3Dy CONFIG_COMEDI_PCL818=3Dy We hope this report is useful. Please let us know if any further information would help. Reported-by: Eulgyu Kim Reported-by: Jaeyoung Chung Kernel delay patch: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D diff --git a/drivers/comedi/comedi_fops.c b/drivers/comedi/comedi_fops.c index c09bbe04be6c..824e323e076f 100644 --- a/drivers/comedi/comedi_fops.c +++ b/drivers/comedi/comedi_fops.c @@ -294,6 +294,9 @@ static void comedi_file_reset(struct file *file) } cfp->last_attached =3D dev->attached; cfp->last_detach_count =3D dev->detach_count; + if (strncmp(current->comm, "syzrepro1", 9) =3D=3D 0) { + mdelay(100); + } WRITE_ONCE(cfp->read_subdev, read_s); WRITE_ONCE(cfp->write_subdev, write_s); } @@ -2619,6 +2622,9 @@ static __poll_t comedi_poll(struct file *file, poll_t= able *wait) dev_dbg(dev->class_dev, "no driver attached\n"); goto done; } + if (strncmp(current->comm, "syzrepro0", 9) =3D=3D 0) { + mdelay(20); + } =20 s =3D comedi_file_read_subdevice(file); s_read =3D s; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D C reproducer: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D #define _GNU_SOURCE #include #include #include #include #include #include #include #include #include #include #define SYSCHK(x) ({ long __r =3D (long)(x); if (__r =3D=3D -1L) { perror(#= x); exit(1); } __r; }) struct comedi_devconfig { char board_name[20]; int options[32]; }; #define COMEDI_DEVCONFIG _IOW('d', 0, struct comedi_devconfig) static int fd; static volatile int ready; static void *poll_worker(void *name) { struct pollfd pfd =3D { .fd =3D fd, .events =3D POLLIN | POLLOUT }; prctl(PR_SET_NAME, name, 0, 0, 0); __atomic_store_n(&ready, 1, __ATOMIC_RELEASE); poll(&pfd, 1, 0); return NULL; } static void attach(void) { struct comedi_devconfig c; memset(&c, 0, sizeof(c)); memcpy(c.board_name, "pcl818", sizeof("pcl818")); c.options[0] =3D 0x300; c.options[1] =3D 2; c.options[2] =3D -3; c.options[3] =3D 0x4000; c.options[4] =3D 7; c.options[5] =3D 5; c.options[6] =3D 8; SYSCHK(ioctl(fd, COMEDI_DEVCONFIG, &c)); } int main(void) { struct pollfd pfd; pthread_t t0, t1; int i; prctl(PR_SET_NAME, "syzrepro2", 0, 0, 0); fd =3D SYSCHK(open("/dev/comedi3", O_RDWR | O_NONBLOCK)); SYSCHK(ioctl(fd, COMEDI_DEVCONFIG, NULL)); attach(); pfd.fd =3D fd; pfd.events =3D POLLIN | POLLOUT; SYSCHK(poll(&pfd, 1, 0)); for (i =3D 0; i < 50; i++) { SYSCHK(ioctl(fd, COMEDI_DEVCONFIG, NULL)); attach(); ready =3D 0; pthread_create(&t1, NULL, poll_worker, "syzrepro1"); while (!__atomic_load_n(&ready, __ATOMIC_ACQUIRE)) sched_yield(); usleep(5000); pthread_create(&t0, NULL, poll_worker, "syzrepro0"); pthread_join(t0, NULL); pthread_join(t1, NULL); } ioctl(fd, COMEDI_DEVCONFIG, NULL); close(fd); return 0; } =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Crash log: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D BUG: KASAN: slab-use-after-free in comedi_poll+0x2ae/0x7e0 drivers/comedi/c= omedi_fops.c:2631 Read of size 8 at addr ffff8881053ce828 by task syzrepro0/401 CPU: 2 UID: 0 PID: 401 Comm: syzrepro0 Not tainted 7.2.0-dirty #2 PREEMPT=20 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1= .1 04/01/2014 Call Trace: dump_stack_lvl+0x5e/0x80 lib/dump_stack.c:120 print_address_description+0x77/0x200 mm/kasan/report.c:378 print_report+0x64/0x70 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 comedi_poll+0x2ae/0x7e0 drivers/comedi/comedi_fops.c:2631 vfs_poll include/linux/poll.h:82 [inline] do_pollfd fs/select.c:877 [inline] do_poll fs/select.c:920 [inline] do_sys_poll+0x766/0xd40 fs/select.c:1015 __do_sys_poll fs/select.c:1072 [inline] __se_sys_poll fs/select.c:1060 [inline] __x64_sys_poll+0xfb/0x280 fs/select.c:1060 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf7/0x370 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7dec563ea26f Code: 54 24 1c 48 89 74 24 10 48 89 7c 24 08 e8 c9 95 f8 ff 8b 54 24 1c 48 = 8b 74 24 10 41 89 c0 48 8b 7c 24 08 b8 07 00 00 00 0f 05 <48> 3d 00 f0 ff f= f 77 31 44 89 c7 89 44 24 08 e8 1d 96 f8 ff 8b 44 RSP: 002b:00007dec55ae8e90 EFLAGS: 00000293 ORIG_RAX: 0000000000000007 RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007dec563ea26f RDX: 0000000000000000 RSI: 0000000000000001 RDI: 00007dec55ae8ec0 RBP: 0000000000000000 R08: 0000000000000000 R09: 00007ffc77e709e7 R10: 0000000000000000 R11: 0000000000000293 R12: ffffffffffffff80 R13: 0000000000000000 R14: 00007ffc77e708f0 R15: 00007dec552e9000 Allocated by task 399: kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 poison_kmalloc_redzone mm/kasan/common.c:398 [inline] __kasan_kmalloc+0x72/0x90 mm/kasan/common.c:415 kasan_kmalloc include/linux/kasan.h:263 [inline] __do_kmalloc_node mm/slub.c:5334 [inline] __kmalloc_noprof+0x20f/0x4b0 mm/slub.c:5359 _kmalloc_noprof include/linux/slab.h:992 [inline] _kzalloc_noprof include/linux/slab.h:1309 [inline] comedi_alloc_subdevices+0x39/0x4f0 drivers/comedi/drivers.c:104 pcl818_attach+0x486/0x1560 drivers/comedi/drivers/pcl818.c:1052 comedi_device_attach+0x3b5/0x4d0 drivers/comedi/drivers.c:1101 do_devconfig_ioctl drivers/comedi/comedi_fops.c:933 [inline] comedi_unlocked_ioctl+0x45b/0x1410 drivers/comedi/comedi_fops.c:2305 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl+0xb6/0x100 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf7/0x370 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e Freed by task 399: kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:584 poison_slab_object mm/kasan/common.c:253 [inline] __kasan_slab_free+0x3a/0x60 mm/kasan/common.c:285 kasan_slab_free include/linux/kasan.h:235 [inline] slab_free_hook mm/slub.c:2677 [inline] slab_free mm/slub.c:6377 [inline] kfree+0x16c/0x3e0 mm/slub.c:6692 comedi_device_detach_cleanup drivers/comedi/drivers.c:175 [inline] comedi_device_detach_locked+0x278/0x4a0 drivers/comedi/drivers.c:208 do_devconfig_ioctl drivers/comedi/comedi_fops.c:909 [inline] comedi_unlocked_ioctl+0xa90/0x1410 drivers/comedi/comedi_fops.c:2305 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl+0xb6/0x100 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf7/0x370 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e The buggy address belongs to the object at ffff8881053ce800 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 40 bytes inside of freed 1024-byte region [ffff8881053ce800, ffff8881053cec00) The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1053c8 head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 flags: 0x200000000000040(head|node=3D0|zone=3D2) page_type: f5(slab) raw: 0200000000000040 ffff888100042dc0 dead000000000100 dead000000000122 raw: 0000000000000000 0000000800100010 00000000f5000000 0000000000000000 head: 0200000000000040 ffff888100042dc0 dead000000000100 dead000000000122 head: 0000000000000000 0000000800100010 00000000f5000000 0000000000000000 head: 0200000000000003 fffffffffffffe01 00000000ffffffff 00000000ffffffff head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff8881053ce700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff8881053ce780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc >ffff8881053ce800: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff8881053ce880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff8881053ce900: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D