From nobody Tue Sep 29 18:01:26 2026 Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2FDDC3F7884 for ; Thu, 20 Aug 2026 09:40:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787218861; cv=none; b=ocVZcgvbvzW7HMPKfyjOsEwzVqviWvmLoQHdt0EMPZQzM+srqEJUd2bFX6rck+4bzNFqoAvdi054ScZbhJBWHFtfdnCYvYNGz2ldjk5QX+piPLBo+Nf1XdUVZPqxnnUunU/HE59Dlz42F/XUOnJRfOwcHjki82cdoOyw/e6CQIw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787218861; c=relaxed/simple; bh=DLauF+O/kw+FxGx/W6Wx8WXNhgYzduCjAEzP4nQrUMY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Mbc6gjO64TuB915Zvy6+rK692KKj8nLs/yKwTpqV+Yy4Fkk/VwHrpYMldAgDjrLZAl3v3GrUA4GqLmoHLdiN/+us0QBzI0j67RzZwhGw3zST8i9KkY+bT4CpLCoPXrxVCyhAgGB2nxSw2E1NL9D5QwZkEzLWHnmob1IqIsSzebY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr; spf=pass smtp.mailfrom=snu.ac.kr; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b=WQ/EqPqP; arc=none smtp.client-ip=209.85.214.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b="WQ/EqPqP" Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2caed617615so21179055ad.3 for ; Thu, 20 Aug 2026 02:40:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snu.ac.kr; s=google; t=1787218850; x=1787823650; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=tNNCQS/B6nJf+N13IvpvO+yZREnnbBFEaoQTROVnF0g=; b=WQ/EqPqPlGywioW1c4XaChWAG/jdb1zyCCVT/o7CnJQBIogyLJRmoa0QM1cr5zIpK1 FfmP1yS1WwvQ2XIEmZ9i0jQLn7sYlNmgleL9J6Wi9le8mbxKJcsX1mNls7b9ZeaCFa2P IKhUh2cVl1N2etGgmB9jSKCUHOYJHe86Hj8J4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787218850; x=1787823650; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tNNCQS/B6nJf+N13IvpvO+yZREnnbBFEaoQTROVnF0g=; b=SRjm6/qaPnVJP9+ilcX1CnXtvMo6OZiNdlxmsVkXu4vJmsSlfaMYf7s2szMZNoeQ// JAapn7tJYdIWf/Fx3KWmkyOITWu0cHv53/XuiuPgbMlFNRTxIQgr0N2QJbnXhdi7jZms ReXOdbwSLO3R1meJ7SQFtVafbF/eThRCwvPqai81DRabBQTDQUkp0FcRxEZyldMLsQAO nIHAp/r7MZ8I24384btGgToFlhQqNkv6HqMMVorO8wlzvwIM/1dOZjmFFCUSUmHnCQDS 97zIq9iuyuMYu41JFC4S/5OeNWmvOrSeFFr+YT7b7HT/ZJqNjwrKf2PeGYJ+kqGyy1UW XT1A== X-Forwarded-Encrypted: i=1; AHgh+RqvLN8zfmmlaySkZbGC8uQMP07JcL+jLGn9ROXnnY5P00ixcoHxsJIGoI47xgbVycK1Kt56bDD2TS0S4d8=@vger.kernel.org X-Gm-Message-State: AFuF++kUU2E4yTBvHev4j4EoJy+LbxqkVRMImngNNNcCkYlWM2EUPijb OGtO0iG1wMt55xh81HmdnD2eTzRptf8Se/zNHd+XhkNErxRcGhHar6i4L5dEKEVyNdM= X-Gm-Gg: AR+sD11X5mof/QqFIO3mb9TueRNNMWT28sQc8PuF/M8uSkHo9Z5JDZpEMTsYQJ/D2ox UEhAe5iRf2n7Lg7dbub/p1tT62lGTmGhN9gA/wzeismWqcpT6TI5kxA7bFouDLpJgrtPYUzc19N W/9ij9pta2eraqJghO8dtrnJp6bRC4iK6MrfdNsJxxPzm3clgMqZhF4SZit0+T3VTNoYh0w1PVd ByBRcN/zHbkrP6ZUBaAkpKf76Txq9yrj3FVASWYMLibsmpNSLxD+fO4jSyOBnwspfc4Kws0Xrd9 IWouqPfdEL+h7oiV7I+iDY62PXW7CVdVGHekuOq4fG+EF9wfE+VswOaUpGeV0PZKh7OUP1NLaE+ BrmBDehMU3OEavdK/BLWOAjUSxtmQUHUAMsjCWZUEq1WVbB9qQrV8q6sVByY/tHp3L1MCsEH8UU kNBpplRIsYoK3zzsDAfZcN+Xx98BK0ST4GkoiWBzyN3clrNLHjHruRSy0pZ1pgo5L3QCAZSM3WF awk60AWsSgBVwR2jhJZeYlmoylxHx833KhCpb9U2D75bvFTyMN7ms2XslzNDARTzDog74dCxys1 vJ9H3HClvol7DMuGaleG6hv5dGjBDTDlLSyyQIqJz2OsXYfzGC5mjg== X-Received: by 2002:a17:903:3b84:b0:2d5:2f49:b3de with SMTP id d9443c01a7336-2d5fd3e78f6mr227703825ad.0.1787218849595; Thu, 20 Aug 2026 02:40:49 -0700 (PDT) Received: from leesin ([147.46.121.37]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d62d5ae494sm4365595ad.34.2026.08.20.02.40.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 02:40:48 -0700 (PDT) From: Jaeyoung Chung To: bp@alien8.de, dave.hansen@linux.intel.com, linux-kernel@vger.kernel.org, mingo@redhat.com, tglx@kernel.org, x86@kernel.org Cc: hpa@zytor.com, pawan.kumar.gupta@linux.intel.com, seanjc@google.com, sohil.mehta@intel.com, eulgyukim@snu.ac.kr, jjy600901@snu.ac.kr Subject: [BUG] KASAN: stack-out-of-bounds Write in cpu_init_exception_handling Date: Thu, 20 Aug 2026 18:40:33 +0900 Message-ID: <20260820094035.1201193-1-jjy600901@snu.ac.kr> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Hello, We found a "KASAN: stack-out-of-bounds Write in cpu_init_exception_handling= " on Linux v7.2. The issue was found by our own race fuzzer. We have not analyze= d the root cause, so we do not have a proposed fix to offer. To reproduce the race reliably, we applied the delay patch below to the kernel and ran the C reproducer as root inside an x86_64 QEMU guest. The crash log we observed, the delay patch and the reproducer are all included below. We used the syzbot kernel config, disabled the two options below, and built it with clang-20: https://syzkaller.appspot.com/text?tag=3DKernelConfig&x=3D1941312e3e971= b07 ./scripts/config --file .config --disable MODVERSIONS --disable GENDWAR= FKSYMS make LLVM=3D1 olddefconfig We could not reproduce this on a different config, so the report may depend= on the exact stack layout the syzbot config produces. We hope this report is useful. Please let us know if any further information would help. Reported-by: Eulgyu Kim Reported-by: Jaeyoung Chung Kernel delay patch: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D diff --git a/kernel/cpu.c b/kernel/cpu.c index b3c8553d7bd6..9eaea7b14027 100644 --- a/kernel/cpu.c +++ b/kernel/cpu.c @@ -17,6 +17,7 @@ #include #include #include +#include #include #include #include @@ -833,6 +834,9 @@ static int cpuhp_bringup_ap(unsigned int cpu) struct cpuhp_cpu_state *st =3D per_cpu_ptr(&cpuhp_state, cpu); int ret; =20 + if (!strncmp(current->comm, "syzrepro0", 9)) { + mdelay(80); + } /* * Some architectures have to walk the irq descriptors to * setup the vector space for the cpu which comes online. @@ -1385,6 +1389,9 @@ static int cpuhp_down_callbacks(unsigned int cpu, str= uct cpuhp_cpu_state *st, =20 ret =3D cpuhp_invoke_callback_range(false, cpu, st, target); if (ret) { + if (!strncmp(current->comm, "syzrepro", 8)) { + mdelay(20); + } pr_debug("CPU DOWN failed (%d) CPU %u state %s (%d)\n", ret, cpu, cpuhp_get_step(st->state)->name, st->state); =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D C reproducer: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D #define _GNU_SOURCE #include #include #include #include #include #include #include #define SYSCHK(x) ({ long __r =3D (long)(x); if (__r =3D=3D -1L) { perror(#= x); exit(1); } __r; }) #define ONLINE "/sys/devices/system/cpu/cpu1/online" #define STATE "/sys/devices/system/cpu/cpu1/hotplug/state" #define FAIL "/sys/devices/system/cpu/cpu1/hotplug/fail" #define STATES "/sys/devices/system/cpu/hotplug/states" static int bringup; static char failval[16]; static volatile int window, stop; static int rd(const char *path, char *buf, size_t len) { int fd =3D SYSCHK(open(path, O_RDONLY)); int n =3D SYSCHK(read(fd, buf, len - 1)); close(fd); buf[n] =3D 0; return n; } static void wr(const char *path, const char *val) { int fd =3D SYSCHK(open(path, O_WRONLY)); write(fd, val, strlen(val)); close(fd); } static int state_id(const char *name) { char buf[8192], *line, *save, *c; int id =3D -1; rd(STATES, buf, sizeof(buf)); for (line =3D strtok_r(buf, "\n", &save); line; line =3D strtok_r(NULL, "\n", &save)) { c =3D strchr(line, ':'); if (c && !strcmp(c + 2, name)) id =3D atoi(line); } return id; } static void *arm_thread(void *arg) { char buf[64]; prctl(PR_SET_NAME, "syzrepro1", 0, 0, 0); while (!stop) { if (!window) { usleep(300); continue; } rd(STATE, buf, sizeof(buf)); if (atoi(buf) =3D=3D bringup) wr(FAIL, failval); usleep(200); } return NULL; } int main(void) { pthread_t t1; int i, fail_state; prctl(PR_SET_NAME, "syzrepro0", 0, 0, 0); bringup =3D state_id("cpu:bringup"); fail_state =3D state_id("timers:prepare"); if (bringup < 0 || fail_state < 0 || fail_state >=3D bringup) { fprintf(stderr, "state lookup failed: bringup=3D%d fail=3D%d\n", bringup, fail_state); return 1; } snprintf(failval, sizeof(failval), "%d", fail_state); wr(FAIL, "-1"); pthread_create(&t1, NULL, arm_thread, NULL); for (i =3D 0; i < 200; i++) { wr(ONLINE, "0"); window =3D 1; wr(ONLINE, "1"); window =3D 0; usleep(2000); } stop =3D 1; pthread_join(t1, NULL); return 0; } =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Crash log: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D BUG: KASAN: stack-out-of-bounds in __set_tss_desc arch/x86/include/asm/desc= .h:183 [inline] BUG: KASAN: stack-out-of-bounds in cpu_init_exception_handling+0x301/0x950 = arch/x86/kernel/cpu/common.c:2418 Write of size 16 at addr ffffc90000177ea0 by task swapper/1/0 CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Not tainted 7.2.0-dirty #10 PREEMPT(fu= ll)=20 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1= .1 04/01/2014 Call Trace: dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 print_address_description+0x55/0x1e0 mm/kasan/report.c:378 print_report+0x64/0x70 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 check_region_inline mm/kasan/generic.c:-1 [inline] kasan_check_range+0x2b0/0x2c0 mm/kasan/generic.c:200 __asan_memset+0x22/0x50 mm/kasan/shadow.c:84 __set_tss_desc arch/x86/include/asm/desc.h:183 [inline] cpu_init_exception_handling+0x301/0x950 arch/x86/kernel/cpu/common.c:2418 start_secondary+0x17/0x110 arch/x86/kernel/smpboot.c:248 common_startup_64+0x13e/0x157 The buggy address belongs to stack of task swapper/1/0 and is located at offset 128 in frame: cpu_init_exception_handling+0x0/0x950 arch/x86/include/asm/msr.h:-1 This frame has 5 objects: [32, 42) 'gdt_descr.i8.i' [64, 74) 'gdt_descr.i.i' [96, 106) 'gdt.i' [128, 144) 'tss.i' [160, 168) 'd.i' The buggy address belongs to a 8-page vmalloc region starting at 0xffffc900= 00170000 allocated at copy_process+0x7d9/0x3dc0 kernel/fork.c:2115 The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100697 flags: 0x57ff00000000000(node=3D1|zone=3D2|lastcpupid=3D0x7ff) raw: 057ff00000000000 ffffea000401a5c8 ffffea000401a5c8 0000000000000000 raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as allocated page last allocated via order 0, migratetype Unmovable, gfp_mask 0x29c2(GFP= _NOWAIT|__GFP_HIGHMEM|__GFP_IO|__GFP_FS|__GFP_ZERO), pid 1, tgid 1 (swapper= /0), ts 1601422137, free_ts 0 set_page_owner include/linux/page_owner.h:32 [inline] post_alloc_hook+0x205/0x260 mm/page_alloc.c:1859 prep_new_page mm/page_alloc.c:1867 [inline] get_page_from_freelist+0x2366/0x23f0 mm/page_alloc.c:3946 __alloc_frozen_pages_noprof+0x181/0x370 mm/page_alloc.c:5304 __alloc_pages_noprof+0x10/0x100 mm/page_alloc.c:5338 __alloc_pages_node_noprof include/linux/gfp.h:291 [inline] alloc_pages_node_noprof include/linux/gfp.h:318 [inline] vm_area_alloc_pages mm/vmalloc.c:3691 [inline] __vmalloc_area_node mm/vmalloc.c:3914 [inline] __vmalloc_node_range_noprof+0x7c7/0x1750 mm/vmalloc.c:4104 __vmalloc_node_noprof+0xc2/0x110 mm/vmalloc.c:4165 alloc_thread_stack_node kernel/fork.c:359 [inline] dup_task_struct+0x2aa/0x910 kernel/fork.c:929 copy_process+0x7d9/0x3dc0 kernel/fork.c:2115 fork_idle+0xb3/0x240 kernel/fork.c:2658 idle_init kernel/smpboot.c:53 [inline] idle_threads_init+0xd0/0x150 kernel/smpboot.c:72 smp_init+0x16/0x110 kernel/smp.c:1029 kernel_init_freeable+0x289/0x3e0 init/main.c:1650 kernel_init+0x1d/0x1d0 init/main.c:1548 ret_from_fork+0x509/0xb70 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 page_owner free stack trace missing Memory state around the buggy address: ffffc90000177d80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffffc90000177e00: 00 00 00 00 f1 f1 f1 f1 00 02 f2 f2 00 02 f2 f2 >ffffc90000177e80: 00 02 f2 f2 00 f3 f2 f2 00 f3 f3 f3 00 00 00 00 ^ ffffc90000177f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffffc90000177f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D