Hello, syzkaller hit the following crash on 0a07b238e5f488b459b6113a62e06b6aab017f71 git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/master compiler: gcc (GCC) 7.1.1 20170620 .config is attached Raw console output is attached. syzkaller reproducer is attached. See https://goo.gl/kgGztJ for information about syzkaller reproducers ------------[ cut here ]------------ WARNING: CPU: 1 PID: 6842 at arch/x86/kvm/x86.c:8152 __x86_set_memory_region+0x541/0x6c0 arch/x86/kvm/x86.c:8152 Kernel panic - not syncing: panic_on_warn set ... CPU: 1 PID: 6842 Comm: syz-executor7 Not tainted 4.13.0-rc2+ #10 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:16 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:52 panic+0x1e4/0x417 kernel/panic.c:180 __warn+0x1c4/0x1d9 kernel/panic.c:541 report_bug+0x211/0x2d0 lib/bug.c:183 fixup_bug+0x40/0x90 arch/x86/kernel/traps.c:190 do_trap_no_signal arch/x86/kernel/traps.c:224 [inline] do_trap+0x260/0x390 arch/x86/kernel/traps.c:273 do_error_trap+0x120/0x390 arch/x86/kernel/traps.c:310 do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:323 invalid_op+0x1e/0x30 arch/x86/entry/entry_64.S:846 RIP: 0010:__x86_set_memory_region+0x541/0x6c0 arch/x86/kvm/x86.c:8152 RSP: 0018:ffff8801d39277f0 EFLAGS: 00010297 RAX: ffff8801c26ee100 RBX: ffff8801d39278c0 RCX: 1ffff100384ddd2e RDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000286 RBP: ffff8801d39278e8 R08: 0000000000000001 R09: 1ffff1003a724eb9 R10: ffff8801d3927590 R11: 0000000000000001 R12: ffff8801d3927880 R13: 1ffff1003a724f04 R14: 00000000000101ff R15: 0000000000000000 x86_set_memory_region+0x3e/0x60 arch/x86/kvm/x86.c:8164 kvm_arch_destroy_vm+0x7c4/0x990 arch/x86/kvm/x86.c:8180 kvm_destroy_vm arch/x86/kvm/../../../virt/kvm/kvm_main.c:770 [inline] kvm_put_kvm+0x5d7/0xa90 arch/x86/kvm/../../../virt/kvm/kvm_main.c:792 kvm_vcpu_release+0x7b/0xa0 arch/x86/kvm/../../../virt/kvm/kvm_main.c:2412 __fput+0x327/0x7e0 fs/file_table.c:210 ____fput+0x15/0x20 fs/file_table.c:246 task_work_run+0x18a/0x260 kernel/task_work.c:116 tracehook_notify_resume include/linux/tracehook.h:191 [inline] exit_to_usermode_loop+0x26d/0x2d0 arch/x86/entry/common.c:161 prepare_exit_to_usermode arch/x86/entry/common.c:194 [inline] syscall_return_slowpath+0x3a7/0x450 arch/x86/entry/common.c:263 entry_SYSCALL_64_fastpath+0xbc/0xbe RIP: 0033:0x4512c9 RSP: 002b:00007f7577010c08 EFLAGS: 00000216 ORIG_RAX: 0000000000000021 RAX: 000000000000000a RBX: 0000000000718000 RCX: 00000000004512c9 RDX: 0000000000000000 RSI: 000000000000000a RDI: 0000000000000007 RBP: 00000000000004b0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000216 R12: 00000000004b6699 R13: 00000000ffffffff R14: 0000000000000007 R15: 000000000000000a Dumping ftrace buffer: (ftrace buffer empty) Kernel Offset: disabled Rebooting in 86400 seconds.. --- This bug is generated by a dumb bot. It may contain errors. See https://goo.gl/tpsmEJ for details. Direct all questions to syzkaller@googlegroups.com. Please credit me with: Reported-by: syzbot syzbot will keep track of this bug report. Once a fix for this bug is committed, please reply to this email with: #syz fix: exact-commit-title To mark this as a duplicate of another syzbot report, please reply with: #syz dup: exact-subject-of-another-report If it's a one-off invalid bug report, please reply with: #syz invalid Note: if the crash happens again, it will cause creation of a new bug report. Note: all commands must start from beginning of the line.