Hello, syzkaller hit the following crash on 5a3517e009e979f21977d362212b7729c5165d92 git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/master compiler: gcc (GCC) 7.1.1 20170620 .config is attached Raw console output is attached. ============================= WARNING: suspicious RCU usage 4.14.0-rc7-next-20171103+ #10 Not tainted ----------------------------- ./include/net/inet_sock.h:136 suspicious rcu_dereference_check() usage! other info that might help us debug this: rcu_scheduler_active = 2, debug_locks = 1 1 lock held by syz-executor0/836: #0: (sk_lock-AF_INET6){+.+.}, at: [] lock_sock include/net/sock.h:1461 [inline] #0: (sk_lock-AF_INET6){+.+.}, at: [] sock_setsockopt+0x163/0x1ae0 net/core/sock.c:715 stack backtrace: CPU: 0 PID: 836 Comm: syz-executor0 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 lockdep_rcu_suspicious+0x123/0x170 kernel/locking/lockdep.c:4675 ireq_opt_deref include/net/inet_sock.h:135 [inline] inet_csk_route_req+0x82a/0xca0 net/ipv4/inet_connection_sock.c:544 dccp_v4_send_response+0xa7/0x640 net/dccp/ipv4.c:485 dccp_v4_conn_request+0x9f4/0x11b0 net/dccp/ipv4.c:633 dccp_v6_conn_request+0xd30/0x1350 net/dccp/ipv6.c:317 dccp_rcv_state_process+0x574/0x1620 net/dccp/input.c:612 dccp_v4_do_rcv+0xeb/0x160 net/dccp/ipv4.c:682 dccp_v6_do_rcv+0x81a/0x9b0 net/dccp/ipv6.c:578 sk_backlog_rcv include/net/sock.h:909 [inline] __release_sock+0x124/0x360 net/core/sock.c:2264 release_sock+0xa4/0x2a0 net/core/sock.c:2776 sock_setsockopt+0x513/0x1ae0 net/core/sock.c:1066 SYSC_setsockopt net/socket.c:1847 [inline] SyS_setsockopt+0x2ff/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007f86cc482bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007f86cc4836cc RCX: 0000000000447c89 RDX: 000000000000001a RSI: 0000000000000001 RDI: 0000000000000013 RBP: 0000000000000086 R08: 0000000000000010 R09: 0000000000000000 R10: 0000000020c3a000 R11: 0000000000000246 R12: 00000000ffffffff R13: 00000000000006c0 R14: 00000000006e4760 R15: 00007f86cc483700 ============================= WARNING: suspicious RCU usage 4.14.0-rc7-next-20171103+ #10 Not tainted ----------------------------- ./include/net/inet_sock.h:136 suspicious rcu_dereference_check() usage! other info that might help us debug this: rcu_scheduler_active = 2, debug_locks = 1 1 lock held by syz-executor0/836: #0: (sk_lock-AF_INET6){+.+.}, at: [] lock_sock include/net/sock.h:1461 [inline] #0: (sk_lock-AF_INET6){+.+.}, at: [] sock_setsockopt+0x163/0x1ae0 net/core/sock.c:715 stack backtrace: CPU: 0 PID: 836 Comm: syz-executor0 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 lockdep_rcu_suspicious+0x123/0x170 kernel/locking/lockdep.c:4675 ireq_opt_deref include/net/inet_sock.h:135 [inline] dccp_v4_send_response+0x4b0/0x640 net/dccp/ipv4.c:496 dccp_v4_conn_request+0x9f4/0x11b0 net/dccp/ipv4.c:633 dccp_v6_conn_request+0xd30/0x1350 net/dccp/ipv6.c:317 dccp_rcv_state_process+0x574/0x1620 net/dccp/input.c:612 dccp_v4_do_rcv+0xeb/0x160 net/dccp/ipv4.c:682 dccp_v6_do_rcv+0x81a/0x9b0 net/dccp/ipv6.c:578 sk_backlog_rcv include/net/sock.h:909 [inline] __release_sock+0x124/0x360 net/core/sock.c:2264 release_sock+0xa4/0x2a0 net/core/sock.c:2776 sock_setsockopt+0x513/0x1ae0 net/core/sock.c:1066 SYSC_setsockopt net/socket.c:1847 [inline] SyS_setsockopt+0x2ff/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007f86cc482bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007f86cc4836cc RCX: 0000000000447c89 RDX: 000000000000001a RSI: 0000000000000001 RDI: 0000000000000013 RBP: 0000000000000086 R08: 0000000000000010 R09: 0000000000000000 R10: 0000000020c3a000 R11: 0000000000000246 R12: 00000000ffffffff R13: 00000000000006c0 R14: 00000000006e4760 R15: 00007f86cc483700 SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pig=864 comm=syz-executor4 device gre0 entered promiscuous mode audit: type=1326 audit(1509843339.583:8923): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=kernel pid=956 comm="syz-executor6" exe="/syz-executor6" sig=31 arch=c000003e syscall=202 compat=0 ip=0x447c89 code=0xffff0000 Started in network mode Own node address <64.15.3901>, network identity 4711 QAT: Invalid ioctl device eql entered promiscuous mode QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl SELinux: unrecognized netlink message: protocol=0 nlmsg_type=65535 sclass=netlink_route_socket pig=1220 comm=syz-executor4 syz-executor6: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor6 cpuset=/ mems_allowed=0-1 CPU: 2 PID: 1253 Comm: syz-executor6 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007f5954db7bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007f5954db86cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000014 RBP: 0000000000000086 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 0000000000748048 R13: 0000000000005568 R14: 00000000006e9608 R15: 00007f5954db8700 warn_alloc_show_mem: 1 callbacks suppressed Mem-Info: active_anon:120735 inactive_anon:90 isolated_anon:0 active_file:4006 inactive_file:9199 isolated_file:0 unevictable:0 dirty:79 writeback:0 unstable:0 slab_reclaimable:8560 slab_unreclaimable:44010 mapped:22880 shmem:379 pagetables:885 bounce:0 free:202148 free_pcp:1073 free_cma:0 Node 0 active_anon:188676kB inactive_anon:172kB active_file:8232kB inactive_file:28804kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:41344kB dirty:184kB writeback:0kB shmem:368kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 4096kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 1 active_anon:294264kB inactive_anon:188kB active_file:7792kB inactive_file:7992kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:50176kB dirty:132kB writeback:0kB shmem:1148kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 30720kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 0 DMA free:15908kB min:640kB low:800kB high:960kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15908kB mlocked:0kB kernel_stack:0kB pagetables:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB lowmem_reserve[]: 0 882 882 882 Node 0 DMA32 free:543392kB min:36464kB low:45580kB high:54696kB active_anon:188676kB inactive_anon:172kB active_file:8232kB inactive_file:28804kB unevictable:0kB writepending:184kB present:1032192kB managed:905808kB mlocked:0kB kernel_stack:2432kB pagetables:1504kB bounce:0kB free_pcp:1876kB local_pcp:684kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 1 DMA32 free:249292kB min:30476kB low:38092kB high:45708kB active_anon:294264kB inactive_anon:188kB active_file:7792kB inactive_file:7992kB unevictable:0kB writepending:132kB present:1048560kB managed:755124kB mlocked:0kB kernel_stack:3168kB pagetables:2036kB bounce:0kB free_pcp:2416kB local_pcp:656kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 0 DMA: 1*4kB (U) 0*8kB 0*16kB 1*32kB (U) 2*64kB (U) 1*128kB (U) 1*256kB (U) 0*512kB 1*1024kB (U) 1*2048kB (M) 3*4096kB (M) = 15908kB Node 0 DMA32: 280*4kB (UME) 278*8kB (UME) 200*16kB (UME) 282*32kB (UME) 521*64kB (UME) 144*128kB (UM) 36*256kB (UME) 16*512kB (UM) 10*1024kB (UM) 1*2048kB (U) 109*4096kB (UM) = 543504kB Node 1 DMA32: 281*4kB (UME) 409*8kB (UM) 269*16kB (UME) 420*32kB (UM) 429*64kB (UM) 70*128kB (ME) 9*256kB (UME) 20*512kB (UM) 18*1024kB (UME) 6*2048kB (UM) 36*4096kB (M) = 249276kB Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB 13583 total pagecache pages 0 pages in swap cache Swap cache stats: add 0, delete 0, find 0/0 Free swap = 0kB Total swap = 0kB 524186 pages RAM 0 pages HighMem/MovableOnly 104976 pages reserved syz-executor6: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor6 cpuset=/ mems_allowed=0-1 CPU: 2 PID: 1253 Comm: syz-executor6 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007f5954db7bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007f5954db86cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 000000000000001c RBP: 0000000000000086 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 00000000ffffffff R13: 0000000000006ea0 R14: 00000000006eaf40 R15: 00007f5954db8700 SELinux: unknown mount option SELinux: unknown mount option device gre0 entered promiscuous mode SELinux: unrecognized netlink message: protocol=0 nlmsg_type=274 sclass=netlink_route_socket pig=1422 comm=syz-executor4 SELinux: unrecognized netlink message: protocol=0 nlmsg_type=274 sclass=netlink_route_socket pig=1422 comm=syz-executor4 QAT: Invalid ioctl sd 0:0:0:0: tag#0 FAILED Result: hostbyte=DID_OK driverbyte=DRIVER_SENSE sd 0:0:0:0: tag#0 Sense Key : No Sense [current] sd 0:0:0:0: tag#0 Add. Sense: No additional sense information sd 0:0:0:0: tag#0 CDB: Request Sense 03 00 00 00 71 75 QAT: Invalid ioctl sd 0:0:0:0: tag#0 FAILED Result: hostbyte=DID_OK driverbyte=DRIVER_SENSE sd 0:0:0:0: tag#0 Sense Key : No Sense [current] sd 0:0:0:0: tag#0 Add. Sense: No additional sense information sd 0:0:0:0: tag#0 CDB: Request Sense 03 00 00 00 71 75 syz-executor4: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor4 cpuset=/ mems_allowed=0-1 CPU: 0 PID: 1601 Comm: syz-executor4 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007fdc14a73bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007fdc14a746cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000019 RBP: 0000000000000086 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 00000000ffffffff R13: 0000000000007ed8 R14: 00000000006ebf78 R15: 00007fdc14a74700 warn_alloc_show_mem: 1 callbacks suppressed Mem-Info: active_anon:117117 inactive_anon:90 isolated_anon:0 active_file:4007 inactive_file:9240 isolated_file:0 unevictable:0 dirty:136 writeback:0 unstable:0 slab_reclaimable:8483 slab_unreclaimable:40145 mapped:22881 shmem:379 pagetables:837 bounce:0 free:209890 free_pcp:884 free_cma:0 Node 0 active_anon:169944kB inactive_anon:172kB active_file:8232kB inactive_file:28844kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:41276kB dirty:352kB writeback:0kB shmem:368kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 14336kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 1 active_anon:298524kB inactive_anon:188kB active_file:7796kB inactive_file:8116kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:50248kB dirty:192kB writeback:0kB shmem:1148kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 65536kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 0 DMA free:15908kB min:640kB low:800kB high:960kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15908kB mlocked:0kB kernel_stack:0kB pagetables:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB lowmem_reserve[]: 0 882 882 882 Node 0 DMA32 free:551396kB min:36464kB low:45580kB high:54696kB active_anon:169944kB inactive_anon:172kB active_file:8232kB inactive_file:28844kB unevictable:0kB writepending:352kB present:1032192kB managed:905808kB mlocked:0kB kernel_stack:2368kB pagetables:1372kB bounce:0kB free_pcp:1892kB local_pcp:380kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 1 DMA32 free:265528kB min:30476kB low:38092kB high:45708kB active_anon:304784kB inactive_anon:188kB active_file:7796kB inactive_file:8116kB unevictable:0kB writepending:192kB present:1048560kB managed:755124kB mlocked:0kB kernel_stack:3360kB pagetables:1976kB bounce:0kB free_pcp:1704kB local_pcp:624kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 0 DMA: 1*4kB (U) 0*8kB 0*16kB 1*32kB (U) 2*64kB (U) 1*128kB (U) 1*256kB (U) 0*512kB 1*1024kB (U) 1*2048kB (M) 3*4096kB (M) = 15908kB Node 0 DMA32: 283*4kB (UME) 197*8kB (UME) 203*16kB (UME) 228*32kB (UME) 432*64kB (ME) 112*128kB (UM) 38*256kB (UME) 16*512kB (UM) 11*1024kB (UM) 2*2048kB (UM) 113*4096kB (UM) = 551364kB Node 1 DMA32: 194*4kB (UME) 725*8kB (UME) 502*16kB (UME) 485*32kB (UM) 522*64kB (UM) 144*128kB (UME) 15*256kB (UME) 23*512kB (UM) 18*1024kB (UME) 3*2048kB (U) 35*4096kB (M) = 265520kB Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB 13625 total pagecache pages 0 pages in swap cache Swap cache stats: add 0, delete 0, find 0/0 Free swap = 0kB Total swap = 0kB 524186 pages RAM 0 pages HighMem/MovableOnly 104976 pages reserved syz-executor4: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor4 cpuset=/ mems_allowed=0-1 CPU: 0 PID: 1612 Comm: syz-executor4 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007fdc14a10bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007fdc14a116cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000019 RBP: 0000000000000086 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 00000000ffffffff R13: 00000000000028b0 R14: 00000000006e6950 R15: 00007fdc14a11700 loop_reread_partitions: partition scan of loop0 (2�]�fI�����B�!S,��D�') failed (rc=-13) loop: Write error at byte offset 18446744073709547520, length 512. print_req_error: I/O error, dev loop0, sector 0 Buffer I/O error on dev loop0, logical block 0, lost async page write loop_reread_partitions: partition scan of loop0 () failed (rc=-13) loop_reread_partitions: partition scan of loop0 (2�]�fI�����B�!S,��D�') failed (rc=-13) loop_reread_partitions: partition scan of loop0 () failed (rc=-13) loop_reread_partitions: partition scan of loop0 (2�]�fI�����B�!S,��D�') failed (rc=-13) loop: Write error at byte offset 18446744073709547520, length 512. print_req_error: I/O error, dev loop0, sector 0 Buffer I/O error on dev loop0, logical block 0, lost async page write Buffer I/O error on dev loop0, logical block 0, lost async page write loop_reread_partitions: partition scan of loop0 () failed (rc=-13) device gre0 entered promiscuous mode QAT: Invalid ioctl nla_parse: 7 callbacks suppressed netlink: 8 bytes leftover after parsing attributes in process `syz-executor0'. QAT: Invalid ioctl netlink: 8 bytes leftover after parsing attributes in process `syz-executor0'. device lo entered promiscuous mode IPv6: ADDRCONF(NETDEV_UP): lo: link is not ready SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pig=1827 comm=syz-executor4 SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pig=1828 comm=syz-executor4 device lo left promiscuous mode device lo entered promiscuous mode IPv6: ADDRCONF(NETDEV_UP): lo: link is not ready device lo left promiscuous mode RDS: rds_bind could not find a transport for 172.20.1.170, load rds_tcp or rds_rdma? audit: type=1326 audit(1509843344.624:8924): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=kernel pid=1892 comm="syz-executor0" exe="/syz-executor0" sig=31 arch=c000003e syscall=202 compat=0 ip=0x447c89 code=0x0 audit: type=1326 audit(1509843344.736:8925): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=kernel pid=1892 comm="syz-executor0" exe="/syz-executor0" sig=31 arch=c000003e syscall=202 compat=0 ip=0x447c89 code=0x0 RDS: rds_bind could not find a transport for 172.20.1.170, load rds_tcp or rds_rdma? audit: type=1326 audit(1509843344.853:8926): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=kernel pid=1961 comm="syz-executor4" exe="/syz-executor4" sig=31 arch=c000003e syscall=202 compat=0 ip=0x447c89 code=0xffff0000 sctp: [Deprecated]: syz-executor6 (pid 1981) Use of struct sctp_assoc_value in delayed_ack socket option. Use struct sctp_sack_info instead audit: type=1326 audit(1509843344.991:8927): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=kernel pid=1961 comm="syz-executor4" exe="/syz-executor4" sig=31 arch=c000003e syscall=202 compat=0 ip=0x447c89 code=0xffff0000 QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl sg_write: data in/out 156/63 bytes for SCSI command 0x85-- guessing data in; program syz-executor3 not setting count and/or reply_len properly sg_write: data in/out 156/63 bytes for SCSI command 0x85-- guessing data in; program syz-executor3 not setting count and/or reply_len properly print_req_error: I/O error, dev loop0, sector 0 netlink: 11 bytes leftover after parsing attributes in process `syz-executor0'. print_req_error: I/O error, dev loop0, sector 0 netlink: 7 bytes leftover after parsing attributes in process `syz-executor4'. PF_BRIDGE: br_mdb_parse() with invalid attr device gre0 entered promiscuous mode netlink: 7 bytes leftover after parsing attributes in process `syz-executor4'. PF_BRIDGE: br_mdb_parse() with invalid attr syz-executor1: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor1 cpuset=/ mems_allowed=0-1 CPU: 1 PID: 2279 Comm: syz-executor1 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 do_syscall_64+0x26c/0x8d0 arch/x86/entry/common.c:287 entry_SYSCALL64_slow_path+0x25/0x25 RIP: 0033:0x447c89 RSP: 002b:00007f434c033bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007f434c0346cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 000000000000001a RBP: 0000000000748020 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 00000000ffffffff R13: 0000000000006ea0 R14: 00000000006eaf40 R15: 00007f434c034700 warn_alloc_show_mem: 1 callbacks suppressed Mem-Info: active_anon:125431 inactive_anon:116 isolated_anon:0 active_file:4012 inactive_file:9262 isolated_file:0 unevictable:0 dirty:131 writeback:0 unstable:0 slab_reclaimable:8535 slab_unreclaimable:40232 mapped:22907 shmem:414 pagetables:931 bounce:0 free:201027 free_pcp:1138 free_cma:0 Node 0 active_anon:168088kB inactive_anon:184kB active_file:8248kB inactive_file:28860kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:41348kB dirty:320kB writeback:0kB shmem:380kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 34816kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 1 active_anon:323364kB inactive_anon:280kB active_file:7800kB inactive_file:8188kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:50280kB dirty:204kB writeback:0kB shmem:1276kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 47104kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 0 DMA free:15908kB min:640kB low:800kB high:960kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15908kB mlocked:0kB kernel_stack:0kB pagetables:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB lowmem_reserve[]: 0 882 882 882 Node 0 DMA32 free:535484kB min:36464kB low:45580kB high:54696kB active_anon:190728kB inactive_anon:184kB active_file:8248kB inactive_file:28860kB unevictable:0kB writepending:320kB present:1032192kB managed:905808kB mlocked:0kB kernel_stack:2528kB pagetables:1624kB bounce:0kB free_pcp:1796kB local_pcp:76kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 1 DMA32 free:247084kB min:30476kB low:38092kB high:45708kB active_anon:317136kB inactive_anon:280kB active_file:7800kB inactive_file:8188kB unevictable:0kB writepending:204kB present:1048560kB managed:755124kB mlocked:0kB kernel_stack:3360kB pagetables:2248kB bounce:0kB free_pcp:2472kB local_pcp:732kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 0 DMA: 1*4kB (U) 0*8kB 0*16kB 1*32kB (U) 2*64kB (U) 1*128kB (U) 1*256kB (U) 0*512kB 1*1024kB (U) 1*2048kB (M) 3*4096kB (M) = 15908kB Node 0 DMA32: 285*4kB (UME) 306*8kB (UME) 224*16kB (UME) 252*32kB (UME) 449*64kB (UME) 106*128kB (UM) 28*256kB (UME) 17*512kB (UM) 11*1024kB (UM) 2*2048kB (UM) 109*4096kB (UM) = 535236kB Node 1 DMA32: 80*4kB (UME) 254*8kB (UME) 453*16kB (UME) 542*32kB (UME) 541*64kB (UME) 104*128kB (UM) 19*256kB (UME) 23*512kB (UM) 18*1024kB (UME) 4*2048kB (UM) 31*4096kB (M) = 245120kB Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB 13687 total pagecache pages 0 pages in swap cache Swap cache stats: add 0, delete 0, find 0/0 Free swap = 0kB Total swap = 0kB 524186 pages RAM 0 pages HighMem/MovableOnly 104976 pages reserved syz-executor1: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor1 cpuset=/ mems_allowed=0-1 CPU: 3 PID: 2292 Comm: syz-executor1 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 do_syscall_64+0x26c/0x8d0 arch/x86/entry/common.c:287 entry_SYSCALL64_slow_path+0x25/0x25 RIP: 0033:0x447c89 RSP: 002b:00007f434c012bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007f434c0136cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 000000000000001a RBP: 00000000007480d8 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 00000000ffffffff R13: 0000000000006ea0 R14: 00000000006eaf40 R15: 00007f434c013700 SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pig=2368 comm=syz-executor3 SELinux: unrecognized netlink message: protocol=0 nlmsg_type=3250 sclass=netlink_route_socket pig=2400 comm=syz-executor4 netlink: 13 bytes leftover after parsing attributes in process `syz-executor4'. netlink: 4 bytes leftover after parsing attributes in process `syz-executor5'. SELinux: unrecognized netlink message: protocol=0 nlmsg_type=3250 sclass=netlink_route_socket pig=2400 comm=syz-executor4 netlink: 13 bytes leftover after parsing attributes in process `syz-executor4'. netlink: 3 bytes leftover after parsing attributes in process `syz-executor7'. netlink: 2 bytes leftover after parsing attributes in process `syz-executor7'. QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl QAT: Invalid ioctl SELinux: unrecognized netlink message: protocol=0 nlmsg_type=19564 sclass=netlink_route_socket pig=2485 comm=syz-executor4 IPv6: ADDRCONF(NETDEV_CHANGE): lo: link becomes ready A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. device eql entered promiscuous mode IPv6: ADDRCONF(NETDEV_CHANGE): lo: link becomes ready A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. device eql entered promiscuous mode device eql entered promiscuous mode loop_reread_partitions: partition scan of loop5 (���t�?��`��J�z�P[�� �p��>�TK6C�=�"��L� ��l��!�V �#�F-��') failed (rc=-13) ����: renamed from syz3 SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pig=2863 comm=syz-executor5 loop_reread_partitions: partition scan of loop0 (-\�t�@��r�9h�xG�Q:[��i�l� �L�*��@����R�-�T�r-�x��) failed (rc=-13) SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pig=3060 comm=syz-executor4 device eql entered promiscuous mode device eql left promiscuous mode device eql entered promiscuous mode device eql left promiscuous mode device syz5 left promiscuous mode syz-executor4: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor4 cpuset=/ mems_allowed=0-1 CPU: 0 PID: 3353 Comm: syz-executor4 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007fdc14ad6bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007fdc14ad76cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000016 RBP: 0000000000000086 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 00000000ffffffff R13: 0000000000007ed8 R14: 00000000006ebf78 R15: 00007fdc14ad7700 warn_alloc_show_mem: 1 callbacks suppressed Mem-Info: active_anon:123384 inactive_anon:139 isolated_anon:0 active_file:4021 inactive_file:9265 isolated_file:0 unevictable:0 dirty:193 writeback:0 unstable:0 slab_reclaimable:8753 slab_unreclaimable:44702 mapped:22940 shmem:411 pagetables:931 bounce:0 free:198350 free_pcp:1135 free_cma:0 Node 0 active_anon:182480kB inactive_anon:272kB active_file:8284kB inactive_file:28852kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:41476kB dirty:464kB writeback:0kB shmem:364kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 0kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 1 active_anon:304756kB inactive_anon:284kB active_file:7800kB inactive_file:8208kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:50284kB dirty:308kB writeback:0kB shmem:1280kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 88064kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Node 0 DMA free:15908kB min:640kB low:800kB high:960kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15908kB mlocked:0kB kernel_stack:0kB pagetables:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB lowmem_reserve[]: 0 882 882 882 Node 0 DMA32 free:533660kB min:36464kB low:45580kB high:54696kB active_anon:176324kB inactive_anon:272kB active_file:8284kB inactive_file:28852kB unevictable:0kB writepending:464kB present:1032192kB managed:905808kB mlocked:0kB kernel_stack:2368kB pagetables:1436kB bounce:0kB free_pcp:2220kB local_pcp:432kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 1 DMA32 free:244272kB min:30476kB low:38092kB high:45708kB active_anon:317068kB inactive_anon:284kB active_file:7800kB inactive_file:8208kB unevictable:0kB writepending:308kB present:1048560kB managed:755124kB mlocked:0kB kernel_stack:3360kB pagetables:2288kB bounce:0kB free_pcp:2408kB local_pcp:708kB free_cma:0kB lowmem_reserve[]: 0 0 0 0 Node 0 DMA: 1*4kB (U) 0*8kB 0*16kB 1*32kB (U) 2*64kB (U) 1*128kB (U) 1*256kB (U) 0*512kB 1*1024kB (U) 1*2048kB (M) 3*4096kB (M) = 15908kB Node 0 DMA32: 211*4kB (UM) 313*8kB (UM) 412*16kB (UM) 256*32kB (UME) 463*64kB (UME) 96*128kB (UM) 14*256kB (UME) 16*512kB (UM) 13*1024kB (UM) 4*2048kB (UM) 108*4096kB (M) = 535700kB Node 1 DMA32: 134*4kB (UME) 211*8kB (UME) 476*16kB (UME) 543*32kB (UME) 544*64kB (UME) 82*128kB (UME) 18*256kB (UME) 24*512kB (UME) 17*1024kB (UM) 4*2048kB (U) 31*4096kB (M) = 242000kB Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB 13696 total pagecache pages 0 pages in swap cache Swap cache stats: add 0, delete 0, find 0/0 Free swap = 0kB Total swap = 0kB 524186 pages RAM 0 pages HighMem/MovableOnly 104976 pages reserved device gre0 entered promiscuous mode syz-executor4: vmalloc: allocation failure: 4833356120 bytes, mode:0x14080c0(GFP_KERNEL|__GFP_ZERO), nodemask=(null) syz-executor4 cpuset=/ mems_allowed=0-1 CPU: 0 PID: 3353 Comm: syz-executor4 Not tainted 4.14.0-rc7-next-20171103+ #10 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:17 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:53 warn_alloc+0x1c2/0x2f0 mm/page_alloc.c:3265 __vmalloc_node_range+0x4f0/0x650 mm/vmalloc.c:1775 __vmalloc_node mm/vmalloc.c:1804 [inline] __vmalloc_node_flags_caller+0x50/0x60 mm/vmalloc.c:1826 kvmalloc_node+0x82/0xd0 mm/util.c:406 kvmalloc include/linux/mm.h:539 [inline] kvmalloc_array include/linux/mm.h:555 [inline] xt_alloc_entry_offsets+0x21/0x30 net/netfilter/x_tables.c:774 translate_table+0x235/0x1610 net/ipv4/netfilter/ip_tables.c:686 do_replace net/ipv4/netfilter/ip_tables.c:1149 [inline] do_ipt_set_ctl+0x34b/0x5c0 net/ipv4/netfilter/ip_tables.c:1683 nf_sockopt net/netfilter/nf_sockopt.c:106 [inline] nf_setsockopt+0x67/0xc0 net/netfilter/nf_sockopt.c:115 ip_setsockopt+0xa1/0xb0 net/ipv4/ip_sockglue.c:1256 tcp_setsockopt+0x82/0xd0 net/ipv4/tcp.c:2877 sock_common_setsockopt+0x95/0xd0 net/core/sock.c:2965 SYSC_setsockopt net/socket.c:1851 [inline] SyS_setsockopt+0x189/0x360 net/socket.c:1830 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x447c89 RSP: 002b:00007fdc14ad6bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007fdc14ad76cc RCX: 0000000000447c89 RDX: 0000000000000040 RSI: 0000000000000000 RDI: 000000000000001f RBP: 0000000000000086 R08: 0000000000000056 R09: 0000000000000000 R10: 0000000020006000 R11: 0000000000000246 R12: 00000000ffffffff R13: 0000000000005568 R14: 00000000006e9608 R15: 00007fdc14ad7700 --- This bug is generated by a dumb bot. It may contain errors. See https://goo.gl/tpsmEJ for details. Direct all questions to syzkaller@googlegroups.com. Please credit me with: Reported-by: syzbot syzbot will keep track of this bug report. Once a fix for this bug is committed, please reply to this email with: #syz fix: exact-commit-title To mark this as a duplicate of another syzbot report, please reply with: #syz dup: exact-subject-of-another-report If it's a one-off invalid bug report, please reply with: #syz invalid Note: if the crash happens again, it will cause creation of a new bug report. Note: all commands must start from beginning of the line.