Hello,

syzbot found the following issue on:

HEAD commit:    1b78070aaef6 Merge tag 'net-7.3-rc1' of git://git.kernel.o..
git tree:       net
console output: https://syzkaller.appspot.com/x/log.txt?x=1535ce25580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=5e4e3a0e188a497e
dashboard link: https://syzkaller.appspot.com/bug?extid=22c4f9a7026c86bcc3b8
compiler:       Debian clang version 22.1.8 
(++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: 
https://storage.googleapis.com/syzbot-assets/9bf9d046731e/disk-1b78070a.raw.xz
vmlinux: 
https://storage.googleapis.com/syzbot-assets/31e105356045/vmlinux-1b78070a.xz
kernel image: 
https://storage.googleapis.com/syzbot-assets/6087b1118967/bzImage-1b78070a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

bridge0: received packet on bridge_slave_1 with own address as source address 
(addr:aa:aa:aa:aa:aa:1c, vlan:1)
==================================================================
BUG: KASAN: use-after-free in skb_zcopy include/linux/skbuff.h:1793 [inline]
BUG: KASAN: use-after-free in skb_orphan_frags include/linux/skbuff.h:3435 
[inline]
BUG: KASAN: use-after-free in skb_clone+0x31d/0x3a0 net/core/skbuff.c:2107
Read of size 1 at addr ffff88802ad30080 by task kworker/u8:15/7915

CPU: 1 UID: 0 PID: 7915 Comm: kworker/u8:15 Not tainted syzkaller #0 
PREEMPT(full) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 
07/24/2026
Workqueue: events_unbound cfg80211_wiphy_work
Call Trace:
 <IRQ>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 print_address_description+0x55/0x1e0 mm/kasan/report.c:378
 print_report+0x58/0x70 mm/kasan/report.c:482
 kasan_report+0x117/0x150 mm/kasan/report.c:595
 skb_zcopy include/linux/skbuff.h:1793 [inline]
 skb_orphan_frags include/linux/skbuff.h:3435 [inline]
 skb_clone+0x31d/0x3a0 net/core/skbuff.c:2107
 deliver_clone net/bridge/br_forward.c:125 [inline]
 maybe_deliver net/bridge/br_forward.c:191 [inline]
 br_flood+0x3c3/0x8d0 net/bridge/br_forward.c:245
 br_handle_frame_finish+0x1119/0x1950 net/bridge/br_input.c:229
 nf_hook_bridge_pre net/bridge/br_input.c:313 [inline]
 br_handle_frame+0x81b/0x1510 net/bridge/br_input.c:442
 __netif_receive_skb_core+0x989/0x30c0 net/core/dev.c:6151
 __netif_receive_skb_one_core net/core/dev.c:6262 [inline]
 __netif_receive_skb net/core/dev.c:6377 [inline]
 process_backlog+0x727/0x18b0 net/core/dev.c:6728
 __napi_poll+0xaa/0x330 net/core/dev.c:7787
 napi_poll net/core/dev.c:7850 [inline]
 net_rx_action+0x61d/0xf50 net/core/dev.c:8007
 handle_softirqs+0x226/0x860 kernel/softirq.c:645
 do_softirq+0x77/0xd0 kernel/softirq.c:546
 </IRQ>
 <TASK>
 __local_bh_enable_ip+0x100/0x140 kernel/softirq.c:473
 spin_unlock_bh include/linux/spinlock.h:407 [inline]
 cfg80211_inform_single_bss_data+0x1491/0x1be0 net/wireless/scan.c:2426
 cfg80211_inform_bss_data+0x263/0x3cc0 net/wireless/scan.c:3266
 cfg80211_inform_bss_frame_data+0x3c7/0x840 net/wireless/scan.c:3358
 ieee80211_bss_info_update+0x791/0xa50 net/mac80211/scan.c:230
 ieee80211_rx_bss_info net/mac80211/ibss.c:1065 [inline]
 ieee80211_rx_mgmt_probe_beacon net/mac80211/ibss.c:1546 [inline]
 ieee80211_ibss_rx_queued_mgmt+0x1ce3/0x2c40 net/mac80211/ibss.c:1573
 ieee80211_iface_process_skb net/mac80211/iface.c:1769 [inline]
 ieee80211_iface_work+0x78a/0x1010 net/mac80211/iface.c:1823
 cfg80211_wiphy_work+0x29e/0x420 net/wireless/core.c:541
 process_one_work kernel/workqueue.c:3387 [inline]
 process_scheduled_works+0xc3d/0x1630 kernel/workqueue.c:3470
 worker_thread+0xa47/0xfb0 kernel/workqueue.c:3551
 kthread+0x38b/0x480 kernel/kthread.c:436
 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>

The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88802ad36000 
pfn:0x2ad30
flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000000 ffffea0000a99c08 ffff8880b87417b0 0000000000000000
raw: ffff88802ad36000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 3, migratetype Unmovable, gfp_mask 
0x528c0(GFP_NOWAIT|__GFP_IO|__GFP_FS|__GFP_NORETRY|__GFP_COMP), pid 13508, tgid 
13502 (syz.2.1942), ts 299754405803
 set_page_owner include/linux/page_owner.h:33 [inline]
 post_alloc_hook+0x1f9/0x250 mm/page_alloc.c:1871
 prep_new_page mm/page_alloc.c:1879 [inline]
 get_page_from_freelist+0x2209/0x2280 mm/page_alloc.c:3943
 __alloc_frozen_pages_noprof+0x217/0x5a0 mm/page_alloc.c:5436
 alloc_pages_mpol+0x21e/0x390 mm/mempolicy.c:2486
 alloc_frozen_pages_noprof mm/mempolicy.c:2557 [inline]
 alloc_pages_noprof+0xb1/0x2b0 mm/mempolicy.c:2577
 skb_page_frag_refill+0xf5/0x460 net/core/sock.c:3193
 tun_build_skb drivers/net/tun.c:1706 [inline]
 tun_get_user+0x1b32/0x44d0 drivers/net/tun.c:1856
 tun_chr_write_iter+0x113/0x200 drivers/net/tun.c:2091
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x612/0xba0 fs/read_write.c:687
 ksys_write+0x150/0x270 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
page last free pid 7915 tgid 7915 ts 394412542880 stack trace:
 reset_page_owner include/linux/page_owner.h:26 [inline]
 __free_pages_prepare mm/page_alloc.c:1418 [inline]
 __free_frozen_pages+0xc93/0xd90 mm/page_alloc.c:2962
 skb_free_frag include/linux/skbuff.h:3559 [inline]
 skb_free_head net/core/skbuff.c:1093 [inline]
 pskb_expand_head+0x6d1/0x13a0 net/core/skbuff.c:2347
 __skb_cow include/linux/skbuff.h:3904 [inline]
 skb_cow_head include/linux/skbuff.h:3938 [inline]
 __vlan_insert_inner_tag include/linux/if_vlan.h:368 [inline]
 vlan_insert_inner_tag include/linux/if_vlan.h:441 [inline]
 vlan_insert_tag include/linux/if_vlan.h:468 [inline]
 vlan_insert_tag_set_proto include/linux/if_vlan.h:489 [inline]
 __vlan_hwaccel_push_inside include/linux/if_vlan.h:529 [inline]
 validate_xmit_vlan net/core/dev.c:3976 [inline]
 validate_xmit_skb+0x3aa/0x14f0 net/core/dev.c:4081
 __dev_queue_xmit+0xb04/0x3820 net/core/dev.c:4913
 dev_queue_xmit include/linux/netdevice.h:3461 [inline]
 vlan_dev_hard_start_xmit+0x201/0x420 net/8021q/vlan_dev.c:126
 __netdev_start_xmit include/linux/netdevice.h:5429 [inline]
 netdev_start_xmit include/linux/netdevice.h:5438 [inline]
 xmit_one net/core/dev.c:3937 [inline]
 dev_hard_start_xmit+0x2cd/0x830 net/core/dev.c:3953
 __dev_queue_xmit+0x14c0/0x3820 net/core/dev.c:4926
 dev_queue_xmit include/linux/netdevice.h:3461 [inline]
 br_dev_queue_push_xmit+0x370/0x4b0 net/bridge/br_forward.c:53
 NF_HOOK+0x360/0x3f0 include/linux/netfilter.h:325
 br_forward_finish+0xd3/0x130 net/bridge/br_forward.c:66
 NF_HOOK+0x360/0x3f0 include/linux/netfilter.h:325
 __br_forward+0x397/0x540 net/bridge/br_forward.c:115
 deliver_clone net/bridge/br_forward.c:131 [inline]
 maybe_deliver net/bridge/br_forward.c:191 [inline]
 br_flood+0x3e6/0x8d0 net/bridge/br_forward.c:245
 br_handle_frame_finish+0x1119/0x1950 net/bridge/br_input.c:229
 nf_hook_bridge_pre net/bridge/br_input.c:313 [inline]
 br_handle_frame+0x81b/0x1510 net/bridge/br_input.c:442
 __netif_receive_skb_core+0x989/0x30c0 net/core/dev.c:6151

Memory state around the buggy address:
 ffff88802ad2ff80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
 ffff88802ad30000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88802ad30080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                   ^
 ffff88802ad30100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
 ffff88802ad30180: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

Reply via email to