[BUG] afs: ERR_PTR dereference in afs_lookup_server() error path

Farhad Alemi farhad.alemi at berkeley.edu
Wed Sep 9 11:12:24 PDT 2026


Hi David,

Tried it w 7.3.0-rc2-00006-g28924df2a08f:

[   43.872155][ T9500] BUG: unable to handle page fault for address:
ffffffffffffffb1
[   43.873156][ T9500] #PF: supervisor read access in kernel mode
[   43.873889][ T9500] #PF: error_code(0x0000) - not-present page
[   43.874619][ T9500] PGD e94b067 P4D e94b067 PUD e94d067 PMD 0
[   43.875371][ T9500] Oops: Oops: 0000 [#1] SMP KASAN NOPTI
[   43.876050][ T9500] CPU: 1 UID: 0 PID: 9500 Comm: repro Not tainted
7.3.0-rc2-00006-g28924df2a08f #1 PREEMPT(full)
[   43.877196][ T9500] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[   43.878156][ T9500] RIP: 0010:afs_put_addrlist+0x3c/0x110
[   43.878682][ T9500] Code: aa 39 17 fe 4d 85 f6 74 7d 49 8d 7e 18 48
89 f8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df 0f b6 04 08 84 c0 0f
85 af 00 00 00 <41> 8b 6e 18 4d 8d 66 10 4c 89 e7 be 04 00 00 00 e8 9f
35 87 fe 41
[   43.880425][ T9500] RSP: 0018:ffffc90007b67618 EFLAGS: 00010246
[   43.880980][ T9500] RAX: 0000000000000000 RBX: 0000000000000009
RCX: dffffc0000000000
[   43.881803][ T9500] RDX: 0000000000000000 RSI: 0000000000000009
RDI: ffffffffffffffb1
[   43.882537][ T9500] RBP: 0000000000000000 R08: ffff88810ea66a87
R09: 1ffff11021d4cd50
[   43.883253][ T9500] R10: dffffc0000000000 R11: ffffed1021d4cd51
R12: ffff88810d211000
[   43.883970][ T9500] R13: ffff88810ea66800 R14: ffffffffffffff99
R15: ffffffffffffff99
[   43.884688][ T9500] FS:  000000003957f400(0000)
GS:ffff8881da58b000(0000) knlGS:0000000000000000
[   43.885493][ T9500] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   43.886088][ T9500] CR2: ffffffffffffffb1 CR3: 0000000113534000
CR4: 0000000000752ef0
[   43.886811][ T9500] PKRU: 55555554
[   43.887141][ T9500] Call Trace:
[   43.887456][ T9500]  <TASK>
[   43.887733][ T9500]  afs_lookup_server+0xe0a/0x1120
[   43.888196][ T9500]  ? afs_alloc_server_list+0x7da/0x1140
[   43.888704][ T9500]  afs_alloc_server_list+0x7da/0x1140
[   43.889196][ T9500]  ? __pfx_afs_alloc_server_list+0x10/0x10
[   43.889754][ T9500]  ? __raw_spin_lock_init+0x45/0x100
[   43.890262][ T9500]  ? afs_create_volume+0x96d/0x1130
[   43.890766][ T9500]  afs_create_volume+0x994/0x1130
[   43.891294][ T9500]  ? __pfx_afs_create_volume+0x10/0x10
[   43.891791][ T9500]  ? __asan_memset+0x22/0x50
[   43.892221][ T9500]  afs_cell_detect_alias+0x41d/0x1170
[   43.892719][ T9500]  ? __pfx_afs_cell_detect_alias+0x10/0x10
[   43.893249][ T9500]  ? afs_request_key+0x1c8/0x250
[   43.893708][ T9500]  ? __mutex_unlock_slowpath+0x731/0x900
[   43.894230][ T9500]  ? __pfx___mutex_unlock_slowpath+0x10/0x10
[   43.894781][ T9500]  ? afs_request_key+0x13c/0x250
[   43.895235][ T9500]  afs_get_tree+0x24b/0x12b0
[   43.895665][ T9500]  vfs_get_tree+0x92/0x2a0
[   43.896077][ T9500]  do_new_mount+0x341/0xd30
[   43.896498][ T9500]  ? apparmor_capable+0x126/0x170
[   43.896960][ T9500]  ? __pfx_do_new_mount+0x10/0x10
[   43.897422][ T9500]  ? ns_capable+0x89/0xe0
[   43.897821][ T9500]  ? user_path_at+0xd4/0x160
[   43.898254][ T9500]  __se_sys_mount+0x31d/0x420
[   43.898689][ T9500]  ? __pfx___se_sys_mount+0x10/0x10
[   43.899164][ T9500]  ? __x64_sys_mount+0x20/0xc0
[   43.899606][ T9500]  do_syscall_64+0x155/0x510
[   43.900033][ T9500]  ? trace_irq_disable+0x3b/0x140
[   43.900499][ T9500]  ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   43.901051][ T9500]  ? clear_bhb_loop+0x30/0x80
[   43.901554][ T9500]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   43.902093][ T9500] RIP: 0033:0x426ffe
[   43.902464][ T9500] Code: 0a 00 01 00 00 00 eb 85 e8 0f 09 00 00 66
2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 a5
00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8
64 89 01 48
[   43.904183][ T9500] RSP: 002b:00007fff93751b68 EFLAGS: 00000207
ORIG_RAX: 00000000000000a5
[   43.904940][ T9500] RAX: ffffffffffffffda RBX: 0000000000000001
RCX: 0000000000426ffe
[   43.905655][ T9500] RDX: 00000000004a2103 RSI: 00000000004a20fa
RDI: 00000000004a2107
[   43.906369][ T9500] RBP: 00007fff93751b90 R08: 0000000000000000
R09: 0000000000000000
[   43.907082][ T9500] R10: 0000000000000000 R11: 0000000000000207
R12: 00007fff93751cb8
[   43.907837][ T9500] R13: 00007fff93751cc8 R14: 0000000000000002
R15: 00000000004cba40
[   43.908591][ T9500]  </TASK>
[   43.908893][ T9500] Modules linked in:
[   43.909258][ T9500] CR2: ffffffffffffffb1
[   43.909646][ T9500] ---[ end trace 0000000000000000 ]---
[   43.910172][ T9500] RIP: 0010:afs_put_addrlist+0x3c/0x110
[   43.910184][ T9500] Code: aa 39 17 fe 4d 85 f6 74 7d 49 8d 7e 18 48
89 f8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df 0f b6 04 08 84 c0 0f
85 af 00 00 00 <41> 8b 6e 18 4d 8d 66 10 4c 89 e7 be 04 00 00 00 e8 9f
35 87 fe 41
[   43.910190][ T9500] RSP: 0018:ffffc90007b67618 EFLAGS: 00010246
[   43.910196][ T9500] RAX: 0000000000000000 RBX: 0000000000000009
RCX: dffffc0000000000
[   43.910201][ T9500] RDX: 0000000000000000 RSI: 0000000000000009
RDI: ffffffffffffffb1
[   43.910205][ T9500] RBP: 0000000000000000 R08: ffff88810ea66a87
R09: 1ffff11021d4cd50
[   43.910210][ T9500] R10: dffffc0000000000 R11: ffffed1021d4cd51
R12: ffff88810d211000
[   43.910216][ T9500] R13: ffff88810ea66800 R14: ffffffffffffff99
R15: ffffffffffffff99
[   43.910221][ T9500] FS:  000000003957f400(0000)
GS:ffff8881da58b000(0000) knlGS:0000000000000000
[   43.910227][ T9500] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   43.910232][ T9500] CR2: ffffffffffffffb1 CR3: 0000000113534000
CR4: 0000000000752ef0
[   43.910238][ T9500] PKRU: 55555554
[   43.910244][ T9500] Kernel panic - not syncing: Fatal exception
[   43.919939][ T9500] Kernel Offset: disabled
[   43.920340][ T9500] Rebooting in 86400 seconds.

Reproducer attached; thanks!

On Wed, Sep 2, 2026 at 4:41 AM David Howells <dhowells at redhat.com> wrote:
>
> Hi Farhad,
>
> > While fuzzing Linux 7.1-rc5 with syzkaller, as part of research at ASU's
> > SEFCOM lab, we hit the crash below. Crash reports can be found here:
>
> Have you tried it with 7.3-rc1?
>
> >   BUG: unable to handle page fault for address: ffffffffffffff9f
> >   RIP: 0010:afs_put_addrlist+0x43/0x250 fs/afs/addr_list.c:38
> >   afs_lookup_server+0xd3f/0x1020 fs/afs/server.c:243
> >   afs_alloc_server_list+0x800/0x11a0 fs/afs/server_list.c:82
> >   afs_create_volume+0x995/0x1290 fs/afs/volume.c:227
> >   afs_get_tree+0x955/0x10b0 fs/afs/super.c:555
>
> It looks like alist is 0xffffffffffffff9f, but it's not immediately obvious
> how it could be anything other than a valid pointer at that point.
>
> > Our reproducer.c is available upon request.
>
> If I could have that, please?
>
> Thanks,
> David
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: reproducer.c
Type: application/octet-stream
Size: 8904 bytes
Desc: not available
URL: <http://lists.infradead.org/pipermail/linux-afs/attachments/20260909/fa8feb7e/attachment-0001.obj>


More information about the linux-afs mailing list