пятница

[Bug 2078038] Re: UBSAN array-index-out-of-bounds reported with N-6.8 on P9 node baltar

** Changed in: linux (Ubuntu Noble)
Status: New => Fix Committed

--
You received this bug notification because you are subscribed to linux
in Ubuntu.
Matching subscriptions: Bgg, Bmail, Nb
https://bugs.launchpad.net/bugs/2078038

Title:
UBSAN array-index-out-of-bounds reported with N-6.8 on P9 node baltar

Status in ubuntu-kernel-tests:
Invalid
Status in linux package in Ubuntu:
New
Status in linux source package in Noble:
Fix Committed

Bug description:
[Impact]

Issue found with Noble 6.8.0-41-generic on P9 node baltar.

[ 1.628868] i40e 0002:01:00.0: enabling device (0140 -> 0142)
[ 1.631444] ------------[ cut here ]------------
[ 1.631460] UBSAN: array-index-out-of-bounds in /build/linux-k1IV9m/linux-6.8.0/drivers/scsi/aacraid/comminit.c:130:16
[ 1.631497] index 1 is out of range for type '_rrq [1]'
[ 1.631526] CPU: 0 PID: 974 Comm: kworker/0:2 Not tainted 6.8.0-41-generic #41-Ubuntu
[ 1.631551] Hardware name: 9006-12C POWER9 0x4e1202 opal:skiboot-v6.0.19 PowerNV
[ 1.631587] Workqueue: events work_for_cpu_fn
[ 1.631621] Call Trace:
[ 1.631628] [c00000000df938c0] [c0000000016bfec8] dump_stack_lvl+0x80/0x10c (unreliable)
[ 1.631663] [c00000000df938f0] [c000000000c83458] __ubsan_handle_out_of_bounds+0xc4/0x12c
[ 1.631699] [c00000000df939a0] [c00800000c460a28] aac_alloc_comm.constprop.0+0x580/0x620 [aacraid]
[ 1.631742] [c00000000df93a80] [c00800000c460b18] aac_comm_init+0x50/0x4f0 [aacraid]
[ 1.631776] [c00000000df93b10] [c00800000c4616ec] aac_init_adapter+0x234/0x660 [aacraid]
[ 1.631808] [c00000000df93c10] [c00800000c46ee0c] aac_srcv_init+0x28c/0x7b4 [aacraid]
[ 1.631844] [c00000000df93ce0] [c00800000c45395c] aac_probe_one+0x334/0x924 [aacraid]
[ 1.631882] [c00000000df93da0] [c000000000cef564] local_pci_probe+0x68/0x124
[ 1.631919] [c00000000df93e20] [c0000000001c224c] work_for_cpu_fn+0x38/0x60
[ 1.631957] [c00000000df93e50] [c0000000001c8ab8] process_one_work+0x1d4/0x4dc
[ 1.631993] [c00000000df93ef0] [c0000000001ca60c] worker_thread+0x470/0x648
[ 1.632031] [c00000000df93f90] [c0000000001d90bc] kthread+0x138/0x140
[ 1.632068] [c00000000df93fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18
[ 1.632109] ---[ end trace ]---
[ 1.632128] ------------[ cut here ]------------
[ 1.632147] UBSAN: array-index-out-of-bounds in /build/linux-k1IV9m/linux-6.8.0/drivers/scsi/aacraid/comminit.c:132:16
[ 1.632184] index 1 is out of range for type '_rrq [1]'
[ 1.632214] CPU: 0 PID: 974 Comm: kworker/0:2 Not tainted 6.8.0-41-generic #41-Ubuntu
[ 1.632239] Hardware name: 9006-12C POWER9 0x4e1202 opal:skiboot-v6.0.19 PowerNV
[ 1.632271] Workqueue: events work_for_cpu_fn
[ 1.632305] Call Trace:
[ 1.632311] [c00000000df938c0] [c0000000016bfec8] dump_stack_lvl+0x80/0x10c (unreliable)
[ 1.632349] [c00000000df938f0] [c000000000c83458] __ubsan_handle_out_of_bounds+0xc4/0x12c
[ 1.632385] [c00000000df939a0] [c00800000c460a44] aac_alloc_comm.constprop.0+0x59c/0x620 [aacraid]
[ 1.632433] [c00000000df93a80] [c00800000c460b18] aac_comm_init+0x50/0x4f0 [aacraid]
[ 1.632473] [c00000000df93b10] [c00800000c4616ec] aac_init_adapter+0x234/0x660 [aacraid]
[ 1.632511] [c00000000df93c10] [c00800000c46ee0c] aac_srcv_init+0x28c/0x7b4 [aacraid]
[ 1.632547] [c00000000df93ce0] [c00800000c45395c] aac_probe_one+0x334/0x924 [aacraid]
[ 1.632583] [c00000000df93da0] [c000000000cef564] local_pci_probe+0x68/0x124
[ 1.632619] [c00000000df93e20] [c0000000001c224c] work_for_cpu_fn+0x38/0x60
[ 1.632654] [c00000000df93e50] [c0000000001c8ab8] process_one_work+0x1d4/0x4dc
[ 1.632690] [c00000000df93ef0] [c0000000001ca60c] worker_thread+0x470/0x648
[ 1.632728] [c00000000df93f90] [c0000000001d90bc] kthread+0x138/0x140
[ 1.632755] [c00000000df93fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18
[ 1.632791] ---[ end trace ]---
[ 1.632809] ------------[ cut here ]------------
[ 1.632827] UBSAN: array-index-out-of-bounds in /build/linux-k1IV9m/linux-6.8.0/drivers/scsi/aacraid/comminit.c:134:16
[ 1.632863] index 1 is out of range for type '_rrq [1]'
[ 1.632895] CPU: 0 PID: 974 Comm: kworker/0:2 Not tainted 6.8.0-41-generic #41-Ubuntu
[ 1.632930] Hardware name: 9006-12C POWER9 0x4e1202 opal:skiboot-v6.0.19 PowerNV
[ 1.632962] Workqueue: events work_for_cpu_fn
[ 1.632993] Call Trace:
[ 1.633000] [c00000000df938c0] [c0000000016bfec8] dump_stack_lvl+0x80/0x10c (unreliable)
[ 1.633037] [c00000000df938f0] [c000000000c83458] __ubsan_handle_out_of_bounds+0xc4/0x12c
[ 1.633072] [c00000000df939a0] [c00800000c460a60] aac_alloc_comm.constprop.0+0x5b8/0x620 [aacraid]
[ 1.633112] [c00000000df93a80] [c00800000c460b18] aac_comm_init+0x50/0x4f0 [aacraid]
[ 1.633146] [c00000000df93b10] [c00800000c4616ec] aac_init_adapter+0x234/0x660 [aacraid]
[ 1.633184] [c00000000df93c10] [c00800000c46ee0c] aac_srcv_init+0x28c/0x7b4 [aacraid]
[ 1.633226] [c00000000df93ce0] [c00800000c45395c] aac_probe_one+0x334/0x924 [aacraid]
[ 1.633270] [c00000000df93da0] [c000000000cef564] local_pci_probe+0x68/0x124
[ 1.633308] [c00000000df93e20] [c0000000001c224c] work_for_cpu_fn+0x38/0x60
[ 1.633345] [c00000000df93e50] [c0000000001c8ab8] process_one_work+0x1d4/0x4dc
[ 1.633383] [c00000000df93ef0] [c0000000001ca60c] worker_thread+0x470/0x648
[ 1.633422] [c00000000df93f90] [c0000000001d90bc] kthread+0x138/0x140
[ 1.633458] [c00000000df93fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18
[ 1.633494] ---[ end trace ]---
[ 1.633526] ------------[ cut here ]------------
[ 1.633549] UBSAN: array-index-out-of-bounds in /build/linux-k1IV9m/linux-6.8.0/drivers/scsi/aacraid/comminit.c:135:16
[ 1.633586] index 1 is out of range for type '_rrq [1]'
[ 1.633607] CPU: 0 PID: 974 Comm: kworker/0:2 Not tainted 6.8.0-41-generic #41-Ubuntu
[ 1.633645] Hardware name: 9006-12C POWER9 0x4e1202 opal:skiboot-v6.0.19 PowerNV
[ 1.633681] Workqueue: events work_for_cpu_fn
[ 1.633718] Call Trace:
[ 1.633742] [c00000000df938c0] [c0000000016bfec8] dump_stack_lvl+0x80/0x10c (unreliable)
[ 1.633779] [c00000000df938f0] [c000000000c83458] __ubsan_handle_out_of_bounds+0xc4/0x12c
[ 1.633806] [c00000000df939a0] [c00800000c460a7c] aac_alloc_comm.constprop.0+0x5d4/0x620 [aacraid]
[ 1.633832] [c00000000df93a80] [c00800000c460b18] aac_comm_init+0x50/0x4f0 [aacraid]
[ 1.633856] [c00000000df93b10] [c00800000c4616ec] aac_init_adapter+0x234/0x660 [aacraid]
[ 1.633888] [c00000000df93c10] [c00800000c46ee0c] aac_srcv_init+0x28c/0x7b4 [aacraid]
[ 1.633918] [c00000000df93ce0] [c00800000c45395c] aac_probe_one+0x334/0x924 [aacraid]
[ 1.634223] [c00000000df93da0] [c000000000cef564] local_pci_probe+0x68/0x124
[ 1.634321] [c00000000df93e20] [c0000000001c224c] work_for_cpu_fn+0x38/0x60
[ 1.634409] [c00000000df93e50] [c0000000001c8ab8] process_one_work+0x1d4/0x4dc
[ 1.636120] [c00000000df93ef0] [c0000000001ca60c] worker_thread+0x470/0x648
[ 1.636224] [c00000000df93f90] [c0000000001d90bc] kthread+0x138/0x140
[ 1.636293] [c00000000df93fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18
[ 1.636420] ---[ end trace ]---
[ 1.638058] ------------[ cut here ]------------
[ 1.638107] UBSAN: array-index-out-of-bounds in /build/linux-k1IV9m/linux-6.8.0/drivers/scsi/aacraid/comminit.c:138:18
[ 1.638244] index 1 is out of range for type '_rrq [1]'
[ 1.650181] CPU: 0 PID: 974 Comm: kworker/0:2 Not tainted 6.8.0-41-generic #41-Ubuntu
[ 1.650285] Hardware name: 9006-12C POWER9 0x4e1202 opal:skiboot-v6.0.19 PowerNV
[ 1.650368] Workqueue: events work_for_cpu_fn
[ 1.650438] Call Trace:
[ 1.650460] [c00000000df938c0] [c0000000016bfec8] dump_stack_lvl+0x80/0x10c (unreliable)
[ 1.651140] [c00000000df938f0] [c000000000c83458] __ubsan_handle_out_of_bounds+0xc4/0x12c
[ 1.651242] [c00000000df939a0] [c00800000c460a98] aac_alloc_comm.constprop.0+0x5f0/0x620 [aacraid]
[ 1.651988] [c00000000df93a80] [c00800000c460b18] aac_comm_init+0x50/0x4f0 [aacraid]
[ 1.652093] [c00000000df93b10] [c00800000c4616ec] aac_init_adapter+0x234/0x660 [aacraid]
[ 1.652194] [c00000000df93c10] [c00800000c46ee0c] aac_srcv_init+0x28c/0x7b4 [aacraid]
[ 1.652939] [c00000000df93ce0] [c00800000c45395c] aac_probe_one+0x334/0x924 [aacraid]
[ 1.653042] [c00000000df93da0] [c000000000cef564] local_pci_probe+0x68/0x124
[ 1.653130] [c00000000df93e20] [c0000000001c224c] work_for_cpu_fn+0x38/0x60
[ 1.653860] [c00000000df93e50] [c0000000001c8ab8] process_one_work+0x1d4/0x4dc
[ 1.653948] [c00000000df93ef0] [c0000000001ca60c] worker_thread+0x470/0x648
[ 1.654040] [c00000000df93f90] [c0000000001d90bc] kthread+0x138/0x140
[ 1.654761] [c00000000df93fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18
[ 1.654854] ---[ end trace ]---
[ 1.654910] ------------[ cut here ]------------
[ 1.654960] UBSAN: array-index-out-of-bounds in /build/linux-k1IV9m/linux-6.8.0/drivers/scsi/aacraid/comminit.c:137:16
[ 1.655694] index 1 is out of range for type '_rrq [1]'
[ 1.655761] CPU: 0 PID: 974 Comm: kworker/0:2 Not tainted 6.8.0-41-generic #41-Ubuntu
[ 1.655864] Hardware name: 9006-12C POWER9 0x4e1202 opal:skiboot-v6.0.19 PowerNV
[ 1.656575] Workqueue: events work_for_cpu_fn
[ 1.656640] Call Trace:
[ 1.656672] [c00000000df938c0] [c0000000016bfec8] dump_stack_lvl+0x80/0x10c (unreliable)
[ 1.656781] [c00000000df938f0] [c000000000c83458] __ubsan_handle_out_of_bounds+0xc4/0x12c
[ 1.657529] [c00000000df939a0] [c00800000c460a10] aac_alloc_comm.constprop.0+0x568/0x620 [aacraid]
[ 1.657636] [c00000000df93a80] [c00800000c460b18] aac_comm_init+0x50/0x4f0 [aacraid]
[ 1.658357] [c00000000df93b10] [c00800000c4616ec] aac_init_adapter+0x234/0x660 [aacraid]
[ 1.658468] [c00000000df93c10] [c00800000c46ee0c] aac_srcv_init+0x28c/0x7b4 [aacraid]
[ 1.658557] [c00000000df93ce0] [c00800000c45395c] aac_probe_one+0x334/0x924 [aacraid]
[ 1.659199] [c00000000df93da0] [c000000000cef564] local_pci_probe+0x68/0x124
[ 1.659288] [c00000000df93e20] [c0000000001c224c] work_for_cpu_fn+0x38/0x60
[ 1.659372] [c00000000df93e50] [c0000000001c8ab8] process_one_work+0x1d4/0x4dc
[ 1.674297] [c00000000df93ef0] [c0000000001ca60c] worker_thread+0x470/0x648
[ 1.674397] [c00000000df93f90] [c0000000001d90bc] kthread+0x138/0x140
[ 1.674483] [c00000000df93fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18
[ 1.674580] ---[ end trace ]---
[ 1.676253] aacraid: Comm Interface type3 enabled

[Test Case]

Boot kernel on affected machine and check dmesg.

[Where Problems Could Occur]

Modifications are limited to the aacraid driver, so only machines that
use that driver are affected. Potential side-effects include kernel
crashes, disk access failures, ...

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-kernel-tests/+bug/2078038/+subscriptions

Комментариев нет:

Отправить комментарий