Unable to handle kernel paging request at virtual address ffff8000379d04ea Mem abort info: Exception class = DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 Data abort info: ISV = 0, ISS = 0x00000033 CM = 0, WnR = 0 swapper pgtable: 4k pages, 48-bit VAs, pgd = ffff20000eeb2000 [ffff8000379d04ea] *pgd=000000007eff7003, *pud=000000007eff6003, *pmd=00f8000077800711 Internal error: Oops: 96000021 [#1] PREEMPT SMP Modules linked in: CPU: 2 PID: 21137 Comm: syz-executor1 Not tainted 4.14.0-rc2-00001-gd7ad33d #115 Hardware name: linux,dummy-virt (DT) task: ffff80003a211a80 task.stack: ffff800039338000 PC is at __ll_sc_atomic_add+0x4/0x18 arch/arm64/include/asm/atomic_ll_sc.h:113 LR is at atomic_add arch/arm64/include/asm/atomic_lse.h:45 [inline] LR is at __skb_clone+0x4a8/0x6c0 net/core/skbuff.c:873 pc : [] lr : [] pstate: 10000145 sp : ffff80003efbd6e0 x29: ffff80003efbd6e0 x28: 0000600034170000 x27: ffff20000ae55360 x26: ffff80001375c988 x25: ffff8000379d0346 x24: ffff80001375c990 x23: ffff20000ae60000 x22: ffff80001357fc5c x21: 1ffff00007df7ae8 x20: ffff80001375c8c0 x19: ffff80001357fb80 x18: ffff20000da58140 x17: 0000000000000001 x16: 0000000000000000 x15: ffff20000e1485a0 x14: 1ffff0000744248b x13: 1ffff0000744248c x12: ffffffffffffffff x11: 1ffff000026aff87 x10: ffff1000026aff87 x9 : dfff200000000000 x8 : 0082009000a40008 x7 : 0000000000000000 x6 : ffff80001357fc40 x5 : ffff1000026aff88 x4 : 0000000000000000 x3 : 1ffff000026aff8b x2 : ffff8000379d04c6 x1 : ffff8000379d04ea x0 : 0000000000000001 Process syz-executor1 (pid: 21137, stack limit = 0xffff800039338000) Call trace: Exception stack(0xffff80003efbd5a0 to 0xffff80003efbd6e0) d5a0: 0000000000000001 ffff8000379d04ea ffff8000379d04c6 1ffff000026aff8b d5c0: 0000000000000000 ffff1000026aff88 ffff80001357fc40 0000000000000000 d5e0: 0082009000a40008 dfff200000000000 ffff1000026aff87 1ffff000026aff87 d600: ffffffffffffffff 1ffff0000744248c 1ffff0000744248b ffff20000e1485a0 d620: 0000000000000000 0000000000000001 ffff20000da58140 ffff80001357fb80 d640: ffff80001375c8c0 1ffff00007df7ae8 ffff80001357fc5c ffff20000ae60000 d660: ffff80001375c990 ffff8000379d0346 ffff80001375c988 ffff20000ae55360 d680: 0000600034170000 ffff80003efbd6e0 ffff200009dffb58 ffff80003efbd6e0 d6a0: ffff20000a30ce44 0000000010000145 ffff80001357fb80 ffff80001375c8c0 d6c0: 0001000000000000 ffff80001375c94e ffff80003efbd6e0 ffff20000a30ce44 [] __ll_sc_atomic_add+0x4/0x18 arch/arm64/include/asm/atomic_ll_sc.h:113 [] skb_clone+0x1c4/0x3b0 net/core/skbuff.c:1286 [] ip_expire+0x4e8/0x7c0 net/ipv4/ip_fragment.c:239 [] call_timer_fn+0x1b8/0x430 kernel/time/timer.c:1281 [] expire_timers+0x1d4/0x320 kernel/time/timer.c:1320 [] __run_timers kernel/time/timer.c:1620 [inline] [] run_timer_softirq+0x214/0x5f0 kernel/time/timer.c:1646 [] __do_softirq+0x350/0xc0c kernel/softirq.c:284 [] do_softirq_own_stack include/linux/interrupt.h:498 [inline] [] invoke_softirq kernel/softirq.c:371 [inline] [] irq_exit+0x1dc/0x2f8 kernel/softirq.c:405 [] __handle_domain_irq+0xdc/0x230 kernel/irq/irqdesc.c:647 [] handle_domain_irq include/linux/irqdesc.h:175 [inline] [] gic_handle_irq+0x6c/0xe0 drivers/irqchip/irq-gic.c:367 Exception stack(0xffff80003933bbc0 to 0xffff80003933bd00) bbc0: ffff80003a21234c 0000000000000007 0000000000000000 1ffff00007442469 bbe0: dfff200000000000 ffff10000726771c dfff200000000000 0000000000000000 bc00: ffff80003a212350 1ffff00007442469 ffff80003a212348 ffff80003a212368 bc20: 1ffff0000744246c 1ffff0000744246e 1ffff0000744246d ffff20000e1485a0 bc40: 0000000000000000 0000000000000001 ffff20000da58140 ffff80003a211a80 bc60: 0000000000000140 ffff800013b72910 0000000000000000 0000000000000001 bc80: 0000ffffc97b5840 0000000000000124 0000000000000071 ffff20000a377000 bca0: ffff80003a211a80 ffff80003933bd10 ffff20000827bd10 ffff80003933bd00 bcc0: ffff20000827bd44 0000000010000145 ffff80003933bd10 ffff2000081e1678 bce0: 0001000000000000 ffff20000a3c9c00 ffff80003933bd10 ffff20000827bd44 [] el1_irq+0xb4/0x12c arch/arm64/kernel/entry.S:569 [] arch_local_irq_restore arch/arm64/include/asm/irqflags.h:81 [inline] [] lock_acquire+0xec/0x1c0 kernel/locking/lockdep.c:4005 [] __might_fault+0x12c/0x220 mm/memory.c:4502 [] _copy_to_user include/linux/uaccess.h:130 [inline] [] copy_to_user include/linux/uaccess.h:154 [inline] [] put_timespec64+0xc8/0x1b8 kernel/time/time.c:918 [] SYSC_clock_gettime kernel/time/posix-timers.c:1063 [inline] [] SyS_clock_gettime+0x144/0x178 kernel/time/posix-timers.c:1051 Exception stack(0xffff80003933bec0 to 0xffff80003933c000) bec0: 0000000000000001 0000ffffc97b5840 0000ffffc97b5988 0000ffffc97b5940 bee0: 00000000004d2ec0 000000000000002d 0dc66fef2fd12212 0dc66fef2fd12212 bf00: 0000000000000071 e46546a8bba98d43 9a7c3168cba61200 616981b8c14b12b0 bf20: ef2fd1221247e56e 103c2634240dc66f 0000000000000008 0000000000000001 bf40: 0000000000000000 0000000000826000 0000000000000000 000000000000000b bf60: 0000000000000006 0000ffffc97b5940 000000000000037d 0000ffffc97b5930 bf80: 00000000000f4240 00000000004c0008 0000ffffc97b5b30 0000000040000001 bfa0: 000000000004935d 0000ffffc97b5830 0000000000400f28 0000ffffc97b5830 bfc0: 000000000042e744 0000000000000000 0000000000000001 0000000000000071 bfe0: 0000000000000000 0000000000000000 0000000000000000 0000000000000000 [] el0_svc_naked+0x24/0x28 Code: 978b7cfd 17ffff91 00000000 f9800031 (885f7c31) ---[ end trace 12bdc649a111cd4a ]---