UBSAN: array-index-out-of-bounds in /build/linux-IPoq5q/linux-6.5.0/drivers/message/fusion/mptsas.c

Bug #2037490 reported by Yan Jin
20
This bug affects 3 people
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Steps to reproduce:
1. install a ubuntu 23.10 VM on an ESXi Server
2. hot add a lsilogicsas controller and a lsilogicsas disk

Call Trace will be reported in dmesg log

[ 176.181166] ================================================================================
[ 176.181167] UBSAN: array-index-out-of-bounds in /build/linux-IPoq5q/linux-6.5.0/drivers/message/fusion/mptsas.c:2448:22
[ 176.181171] index 1 is out of range for type 'MPI_SAS_IO_UNIT0_PHY_DATA [1]'
[ 176.181174] CPU: 0 PID: 2102 Comm: (udev-worker) Not tainted 6.5.0-5-generic #5-Ubuntu
[ 176.181177] Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.21805430.B64.2305221830 05/22/2023
[ 176.181179] Call Trace:
[ 176.181181] <TASK>
[ 176.181183] dump_stack_lvl+0x48/0x70
[ 176.181228] dump_stack+0x10/0x20
[ 176.181232] __ubsan_handle_out_of_bounds+0xc6/0x110
[ 176.181236] mptsas_sas_io_unit_pg0+0x3b1/0x3f0 [mptsas]
[ 176.181248] mptsas_probe_hba_phys.isra.0+0x55/0x490 [mptsas]
[ 176.181257] ? __pfx_scsi_runtime_idle+0x10/0x10
[ 176.181264] ? rpm_idle+0x1dc/0x2b0
[ 176.181269] mptsas_scan_sas_topology+0x32/0x210 [mptsas]
[ 176.181277] ? scsi_autopm_put_host+0x1a/0x30
[ 176.181280] mptsas_probe.part.0+0x3cc/0x570 [mptsas]
[ 176.181289] mptsas_probe+0x1e/0x30 [mptsas]
[ 176.181298] local_pci_probe+0x44/0xb0
[ 176.181302] pci_call_probe+0x55/0x190
[ 176.181307] pci_device_probe+0x84/0x120
[ 176.181312] really_probe+0x1c4/0x410
[ 176.181316] __driver_probe_device+0x8c/0x180
[ 176.181320] driver_probe_device+0x24/0xd0
[ 176.181324] __driver_attach+0x10b/0x210
[ 176.181327] ? __pfx___driver_attach+0x10/0x10
[ 176.181330] bus_for_each_dev+0x8a/0xf0
[ 176.181333] driver_attach+0x1e/0x30
[ 176.181336] bus_add_driver+0x127/0x240
[ 176.181340] driver_register+0x5e/0x130
[ 176.181343] ? __pfx_mptsas_init+0x10/0x10 [mptsas]
[ 176.181352] __pci_register_driver+0x62/0x70
[ 176.181356] mptsas_init+0x119/0xff0 [mptsas]
[ 176.181365] do_one_initcall+0x5b/0x340
[ 176.181371] do_init_module+0x68/0x260
[ 176.181375] load_module+0xba1/0xcf0
[ 176.181380] ? vfree+0xff/0x2d0
[ 176.181385] init_module_from_file+0x96/0x100
[ 176.181388] ? init_module_from_file+0x96/0x100
[ 176.181394] idempotent_init_module+0x11c/0x2b0
[ 176.181399] __x64_sys_finit_module+0x64/0xd0
[ 176.181402] do_syscall_64+0x59/0x90
[ 176.181409] ? exit_to_user_mode_prepare+0x30/0xb0
[ 176.181413] ? syscall_exit_to_user_mode+0x37/0x60
[ 176.181417] ? do_syscall_64+0x68/0x90
[ 176.181421] ? syscall_exit_to_user_mode+0x37/0x60
[ 176.181424] ? do_syscall_64+0x68/0x90
[ 176.181428] entry_SYSCALL_64_after_hwframe+0x6e/0xd8
[ 176.181432] RIP: 0033:0x7f847a725c5d
[ 176.181441] Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8b 71 13 00 f7 d8 64 89 01 48
[ 176.181481] RSP: 002b:00007fff6734e878 EFLAGS: 00000246 ORIG_RAX: 0000000000000139
[ 176.181484] RAX: ffffffffffffffda RBX: 0000563ba212a6b0 RCX: 00007f847a725c5d
[ 176.181486] RDX: 0000000000000004 RSI: 00007f847aa0144a RDI: 000000000000000d
[ 176.181488] RBP: 00007f847aa0144a R08: 0000000000000040 R09: fffffffffffffde0
[ 176.181490] R10: fffffffffffffe18 R11: 0000000000000246 R12: 0000000000020000
[ 176.181526] R13: 0000563ba2216ae0 R14: 0000000000000000 R15: 0000563ba20dff90
[ 176.181531] </TASK>
[ 176.181532] ================================================================================
---
ProblemType: Bug
ApportVersion: 2.27.0-0ubuntu2
Architecture: amd64
AudioDevicesInUse:
 USER PID ACCESS COMMAND
 /dev/snd/seq: vmware 950 F.... pipewire
CRDA: N/A
CasperMD5CheckResult: unknown
CurrentDesktop: ubuntu:GNOME
DistroRelease: Ubuntu 23.10
InstallationDate: Installed on 2023-09-26 (0 days ago)
InstallationMedia: Ubuntu 23.10 "Mantic Minotaur" - Beta amd64 (20230919.1)
IwConfig:
 lo no wireless extensions.

 ens33 no wireless extensions.
Lsusb: Error: command ['lsusb'] failed with exit code 1:
Lsusb-t:

Lsusb-v: Error: command ['lsusb', '-v'] failed with exit code 1:
MachineType: {report['dmi.sys.vendor']} {report['dmi.product.name']}
Package: linux (not installed)
ProcEnviron:
 LANG=en_US.UTF-8
 PATH=(custom, no user)
 SHELL=/bin/bash
 TERM=xterm-256color
ProcFB: 0 vmwgfxdrmfb
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-6.5.0-5-generic root=UUID=e70caf6c-4fa5-4fd6-9a60-61d851a337f9 ro quiet splash vt.handoff=7
ProcVersionSignature: Ubuntu 6.5.0-5.5-generic 6.5.0
RelatedPackageVersions:
 linux-restricted-modules-6.5.0-5-generic N/A
 linux-backports-modules-6.5.0-5-generic N/A
 linux-firmware 20230919.git3672ccab-0ubuntu2
RfKill:

Tags: mantic
Uname: Linux 6.5.0-5-generic x86_64
UpgradeStatus: No upgrade log present (probably fresh install)
UserGroups: N/A
_MarkForUpload: True
dmi.bios.date: 05/22/2023
dmi.bios.vendor: VMware, Inc.
dmi.bios.version: VMW201.00V.21805430.B64.2305221830
dmi.board.name: 440BX Desktop Reference Platform
dmi.board.vendor: Intel Corporation
dmi.board.version: None
dmi.chassis.asset.tag: No Asset Tag
dmi.chassis.type: 1
dmi.chassis.vendor: No Enclosure
dmi.chassis.version: N/A
dmi.modalias: dmi:bvnVMware,Inc.:bvrVMW201.00V.21805430.B64.2305221830:bd05/22/2023:svnVMware,Inc.:pnVMware20,1:pvrNone:rvnIntelCorporation:rn440BXDesktopReferencePlatform:rvrNone:cvnNoEnclosure:ct1:cvrN/A:sku:
dmi.product.name: VMware20,1
dmi.product.version: None
dmi.sys.vendor: VMware, Inc.

Yan Jin (yanjin-vmw)
description: updated
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Missing required logs.

This bug is missing log files that will aid in diagnosing the problem. While running an Ubuntu kernel (not a mainline or third-party kernel) please enter the following command in a terminal window:

apport-collect 2037490

and then change the status of the bug to 'Confirmed'.

If, due to the nature of the issue you have encountered, you are unable to run this command, please add a comment stating that fact and change the bug status to 'Confirmed'.

This change has been made by an automated script, maintained by the Ubuntu Kernel Team.

Changed in linux (Ubuntu):
status: New → Incomplete
Revision history for this message
Yan Jin (yanjin-vmw) wrote : AlsaInfo.txt

apport information

tags: added: apport-collected mantic
description: updated
Revision history for this message
Yan Jin (yanjin-vmw) wrote : CurrentDmesg.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : Lspci.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : Lspci-vt.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : ProcCpuinfo.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : ProcCpuinfoMinimal.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : ProcInterrupts.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : ProcModules.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : UdevDb.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : WifiSyslog.txt

apport information

Revision history for this message
Yan Jin (yanjin-vmw) wrote : acpidump.txt

apport information

Changed in linux (Ubuntu):
status: Incomplete → Confirmed
Revision history for this message
Juerg Haefliger (juergh) wrote : Re: "call trace" is reported for mptsas driver
tags: added: kernel-flexible-array
Juerg Haefliger (juergh)
summary: - "call trace" is reported for mptsas driver
+ UBSAN: array-index-out-of-bounds in /build/linux-
+ IPoq5q/linux-6.5.0/drivers/message/fusion/mptsas.c
Revision history for this message
Yan Jin (yanjin-vmw) wrote :

This issue exists in ubuntu 22.04 desktop after the kernel is upgraded to Linux version 6.5.0-15-generic.

Revision history for this message
Yan Jin (yanjin-vmw) wrote :
Download full text (3.5 KiB)

[ 7.182980] ================================================================================
[ 7.187100] UBSAN: array-index-out-of-bounds in /build/linux-hwe-6.5-BV4m5T/linux-hwe-6.5-6.5.0/drivers/message/fusion/mptsas.c:2446:22
[ 7.192943] index 1 is out of range for type 'MPI_SAS_IO_UNIT0_PHY_DATA [1]'
[ 7.196248] CPU: 0 PID: 116 Comm: systemd-udevd Not tainted 6.5.0-15-generic #15~22.04.1-Ubuntu
[ 7.196253] Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.23175959.B64.2401231913 01/23/2024
[ 7.196255] Call Trace:
[ 7.196268] <TASK>
[ 7.196271] dump_stack_lvl+0x48/0x70
[ 7.196321] dump_stack+0x10/0x20
[ 7.196324] __ubsan_handle_out_of_bounds+0xc6/0x110
[ 7.196363] mptsas_sas_io_unit_pg0+0x3d9/0x3f0 [mptsas]
[ 7.196375] mptsas_probe_hba_phys.isra.0+0x55/0x4a0 [mptsas]
[ 7.196382] ? __pfx_scsi_runtime_idle+0x10/0x10
[ 7.196421] ? rpm_idle+0x1dc/0x2b0
[ 7.196443] mptsas_scan_sas_topology+0x32/0x210 [mptsas]
[ 7.196450] ? scsi_autopm_put_host+0x1a/0x30
[ 7.196454] mptsas_probe.part.0+0x3cc/0x570 [mptsas]
[ 7.196490] mptsas_probe+0x1e/0x30 [mptsas]
[ 7.196496] local_pci_probe+0x44/0xb0
[ 7.196510] pci_call_probe+0x55/0x190
[ 7.196514] pci_device_probe+0x84/0x120
[ 7.196518] really_probe+0x1c9/0x430
[ 7.196522] __driver_probe_device+0x8c/0x190
[ 7.196525] driver_probe_device+0x24/0xd0
[ 7.196527] __driver_attach+0x10b/0x210
[ 7.196529] ? __pfx___driver_attach+0x10/0x10
[ 7.196532] bus_for_each_dev+0x8a/0xf0
[ 7.196537] driver_attach+0x1e/0x30
[ 7.196541] bus_add_driver+0x127/0x240
[ 7.196545] driver_register+0x5e/0x130
[ 7.196548] ? __pfx_mptsas_init+0x10/0x10 [mptsas]
[ 7.196555] __pci_register_driver+0x62/0x70
[ 7.196558] mptsas_init+0x119/0xff0 [mptsas]
[ 7.196565] do_one_initcall+0x5b/0x340
[ 7.196572] do_init_module+0x68/0x260
[ 7.196577] load_module+0xb85/0xcd0
[ 7.196581] ? security_kernel_post_read_file+0x75/0x90
[ 7.196585] ? security_kernel_post_read_file+0x75/0x90
[ 7.196589] init_module_from_file+0x96/0x100
[ 7.196592] ? init_module_from_file+0x96/0x100
[ 7.196598] idempotent_init_module+0x11c/0x2b0
[ 7.196603] __x64_sys_finit_module+0x64/0xd0
[ 7.196607] do_syscall_64+0x58/0x90
[ 7.196651] ? do_syscall_64+0x67/0x90
[ 7.196665] ? exit_to_user_mode_prepare+0x30/0xb0
[ 7.196671] ? syscall_exit_to_user_mode+0x37/0x60
[ 7.196676] ? do_syscall_64+0x67/0x90
[ 7.196679] ? exit_to_user_mode_prepare+0x30/0xb0
[ 7.196682] ? syscall_exit_to_user_mode+0x37/0x60
[ 7.196686] ? do_syscall_64+0x67/0x90
[ 7.196689] entry_SYSCALL_64_after_hwframe+0x6e/0xd8
[ 7.196711] RIP: 0033:0x7fcdf8abfa3d
[ 7.196717] Code: 5b 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d c3 a3 0f 00 f7 d8 64 89 01 48
[ 7.196720] RSP: 002b:00007ffc7355f6c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000139
[ 7.196723] RAX: ffffffffffffffda RBX: 000055b90bf7a020 RCX: 00007fcdf8abfa3d
[ 7.196725] RDX: 0000000000000000 RSI: 00007fc...

Read more...

Revision history for this message
Steven Han (nazgul33) wrote :
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.