loop0: detected capacity change from 0 to 64 BUG: kernel NULL pointer dereference, address: 0000000000000040 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD eab4067 P4D eab4067 PUD dd6a067 PMD 0 Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 1 UID: 0 PID: 8201 Comm: syz-executor153 Not tainted 6.12.0-rc1 #5 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:hfs_find_init+0x2b/0xd0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/bfind.c:21 Code: 0f 1f 00 55 48 89 e5 41 55 41 54 49 89 f4 53 48 89 fb e8 58 43 9f ff 49 89 5c 24 10 be c0 0c 00 00 49 c7 44 24 18 00 00 00 00 <8b> 43 40 8d 7c 00 04 e8 d9 05 c4 ff 48 85 c0 0f 84 80 00 00 00 49 RSP: 0018:ffff8880120ff978 EFLAGS: 00010293 RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff81960dd1 RDX: ffff88800e1b4400 RSI: 0000000000000cc0 RDI: 0000000000000000 RBP: ffff8880120ff990 R08: ffff8880120ff988 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff8880120ff9a8 R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000004 FS: 0000555560bc73c0(0000) GS:ffff88807ee00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000040 CR3: 000000000e424000 CR4: 0000000000350ef0 Call Trace: <TASK> hfs_ext_read_extent+0x73/0x280 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/extent.c:200 hfs_get_block+0x23c/0x390 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/extent.c:366 block_read_full_folio+0x1ca/0x520 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/buffer.c:2401 hfs_read_folio+0x21/0x30 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/inode.c:34 filemap_read_folio+0x4c/0x140 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/mm/filemap.c:2367 do_read_cache_folio+0x1ac/0x300 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/mm/filemap.c:3825 do_read_cache_page data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/mm/filemap.c:3891 [inline] read_cache_page+0x38/0xb0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/mm/filemap.c:3900 read_mapping_page data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/include/linux/pagemap.h:1005 [inline] hfs_btree_open+0x1e7/0x690 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/btree.c:78 hfs_mdb_get+0x6c1/0x930 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/mdb.c:199 hfs_fill_super+0x420/0x900 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/super.c:407 mount_bdev+0x130/0x1a0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/super.c:1679 hfs_mount+0x39/0x50 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/super.c:457 legacy_get_tree+0x36/0xa0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/fs_context.c:662 vfs_get_tree+0x37/0x130 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/super.c:1800 do_new_mount data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/namespace.c:3507 [inline] path_mount+0xc4c/0x1100 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/namespace.c:3834 do_mount data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/namespace.c:3847 [inline] __do_sys_mount data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/namespace.c:4055 [inline] __se_sys_mount data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/namespace.c:4032 [inline] __x64_sys_mount+0x178/0x1c0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/namespace.c:4032 x64_sys_call+0x209b/0x20d0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/arch/x86/include/generated/asm/syscalls_64.h:166 do_syscall_x64 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/arch/x86/entry/common.c:52 [inline] do_syscall_64+0x9e/0x1d0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fc03b79f4ee Code: 48 c7 c0 ff ff ff ff eb aa e8 fe 06 00 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 f3 0f 1e fa 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffca88dfd18 EFLAGS: 00000286 ORIG_RAX: 00000000000000a5 RAX: ffffffffffffffda RBX: 0000555560bc7378 RCX: 00007fc03b79f4ee RDX: 0000000020000240 RSI: 0000000020000040 RDI: 00007ffca88dfd30 RBP: 00007ffca88dfd30 R08: 00007ffca88dfd70 R09: 0000000000000256 R10: 0000000003008800 R11: 0000000000000286 R12: 0000000003008800 R13: 00007ffca88dfd70 R14: 0000000000000003 R15: 0000000000000000 </TASK> Modules linked in: CR2: 0000000000000040 ---[ end trace 0000000000000000 ]--- RIP: 0010:hfs_find_init+0x2b/0xd0 data/ghui/docker_data/linux_kernel/upstream/linux_v6.11/fs/hfs/bfind.c:21 Code: 0f 1f 00 55 48 89 e5 41 55 41 54 49 89 f4 53 48 89 fb e8 58 43 9f ff 49 89 5c 24 10 be c0 0c 00 00 49 c7 44 24 18 00 00 00 00 <8b> 43 40 8d 7c 00 04 e8 d9 05 c4 ff 48 85 c0 0f 84 80 00 00 00 49 RSP: 0018:ffff8880120ff978 EFLAGS: 00010293 RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff81960dd1 RDX: ffff88800e1b4400 RSI: 0000000000000cc0 RDI: 0000000000000000 RBP: ffff8880120ff990 R08: ffff8880120ff988 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff8880120ff9a8 R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000004 FS: 0000555560bc73c0(0000) GS:ffff88807ee00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000040 CR3: 000000000e424000 CR4: 0000000000350ef0 ---------------- Code disassembly (best guess): 0: 0f 1f 00 nopl (%rax) 3: 55 push %rbp 4: 48 89 e5 mov %rsp,%rbp 7: 41 55 push %r13 9: 41 54 push %r12 b: 49 89 f4 mov %rsi,%r12 e: 53 push %rbx f: 48 89 fb mov %rdi,%rbx 12: e8 58 43 9f ff call 0xff9f436f 17: 49 89 5c 24 10 mov %rbx,0x10(%r12) 1c: be c0 0c 00 00 mov $0xcc0,%esi 21: 49 c7 44 24 18 00 00 movq $0x0,0x18(%r12) 28: 00 00 * 2a: 8b 43 40 mov 0x40(%rbx),%eax <-- trapping instruction 2d: 8d 7c 00 04 lea 0x4(%rax,%rax,1),%edi 31: e8 d9 05 c4 ff call 0xffc4060f 36: 48 85 c0 test %rax,%rax 39: 0f 84 80 00 00 00 je 0xbf 3f: 49 rex.WB