===================================================== BUG: KMSAN: kernel-infoleak-after-free in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: kernel-infoleak-after-free in copy_to_user_iter lib/iov_iter.c:24 [inline] BUG: KMSAN: kernel-infoleak-after-free in iterate_ubuf include/linux/iov_iter.h:30 [inline] BUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance2 include/linux/iov_iter.h:300 [inline] BUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance include/linux/iov_iter.h:328 [inline] BUG: KMSAN: kernel-infoleak-after-free in _copy_to_iter+0xf0e/0x33f0 lib/iov_iter.c:185 instrument_copy_to_user include/linux/instrumented.h:114 [inline] copy_to_user_iter lib/iov_iter.c:24 [inline] iterate_ubuf include/linux/iov_iter.h:30 [inline] iterate_and_advance2 include/linux/iov_iter.h:300 [inline] iterate_and_advance include/linux/iov_iter.h:328 [inline] _copy_to_iter+0xf0e/0x33f0 lib/iov_iter.c:185 copy_page_to_iter+0x482/0x910 lib/iov_iter.c:362 copy_folio_to_iter include/linux/uio.h:204 [inline] filemap_read+0xcfd/0x2300 mm/filemap.c:2762 blkdev_read_iter+0x89f/0xb00 block/fops.c:833 new_sync_read fs/read_write.c:491 [inline] vfs_read+0x85a/0xf00 fs/read_write.c:572 ksys_read fs/read_write.c:715 [inline] __do_sys_read fs/read_write.c:724 [inline] __se_sys_read fs/read_write.c:722 [inline] __x64_sys_read+0x1fb/0x4d0 fs/read_write.c:722 x64_sys_call+0x39db/0x3db0 arch/x86/include/generated/asm/syscalls_64.h:1 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: slab_free_hook mm/slub.c:2307 [inline] slab_free mm/slub.c:4643 [inline] kfree+0x252/0xec0 mm/slub.c:4842 ieee80211_inform_bss+0x1415/0x1540 net/mac80211/scan.c:160 rdev_inform_bss net/wireless/rdev-ops.h:418 [inline] cfg80211_inform_single_bss_data+0x1858/0x2870 net/wireless/scan.c:2367 cfg80211_inform_bss_data+0x29b/0x7e70 net/wireless/scan.c:3222 cfg80211_inform_bss_frame_data+0x6cd/0xaa0 net/wireless/scan.c:3313 ieee80211_bss_info_update+0x8a4/0xaa0 net/mac80211/scan.c:226 ieee80211_scan_rx+0xa23/0xd70 net/mac80211/scan.c:355 __ieee80211_rx_handle_packet net/mac80211/rx.c:5179 [inline] ieee80211_rx_list+0x449a/0x6120 net/mac80211/rx.c:5416 ieee80211_rx_napi+0x84/0x400 net/mac80211/rx.c:5439 ieee80211_rx include/net/mac80211.h:5185 [inline] ieee80211_handle_queued_frames+0x14f/0x350 net/mac80211/main.c:441 ieee80211_tasklet_handler+0x25/0x30 net/mac80211/main.c:460 tasklet_action_common+0x35f/0xd70 kernel/softirq.c:829 tasklet_action+0x2d/0x40 kernel/softirq.c:855 handle_softirqs+0x166/0x6e0 kernel/softirq.c:579 run_ksoftirqd+0x29/0x50 kernel/softirq.c:968 smpboot_thread_fn+0x569/0xa30 kernel/smpboot.c:164 kthread+0xd5c/0xf00 kernel/kthread.c:464 ret_from_fork+0x1e0/0x310 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Bytes 202-207 of 512 are uninitialized Memory access of size 512 starts at ffff88803a45c000 Data copied to user address 00007fd4d2b95000 CPU: 0 UID: 0 PID: 6019 Comm: udevd Tainted: G W 6.16.0-rc1-syzkaller-00239-g08215f5486ec #0 PREEMPT(undef) Tainted: [W]=WARN Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 =====================================================