Good day, dear maintainers, We found a bug using a modified kernel configuration file used by syzbot. We enhanced the coverage of the configuration file using our tool, klocalizer. Kernel Branch: 6.2.0-rc5-next-20230124 Kernel config: https://drive.google.com/file/d/1MZSgIF4R9QfikEuF5siUIZVPce-GiJQK/view?usp=sharing Reproducer: https://drive.google.com/file/d/1L03M-21V_CDlUX3Q281GkLyC5Oxeh3Pg/view?usp=sharing Thank you! Best regards, Sanan Hasanov ------------[ cut here ]------------ WARNING: CPU: 3 PID: 29148 at mm/mmap.c:2167 __split_vma+0x5fc/0x780 mm/mmap.c:2167 Modules linked in: CPU: 3 PID: 29148 Comm: syz-executor.6 Not tainted 6.2.0-rc5-next-20230124 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:__split_vma+0x5fc/0x780 mm/mmap.c:2167 Code: aa 22 c3 ff 4c 89 f7 e8 a2 11 8c ff e9 26 ff ff ff 41 bc f4 ff ff ff eb e6 e8 90 22 c3 ff 0f 0b e9 ac fa ff ff e8 84 22 c3 ff <0f> 0b e9 e1 fa ff ff e8 78 22 c3 ff 48 8b 54 24 08 48 b8 00 00 00 RSP: 0018:ffffc9000b1d78f0 EFLAGS: 00010246 RAX: 0000000000040000 RBX: ffff88810f524bd0 RCX: ffffc90003d89000 RDX: 0000000000040000 RSI: ffffffff81bbc3fc RDI: 0000000000000006 RBP: 0000000020ffd000 R08: 0000000000000006 R09: 0000000020ffd000 R10: 0000000020ffd000 R11: 0000000000000001 R12: 0000000020ffd000 R13: 1ffff9200163af22 R14: 0000000020ffd000 R15: ffffc9000b1d7cc0 FS: 00007f70ff656700(0000) GS:ffff888119d80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f6622840260 CR3: 000000007d1bc000 CR4: 0000000000350ee0 Call Trace: <TASK> do_vmi_align_munmap+0x223/0xbb0 mm/mmap.c:2305 do_vmi_munmap+0x26c/0x2c0 mm/mmap.c:2451 move_vma+0x7c2/0xf30 mm/mremap.c:704 __do_sys_mremap+0x48c/0x17f0 mm/mremap.c:1095 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x39/0x80 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd RIP: 0033:0x7f70fe48edcd Code: 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f70ff655bf8 EFLAGS: 00000246 ORIG_RAX: 0000000000000019 RAX: ffffffffffffffda RBX: 00007f70fe5bbf80 RCX: 00007f70fe48edcd RDX: 0000000000001000 RSI: 0000000000001000 RDI: 0000000020003000 RBP: 00007f70ff655c50 R08: 0000000020ffd000 R09: 0000000000000000 R10: 0000000000000007 R11: 0000000000000246 R12: 000000000000000e R13: 00007ffe16c8ac1f R14: 00007ffe16c8adc0 R15: 00007f70ff655d80 </TASK> irq event stamp: 1113 hardirqs last enabled at (1121): [<ffffffff8163e2e2>] console_emit_next_record kernel/printk/printk.c:2893 [inline] hardirqs last enabled at (1121): [<ffffffff8163e2e2>] console_flush_all+0x902/0xd10 kernel/printk/printk.c:2942 hardirqs last disabled at (1132): [<ffffffff8997e59c>] __schedule+0x2f1c/0x5a70 kernel/sched/core.c:6518 softirqs last enabled at (922): [<ffffffff814a50bd>] invoke_softirq kernel/softirq.c:445 [inline] softirqs last enabled at (922): [<ffffffff814a50bd>] __irq_exit_rcu+0x11d/0x190 kernel/softirq.c:650 softirqs last disabled at (771): [<ffffffff814a50bd>] invoke_softirq kernel/softirq.c:445 [inline] softirqs last disabled at (771): [<ffffffff814a50bd>] __irq_exit_rcu+0x11d/0x190 kernel/softirq.c:650 ---[ end trace 0000000000000000 ]---