[ 329.459153][ C0] ==================================================================
[ 329.459445][ C0] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 329.459727][ C0] Read of size 8 at addr ff110000095d8bd0 by task iperf3/3537
[ 329.459971][ C0]
[ 329.460053][ C0] CPU: 0 UID: 0 PID: 3537 Comm: iperf3 Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 329.460057][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 329.460059][ C0] Call Trace:
[ 329.460060][ C0]
[ 329.460062][ C0] dump_stack_lvl+0x6f/0xa0
[ 329.460067][ C0] print_address_description.constprop.0+0x56/0x2d0
[ 329.460071][ C0] print_report+0xfc/0x1fa
[ 329.460073][ C0] ? __virt_addr_valid+0x102/0x440
[ 329.460077][ C0] ? __virt_addr_valid+0x1da/0x440
[ 329.460079][ C0] kasan_report+0x108/0x130
[ 329.460082][ C0] ? tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 329.460084][ C0] ? tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 329.460086][ C0] kasan_check_range+0x130/0x200
[ 329.460088][ C0] tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 329.460090][ C0] ? rcu_lockdep_current_cpu_online+0x3f/0x1b0
[ 329.460094][ C0] ? __xfrm_policy_check2.constprop.0+0x720/0x720
[ 329.460096][ C0] ? clock_was_set+0x6a5/0xa10
[ 329.460099][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 329.460102][ C0] ? rcu_is_watching+0x16/0xd0
[ 329.460104][ C0] ? mark_held_locks+0x40/0x70
[ 329.460106][ C0] tcp_v6_rcv+0x21c9/0x2de0
[ 329.460110][ C0] ? tcp_v6_syn_recv_sock+0x1ab0/0x1ab0
[ 329.460112][ C0] ? ipv6_raw_deliver+0x323/0x890
[ 329.460114][ C0] ? ipv6_raw_deliver+0x32d/0x890
[ 329.460117][ C0] ip6_protocol_deliver_rcu+0x15a/0x1290
[ 329.460120][ C0] ? rcu_is_watching+0x16/0xd0
[ 329.460122][ C0] ? process_backlog+0x3f1/0x14c0
[ 329.460126][ C0] ip6_input+0x223/0x5f0
[ 329.460128][ C0] __netif_receive_skb_one_core+0xfc/0x180
[ 329.460130][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 329.460131][ C0] ? process_backlog+0x3f1/0x14c0
[ 329.460133][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 329.460135][ C0] ? rcu_is_watching+0x16/0xd0
[ 329.460137][ C0] process_backlog+0x431/0x14c0
[ 329.460139][ C0] __napi_poll+0xa7/0x3b0
[ 329.460141][ C0] net_rx_action+0x513/0xf50
[ 329.460144][ C0] ? __napi_poll+0x3b0/0x3b0
[ 329.460146][ C0] ? find_held_lock+0x2b/0x80
[ 329.460150][ C0] ? mark_held_locks+0x40/0x70
[ 329.460152][ C0] handle_softirqs+0x1d3/0x900
[ 329.460156][ C0] ? _local_bh_enable+0xc0/0xc0
[ 329.460157][ C0] ? rcu_is_watching+0x16/0xd0
[ 329.460159][ C0] ? trace_csd_function_exit+0xb3/0x180
[ 329.460162][ C0] do_softirq+0xac/0xe0
[ 329.460164][ C0]
[ 329.460164][ C0]
[ 329.460165][ C0] ? __dev_queue_xmit+0x93b/0x1a20
[ 329.460167][ C0] __local_bh_enable_ip+0x118/0x150
[ 329.460169][ C0] __dev_queue_xmit+0x950/0x1a20
[ 329.460171][ C0] ? __lock_acquire+0x518/0xc20
[ 329.460173][ C0] ? netdev_core_pick_tx+0x2d0/0x2d0
[ 329.460175][ C0] ? __lock_acquire+0xc00/0xc20
[ 329.460176][ C0] ? find_held_lock+0x2b/0x80
[ 329.460178][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 329.460180][ C0] ? rcu_is_watching+0x16/0xd0
[ 329.460182][ C0] ? mark_held_locks+0x40/0x70
[ 329.460183][ C0] ? __asan_memcpy+0x3c/0x60
[ 329.460185][ C0] ? neigh_hh_output+0x152/0x4c0
[ 329.460188][ C0] ip6_finish_output+0x1f1/0xc50
[ 329.460190][ C0] ip6_output+0x186/0x4a0
[ 329.460192][ C0] ip6_xmit+0xb66/0x1930
[ 329.460196][ C0] ? ip6_autoflowlabel+0x120/0x120
[ 329.460197][ C0] ? __lock_acquire+0x518/0xc20
[ 329.460200][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 329.460201][ C0] ? inet6_csk_xmit+0xfe/0x5e0
[ 329.460204][ C0] ? rcu_is_watching+0x16/0xd0
[ 329.460205][ C0] ? lock_acquire+0x13c/0x160
[ 329.460207][ C0] inet6_csk_xmit+0x2ea/0x5e0
[ 329.460210][ C0] __tcp_transmit_skb+0x1ad9/0x3a70
[ 329.460215][ C0] ? __tcp_select_window+0xf20/0xf20
[ 329.460216][ C0] ? tcp_mtu_probe+0x19/0x1b60
[ 329.460219][ C0] tcp_write_xmit+0x1002/0x3710
[ 329.460222][ C0] ? tcp_current_mss+0x180/0x310
[ 329.460224][ C0] ? tcp_retrans_try_collapse+0xee0/0xee0
[ 329.460226][ C0] ? tcp_set_state+0x101/0x580
[ 329.460230][ C0] __tcp_push_pending_frames+0x8f/0x3b0
[ 329.460232][ C0] __tcp_close+0x84e/0xe70
[ 329.460234][ C0] tcp_close+0x23/0xb0
[ 329.460242][ C0] inet_release+0x10a/0x240
[ 329.460244][ C0] ? fcntl_setlk+0xc80/0xc80
[ 329.460248][ C0] __sock_release+0xb8/0x280
[ 329.460250][ C0] sock_close+0x18/0x20
[ 329.460252][ C0] __fput+0x363/0xac0
[ 329.460255][ C0] fput_close_sync+0xde/0x1b0
[ 329.460257][ C0] ? alloc_file_clone+0xe0/0xe0
[ 329.460259][ C0] ? do_raw_spin_unlock+0x59/0x250
[ 329.460261][ C0] __x64_sys_close+0x8b/0xf0
[ 329.460262][ C0] do_syscall_64+0xff/0x530
[ 329.460264][ C0] ? exc_page_fault+0xee/0x100
[ 329.460267][ C0] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 329.460269][ C0] RIP: 0033:0x7fe804ea1312
[ 329.460272][ C0] Code: 08 0f 85 71 41 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 bf 01 00
[ 329.460274][ C0] RSP: 002b:00007ffdaecdd7d8 EFLAGS: 00000246 ORIG_RAX: 0000000000000003
[ 329.460278][ C0] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fe804ea1312
[ 329.460279][ C0] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000007
[ 329.460280][ C0] RBP: 00007ffdaecdd800 R08: 0000000000000000 R09: 0000000000000000
[ 329.460281][ C0] R10: 0000000000000000 R11: 0000000000000246 R12: 0000564660b83010
[ 329.460282][ C0] R13: 00005646319de020 R14: 0000000000000077 R15: 0000564660b83010
[ 329.460284][ C0]
[ 329.460285][ C0]
[ 329.477442][ C0] The buggy address belongs to the object at ff110000095d8b30
[ 329.477442][ C0] which belongs to the cache tw_sock_TCPv6 of size 280
[ 329.477915][ C0] The buggy address is located 160 bytes inside of
[ 329.477915][ C0] allocated 280-byte region [ff110000095d8b30, ff110000095d8c48)
[ 329.478391][ C0]
[ 329.478523][ C0] The buggy address belongs to the physical page:
[ 329.478714][ C0] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff110000095d8800 pfn:0x95d8
[ 329.479097][ C0] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 329.479401][ C0] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 329.479660][ C0] page_type: f5(slab)
[ 329.479780][ C0] raw: 0080000000000240 ff11000005dbf9c0 ff11000005dcad08 ff11000005dcad08
[ 329.480118][ C0] raw: ff110000095d8800 0000000000140005 00000000f5000000 0000000000000000
[ 329.480455][ C0] head: 0080000000000240 ff11000005dbf9c0 ff11000005dcad08 ff11000005dcad08
[ 329.480791][ C0] head: ff110000095d8800 0000000000140005 00000000f5000000 0000000000000000
[ 329.481126][ C0] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 329.481406][ C0] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 329.481739][ C0] page dumped because: kasan: bad access detected
[ 329.481989][ C0]
[ 329.482069][ C0] Memory state around the buggy address:
[ 329.482285][ C0] ff110000095d8a80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 329.482513][ C0] ff110000095d8b00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 329.482794][ C0] >ff110000095d8b80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 329.483023][ C0] ^
[ 329.483273][ C0] ff110000095d8c00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 329.483497][ C0] ff110000095d8c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 329.483777][ C0] ==================================================================
[ 329.484069][ C0] Disabling lock debugging due to kernel taint