[ 836.282216][T23538] test_team2: Mode changed to "roundrobin"
[ 836.317761][T23539] test_team2: Port device eth0 added
[ 836.358202][T23540] test_team2: Port device eth1 added
[ 836.386274][T23541] 8021q: adding VLAN 0 to HW filter on device test_team2
[ 836.615344][T23549] test_team1: Mode changed to "broadcast"
[ 836.648746][T23550] test_team1: Port device eth0 added
[ 836.684732][T23551] test_team1: Port device eth1 added
[ 836.717478][T23552] 8021q: adding VLAN 0 to HW filter on device test_team1
[ 837.837464][ C1] ==================================================================
[ 837.837970][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 837.838578][ C1] Read of size 8 at addr ff1100000c8be708 by task iperf3/23557
[ 837.839109][ C1]
[ 837.839290][ C1] CPU: 1 UID: 0 PID: 23557 Comm: iperf3 Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 837.839296][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 837.839299][ C1] Call Trace:
[ 837.839304][ C1]
[ 837.839306][ C1] dump_stack_lvl+0x6f/0xa0
[ 837.839319][ C1] print_address_description.constprop.0+0x56/0x2d0
[ 837.839330][ C1] print_report+0xfc/0x1fa
[ 837.839333][ C1] ? __virt_addr_valid+0x102/0x440
[ 837.839337][ C1] ? __virt_addr_valid+0x1da/0x440
[ 837.839341][ C1] kasan_report+0x108/0x130
[ 837.839344][ C1] ? tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 837.839349][ C1] ? tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 837.839355][ C1] kasan_check_range+0x130/0x200
[ 837.839360][ C1] tcp_v6_send_response.isra.0+0xd46/0x1cb0
[ 837.839368][ C1] ? rcu_lockdep_current_cpu_online+0x3f/0x1b0
[ 837.839376][ C1] ? __xfrm_policy_check2.constprop.0+0x720/0x720
[ 837.839384][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 837.839388][ C1] ? rcu_is_watching+0x16/0xd0
[ 837.839391][ C1] ? mark_held_locks+0x40/0x70
[ 837.839394][ C1] tcp_v6_rcv+0x21c9/0x2de0
[ 837.839402][ C1] ? tcp_v6_syn_recv_sock+0x1ab0/0x1ab0
[ 837.839408][ C1] ? ipv6_raw_deliver+0x323/0x890
[ 837.839416][ C1] ? ipv6_raw_deliver+0x32d/0x890
[ 837.839422][ C1] ip6_protocol_deliver_rcu+0x15a/0x1290
[ 837.839431][ C1] ? rcu_is_watching+0x16/0xd0
[ 837.839435][ C1] ? process_backlog+0x3f1/0x14c0
[ 837.839439][ C1] ip6_input+0x223/0x5f0
[ 837.839442][ C1] __netif_receive_skb_one_core+0xfc/0x180
[ 837.839444][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 837.839447][ C1] ? process_backlog+0x3f1/0x14c0
[ 837.839453][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 837.839457][ C1] ? rcu_is_watching+0x16/0xd0
[ 837.839462][ C1] process_backlog+0x431/0x14c0
[ 837.839471][ C1] __napi_poll+0xa7/0x3b0
[ 837.839478][ C1] net_rx_action+0x513/0xf50
[ 837.839482][ C1] ? __napi_poll+0x3b0/0x3b0
[ 837.839485][ C1] ? __print_lock_name+0x80/0x80
[ 837.839491][ C1] ? ktime_get_update_offsets_now+0x2a8/0x490
[ 837.839495][ C1] ? mark_held_locks+0x40/0x70
[ 837.839499][ C1] handle_softirqs+0x1d3/0x900
[ 837.839504][ C1] ? _local_bh_enable+0xc0/0xc0
[ 837.839507][ C1] ? do_raw_spin_unlock+0x59/0x250
[ 837.839509][ C1] ? rcu_is_watching+0x16/0xd0
[ 837.839513][ C1] do_softirq+0xac/0xe0
[ 837.839520][ C1]
[ 837.839521][ C1]
[ 837.839522][ C1] ? __dev_queue_xmit+0x93b/0x1a20
[ 837.839528][ C1] __local_bh_enable_ip+0x118/0x150
[ 837.839532][ C1] __dev_queue_xmit+0x950/0x1a20
[ 837.839541][ C1] ? __lock_acquire+0x518/0xc20
[ 837.839545][ C1] ? netdev_core_pick_tx+0x2d0/0x2d0
[ 837.839547][ C1] ? __lock_acquire+0xc00/0xc20
[ 837.839550][ C1] ? find_held_lock+0x2b/0x80
[ 837.839552][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 837.839555][ C1] ? rcu_is_watching+0x16/0xd0
[ 837.839557][ C1] ? mark_held_locks+0x40/0x70
[ 837.839560][ C1] ? __asan_memcpy+0x3c/0x60
[ 837.839563][ C1] ? neigh_hh_output+0x152/0x4c0
[ 837.839568][ C1] ip6_finish_output+0x1f1/0xc50
[ 837.839576][ C1] ip6_output+0x186/0x4a0
[ 837.839582][ C1] ip6_xmit+0xb66/0x1930
[ 837.839590][ C1] ? ip6_autoflowlabel+0x120/0x120
[ 837.839596][ C1] ? __lock_acquire+0x518/0xc20
[ 837.839600][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 837.839603][ C1] ? inet6_csk_xmit+0xfe/0x5e0
[ 837.839606][ C1] ? rcu_is_watching+0x16/0xd0
[ 837.839608][ C1] ? lock_acquire+0x13c/0x160
[ 837.839612][ C1] inet6_csk_xmit+0x2ea/0x5e0
[ 837.839616][ C1] __tcp_transmit_skb+0x1ad9/0x3a70
[ 837.839627][ C1] ? __tcp_select_window+0xf20/0xf20
[ 837.839633][ C1] ? tcp_mtu_probe+0x19/0x1b60
[ 837.839640][ C1] tcp_write_xmit+0x1002/0x3710
[ 837.839649][ C1] ? tcp_current_mss+0x180/0x310
[ 837.839652][ C1] ? tcp_retrans_try_collapse+0xee0/0xee0
[ 837.839656][ C1] ? tcp_set_state+0x101/0x580
[ 837.839661][ C1] __tcp_push_pending_frames+0x8f/0x3b0
[ 837.839664][ C1] __tcp_close+0x84e/0xe70
[ 837.839668][ C1] tcp_close+0x23/0xb0
[ 837.839671][ C1] inet_release+0x10a/0x240
[ 837.839674][ C1] ? fcntl_setlk+0xc80/0xc80
[ 837.839683][ C1] __sock_release+0xb8/0x280
[ 837.839690][ C1] sock_close+0x18/0x20
[ 837.839694][ C1] __fput+0x363/0xac0
[ 837.839704][ C1] fput_close_sync+0xde/0x1b0
[ 837.839707][ C1] ? alloc_file_clone+0xe0/0xe0
[ 837.839710][ C1] ? do_raw_spin_unlock+0x59/0x250
[ 837.839714][ C1] __x64_sys_close+0x8b/0xf0
[ 837.839716][ C1] do_syscall_64+0xff/0x530
[ 837.839719][ C1] ? exc_page_fault+0xee/0x100
[ 837.839723][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 837.839727][ C1] RIP: 0033:0x7f18a6610312
[ 837.839731][ C1] Code: 08 0f 85 71 41 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 bf 01 00
[ 837.839737][ C1] RSP: 002b:00007ffd57ca0298 EFLAGS: 00000246 ORIG_RAX: 0000000000000003
[ 837.839742][ C1] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f18a6610312
[ 837.839747][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000007
[ 837.839749][ C1] RBP: 00007ffd57ca02c0 R08: 0000000000000000 R09: 0000000000000000
[ 837.839751][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 000055826a385010
[ 837.839752][ C1] R13: 000055826a385338 R14: 000055826a385218 R15: 000055826a385010
[ 837.839758][ C1]
[ 837.839761][ C1]
[ 837.872630][ C1] The buggy address belongs to the object at ff1100000c8be668
[ 837.872630][ C1] which belongs to the cache tw_sock_TCPv6 of size 280
[ 837.873518][ C1] The buggy address is located 160 bytes inside of
[ 837.873518][ C1] allocated 280-byte region [ff1100000c8be668, ff1100000c8be780)
[ 837.874442][ C1]
[ 837.874620][ C1] The buggy address belongs to the physical page:
[ 837.875061][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000c8be338 pfn:0xc8be
[ 837.875643][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 837.876165][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 837.876559][ C1] page_type: f5(slab)
[ 837.876794][ C1] raw: 0080000000000240 ff11000005db79c0 ff11000005dc2d08 ff11000005dc2d08
[ 837.877414][ C1] raw: ff1100000c8be338 0000000000140002 00000000f5000000 0000000000000000
[ 837.878022][ C1] head: 0080000000000240 ff11000005db79c0 ff11000005dc2d08 ff11000005dc2d08
[ 837.878638][ C1] head: ff1100000c8be338 0000000000140002 00000000f5000000 0000000000000000
[ 837.879224][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 837.879737][ C1] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 837.880319][ C1] page dumped because: kasan: bad access detected
[ 837.880688][ C1]
[ 837.880863][ C1] Memory state around the buggy address:
[ 837.881218][ C1] ff1100000c8be600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 837.881724][ C1] ff1100000c8be680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 837.882229][ C1] >ff1100000c8be700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 837.882725][ C1] ^
[ 837.882996][ C1] ff1100000c8be780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 837.883399][ C1] ff1100000c8be800: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 837.883884][ C1] ==================================================================
[ 837.884338][ C1] Disabling lock debugging due to kernel taint
[ 837.989585][T23563] eth0: entered promiscuous mode
[ 838.995833][T23570] eth1: entered promiscuous mode
[ 840.992098][T23563] eth0: left promiscuous mode
[ 841.035391][T23570] eth1: left promiscuous mode
[ 841.328852][T23594] eth0: entered promiscuous mode
[ 842.352818][T23599] eth1: entered promiscuous mode
[ 844.337882][T23594] eth0: left promiscuous mode
[ 844.377550][T23599] eth1: left promiscuous mode
[ 844.679627][T23623] eth0: entered promiscuous mode
[ 845.707805][T23628] eth1: entered promiscuous mode
[ 847.699320][T23623] eth0: left promiscuous mode
[ 847.733980][T23628] eth1: left promiscuous mode
[ 847.925869][T23645] test_team1: Port device eth0 removed
[ 847.943609][T23646] test_team1: Port device eth1 removed
[ 848.015764][T23649] test_team1: Mode changed to "roundrobin"
[ 848.036842][T23650] test_team1: Port device eth0 added
[ 848.063838][T23651] test_team1: Port device eth1 added
[ 848.084550][T23652] 8021q: adding VLAN 0 to HW filter on device test_team1
[ 849.227685][T23663] eth0: entered promiscuous mode
[ 850.253935][T23670] eth1: entered promiscuous mode
[ 852.234340][T23663] eth0: left promiscuous mode
[ 852.283783][T23670] eth1: left promiscuous mode
[ 852.591478][T23694] eth0: entered promiscuous mode
[ 853.623631][T23699] eth1: entered promiscuous mode
[ 855.608765][T23694] eth0: left promiscuous mode
[ 855.653331][T23699] eth1: left promiscuous mode
[ 855.943811][T23723] eth0: entered promiscuous mode
[ 856.961251][T23728] eth1: entered promiscuous mode
[ 858.956615][T23723] eth0: left promiscuous mode
[ 858.995789][T23728] eth1: left promiscuous mode
[ 859.151065][T23745] test_team1: Port device eth0 removed
[ 859.171842][T23746] test_team1: Port device eth1 removed
[ 859.240807][T23749] test_team1: Mode changed to "random"
[ 859.257980][T23750] test_team1: Port device eth0 added
[ 859.282367][T23751] test_team1: Port device eth1 added
[ 859.298656][T23752] 8021q: adding VLAN 0 to HW filter on device test_team1
[ 860.435111][T23763] eth0: entered promiscuous mode
[ 861.459133][T23770] eth1: entered promiscuous mode
[ 863.447188][T23763] eth0: left promiscuous mode
[ 863.490758][T23770] eth1: left promiscuous mode
[ 863.779640][T23794] eth0: entered promiscuous mode
[ 864.794956][T23799] eth1: entered promiscuous mode
[ 866.793552][T23794] eth0: left promiscuous mode
[ 866.839519][T23799] eth1: left promiscuous mode
[ 867.141261][T23823] eth0: entered promiscuous mode
[ 868.173174][T23828] eth1: entered promiscuous mode
[ 870.152882][T23823] eth0: left promiscuous mode
[ 870.192684][T23828] eth1: left promiscuous mode
[ 870.397246][T22491] test_team1 (unregistering): Port device eth0 removed
[ 870.398642][T22491] test_team1 (unregistering): Port device eth1 removed
[ 870.402815][T22491] test_team2: Port device eth1 removed
[ 870.405436][T22491] test_team2: Port device eth0 removed