[ 481.518081][ T5365] lag1: Mode changed to "loadbalance" [ 481.555306][ T5367] 8021q: adding VLAN 0 to HW filter on device lag1 [ 481.819592][ T5375] lag1: Port device veth0 added [ 481.848817][ T5376] lag1: Port device veth6 added [ 482.006655][ T5384] 8021q: adding VLAN 0 to HW filter on device lag1 [ 482.535278][ T5408] lag4: Mode changed to "loadbalance" [ 482.572988][ T5409] 8021q: adding VLAN 0 to HW filter on device lag4 [ 482.740487][ T5417] lag4: Port device veth3 added [ 482.768796][ T5418] lag4: Port device veth5 added [ 482.892372][ T5424] 8021q: adding VLAN 0 to HW filter on device lag4 [ 483.392469][ T5447] lag2: Mode changed to "loadbalance" [ 483.424206][ T5448] 8021q: adding VLAN 0 to HW filter on device lag2 [ 483.598158][ T5456] lag2: Port device veth1 added [ 483.623711][ T5457] lag2: Port device veth7 added [ 483.897244][ T5473] br1: port 1(lag2.100) entered blocking state [ 483.897467][ T5473] br1: port 1(lag2.100) entered disabled state [ 483.897658][ T5473] lag2.100: entered allmulticast mode [ 483.897788][ T5473] lag2: entered allmulticast mode [ 483.897936][ T5473] veth1: entered allmulticast mode [ 483.898072][ T5473] veth7: entered allmulticast mode [ 483.899926][ T5473] lag2.100: entered promiscuous mode [ 483.900066][ T5473] lag2: entered promiscuous mode [ 483.900202][ T5473] veth1: entered promiscuous mode [ 483.900490][ T5473] veth7: entered promiscuous mode [ 484.082046][ T5480] br2: port 1(lag2.200) entered blocking state [ 484.082580][ T5480] br2: port 1(lag2.200) entered disabled state [ 484.082884][ T5480] lag2.200: entered allmulticast mode [ 484.086009][ T5480] lag2.200: entered promiscuous mode [ 484.178245][ T5484] br1: port 1(lag2.100) entered blocking state [ 484.178611][ T5484] br1: port 1(lag2.100) entered forwarding state [ 484.228372][ T5485] br2: port 1(lag2.200) entered blocking state [ 484.228710][ T5485] br2: port 1(lag2.200) entered forwarding state [ 484.451516][ T5493] lag3: Mode changed to "loadbalance" [ 484.490935][ T5494] 8021q: adding VLAN 0 to HW filter on device lag3 [ 484.695150][ T5502] lag3: Port device veth2 added [ 484.727164][ T5503] lag3: Port device veth4 added [ 495.047223][ T5592] veth7: left promiscuous mode [ 495.047589][ T5592] veth7: left allmulticast mode [ 495.048607][ T5592] lag2: Port device veth7 removed [ 509.704092][ T5655] veth7: entered promiscuous mode [ 509.704431][ T5655] veth7: entered allmulticast mode [ 509.705259][ T5655] lag2: Port device veth7 added [ 509.854747][ T5666] veth1: left promiscuous mode [ 509.855326][ T5666] veth1: left allmulticast mode [ 509.857552][ T5666] lag2: Port device veth1 removed [ 524.328237][ T61] br1: port 1(lag2.100) entered disabled state [ 524.330440][ T61] br2: port 1(lag2.200) entered disabled state [ 524.351940][ T5729] veth7: left promiscuous mode [ 524.352226][ T5729] veth7: left allmulticast mode [ 524.353201][ T5729] lag2: Port device veth7 removed [ 524.465902][ T5740] veth1: entered promiscuous mode [ 524.466212][ T5740] veth1: entered allmulticast mode [ 524.467861][ T5740] lag2: Port device veth1 added [ 524.482077][ T57] br1: port 1(lag2.100) entered blocking state [ 524.482328][ T57] br1: port 1(lag2.100) entered forwarding state [ 524.482953][ T57] br2: port 1(lag2.200) entered blocking state [ 524.483177][ T57] br2: port 1(lag2.200) entered forwarding state [ 524.594705][ T5751] veth7: entered promiscuous mode [ 524.594988][ T5751] veth7: entered allmulticast mode [ 524.595794][ T5751] lag2: Port device veth7 added [ 538.974106][ T5813] lag2.200: left allmulticast mode [ 538.974771][ T5813] lag2.200: left promiscuous mode [ 538.975275][ T5813] br2: port 1(lag2.200) entered disabled state [ 538.999851][ T5814] lag2.100: left allmulticast mode [ 539.000007][ T5814] lag2: left allmulticast mode [ 539.000149][ T5814] veth1: left allmulticast mode [ 539.000903][ T5814] veth7: left allmulticast mode [ 539.001137][ T5814] lag2.100: left promiscuous mode [ 539.001283][ T5814] lag2: left promiscuous mode [ 539.001426][ T5814] veth1: left promiscuous mode [ 539.001722][ T5814] veth7: left promiscuous mode [ 539.002683][ T5814] br1: port 1(lag2.100) entered disabled state [ 541.044744][ T5816] br1: port 1(lag2.100) entered blocking state [ 541.044965][ T5816] br1: port 1(lag2.100) entered disabled state [ 541.045164][ T5816] lag2.100: entered allmulticast mode [ 541.045642][ T5816] lag2: entered allmulticast mode [ 541.045778][ T5816] veth1: entered allmulticast mode [ 541.045920][ T5816] veth7: entered allmulticast mode [ 541.047592][ T5816] lag2.100: entered promiscuous mode [ 541.047733][ T5816] lag2: entered promiscuous mode [ 541.047871][ T5816] veth1: entered promiscuous mode [ 541.048160][ T5816] veth7: entered promiscuous mode [ 541.049086][ T5816] br1: port 1(lag2.100) entered blocking state [ 541.049271][ T5816] br1: port 1(lag2.100) entered forwarding state [ 541.074943][ T5817] br2: port 1(lag2.200) entered blocking state [ 541.075132][ T5817] br2: port 1(lag2.200) entered disabled state [ 541.075352][ T5817] lag2.200: entered allmulticast mode [ 541.076903][ T5817] lag2.200: entered promiscuous mode [ 541.077671][ T5817] br2: port 1(lag2.200) entered blocking state [ 541.077851][ T5817] br2: port 1(lag2.200) entered forwarding state [ 555.582797][ T5879] lag3: Port device veth2 removed [ 570.095161][ T5942] lag3: Port device veth2 added [ 570.255630][ T5953] lag3: Port device veth4 removed [ 584.811503][ T6016] lag3: Port device veth2 removed [ 584.938642][ T6027] lag3: Port device veth4 added [ 585.079008][ T6038] lag3: Port device veth2 added [ 599.788119][ T6109] lag3: Port device veth4 removed [ 599.822732][ T6112] lag3: Port device veth2 removed [ 599.874326][ T5408] ================================================================== [ 599.874518][ T5408] BUG: KASAN: slab-use-after-free in rtnl_fill_prop_list+0x5ad/0x600 [ 599.874665][ T5408] Read of size 8 at addr ff1100000c761350 by task teamd/5408 [ 599.874818][ T5408] [ 599.874868][ T5408] CPU: 2 UID: 0 PID: 5408 Comm: teamd Not tainted 7.1.0-rc3-virtme #1 PREEMPT(full) [ 599.874872][ T5408] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 599.874874][ T5408] Call Trace: [ 599.874875][ T5408] [ 599.874877][ T5408] dump_stack_lvl+0x6f/0xa0 [ 599.874883][ T5408] print_address_description.constprop.0+0x56/0x2d0 [ 599.874888][ T5408] print_report+0xfc/0x1fa [ 599.874890][ T5408] ? __virt_addr_valid+0x102/0x440 [ 599.874894][ T5408] ? __virt_addr_valid+0x1da/0x440 [ 599.874896][ T5408] kasan_report+0x108/0x130 [ 599.874899][ T5408] ? rtnl_fill_prop_list+0x5ad/0x600 [ 599.874901][ T5408] ? rtnl_fill_prop_list+0x5ad/0x600 [ 599.874903][ T5408] rtnl_fill_prop_list+0x5ad/0x600 [ 599.874905][ T5408] ? __asan_memcpy+0x3c/0x60 [ 599.874908][ T5408] rtnl_fill_ifinfo.isra.0+0x3dc/0x2a80 [ 599.874911][ T5408] ? rcu_read_lock_any_held+0x3c/0x90 [ 599.874913][ T5408] ? validate_chain+0x38b/0xc20 [ 599.874916][ T5408] ? rtnl_fill_vf+0x450/0x450 [ 599.874917][ T5408] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 599.874919][ T5408] ? lockdep_hardirqs_on+0x8c/0x130 [ 599.874922][ T5408] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 599.874925][ T5408] ? __lock_acquire+0x508/0xc10 [ 599.874926][ T5408] ? rtnl_fill_vfinfo+0x607/0xf70 [ 599.874928][ T5408] ? lock_acquire.part.0+0xbc/0x260 [ 599.874930][ T5408] ? find_held_lock+0x2b/0x80 [ 599.874933][ T5408] ? __lock_release.isra.0+0x6b/0x1a0 [ 599.874934][ T5408] ? mark_held_locks+0x40/0x70 [ 599.874936][ T5408] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 599.874937][ T5408] ? lockdep_hardirqs_on+0x8c/0x130 [ 599.874939][ T5408] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 599.874941][ T5408] rtnl_getlink+0xa48/0xe50 [ 599.874944][ T5408] ? find_held_lock+0x2b/0x80 [ 599.874946][ T5408] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 599.874948][ T5408] ? mark_usage+0x61/0x170 [ 599.874949][ T5408] ? __lock_release.isra.0+0x6b/0x1a0 [ 599.874951][ T5408] ? __lock_acquire+0x508/0xc10 [ 599.874959][ T5408] ? lock_acquire.part.0+0xbc/0x260 [ 599.874961][ T5408] ? find_held_lock+0x2b/0x80 [ 599.874963][ T5408] ? mark_usage+0x61/0x170 [ 599.874964][ T5408] ? __lock_release.isra.0+0x6b/0x1a0 [ 599.874965][ T5408] ? __lock_acquire+0x508/0xc10 [ 599.874967][ T5408] ? bpf_address_lookup+0x282/0x290 [ 599.874970][ T5408] ? lock_acquire.part.0+0xbc/0x260 [ 599.874971][ T5408] ? find_held_lock+0x2b/0x80 [ 599.874973][ T5408] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 599.874975][ T5408] ? __lock_release.isra.0+0x6b/0x1a0 [ 599.874977][ T5408] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 599.874979][ T5408] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 599.874981][ T5408] ? validate_chain+0x38b/0xc20 [ 599.874982][ T5408] ? rtnl_link_fill+0x900/0x900 [ 599.874984][ T5408] ? __lock_acquire+0x508/0xc10 [ 599.874986][ T5408] ? lock_acquire.part.0+0xbc/0x260 [ 599.874987][ T5408] ? find_held_lock+0x2b/0x80 [ 599.874990][ T5408] netlink_rcv_skb+0x14e/0x3a0 [ 599.874992][ T5408] ? rtnl_link_fill+0x900/0x900 [ 599.874994][ T5408] ? netlink_ack+0xcd0/0xcd0 [ 599.874997][ T5408] ? netlink_deliver_tap+0xc5/0x330 [ 599.874999][ T5408] ? netlink_deliver_tap+0x13c/0x330 [ 599.875002][ T5408] netlink_unicast+0x4af/0x780 [ 599.875004][ T5408] ? netlink_attachskb+0x800/0x800 [ 599.875006][ T5408] ? trace_irq_enable.constprop.0+0x9b/0x180 [ 599.875009][ T5408] ? __lock_acquire+0x508/0xc10 [ 599.875011][ T5408] netlink_sendmsg+0x735/0xc60 [ 599.875014][ T5408] ? netlink_unicast+0x780/0x780 [ 599.875016][ T5408] ? __might_fault+0x97/0x140 [ 599.875020][ T5408] ____sys_sendmsg+0x419/0x850 [ 599.875024][ T5408] ? copy_msghdr_from_user+0x2a0/0x460 [ 599.875026][ T5408] ? get_timestamp.constprop.0+0x3a0/0x3a0 [ 599.875028][ T5408] ? move_addr_to_kernel+0x40/0x40 [ 599.875032][ T5408] ___sys_sendmsg+0x14e/0x1d0 [ 599.875034][ T5408] ? copy_msghdr_from_user+0x460/0x460 [ 599.875035][ T5408] ? kfree+0x22/0x5a0 [ 599.875043][ T5408] __sys_sendmsg+0x145/0x1f0 [ 599.875046][ T5408] ? __sys_sendmsg_sock+0x20/0x20 [ 599.875050][ T5408] ? rcu_is_watching+0x15/0xd0 [ 599.875053][ T5408] do_syscall_64+0x117/0xfc0 [ 599.875055][ T5408] ? irq_exit_rcu+0x1a/0x30 [ 599.875058][ T5408] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 599.875060][ T5408] RIP: 0033:0x7f7b2019b08e [ 599.875064][ T5408] Code: 4d 89 d8 e8 94 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 599.875066][ T5408] RSP: 002b:00007ffcd6fe79b0 EFLAGS: 00000202 ORIG_RAX: 000000000000002e [ 599.875070][ T5408] RAX: ffffffffffffffda RBX: 000055ebc57b0330 RCX: 00007f7b2019b08e [ 599.875072][ T5408] RDX: 0000000000000000 RSI: 00007ffcd6fe7a50 RDI: 0000000000000005 [ 599.875073][ T5408] RBP: 00007ffcd6fe79c0 R08: 0000000000000000 R09: 0000000000000000 [ 599.875074][ T5408] R10: 0000000000000000 R11: 0000000000000202 R12: 000055ebc57b9690 [ 599.875075][ T5408] R13: 00007ffcd6fe7a50 R14: 000055ebc57b0240 R15: 00007ffcd6fe7b90 [ 599.875078][ T5408] [ 599.875079][ T5408] [ 599.883241][ T5408] Allocated by task 5493: [ 599.883309][ T5408] kasan_save_stack+0x2f/0x50 [ 599.883440][ T5408] kasan_save_track+0x14/0x30 [ 599.883562][ T5408] __kasan_kmalloc+0x7b/0x90 [ 599.883648][ T5408] register_netdevice+0x48b/0x1980 [ 599.883741][ T5408] team_newlink+0xa2/0x1a0 [ 599.883826][ T5408] rtnl_newlink_create+0x2da/0x780 [ 599.883910][ T5408] __rtnl_newlink+0x22b/0xa50 [ 599.883993][ T5408] rtnl_newlink+0x8d1/0xee0 [ 599.884074][ T5408] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 599.884157][ T5408] netlink_rcv_skb+0x14e/0x3a0 [ 599.884248][ T5408] netlink_unicast+0x4af/0x780 [ 599.884340][ T5408] netlink_sendmsg+0x735/0xc60 [ 599.884427][ T5408] ____sys_sendmsg+0x419/0x850 [ 599.884513][ T5408] ___sys_sendmsg+0x14e/0x1d0 [ 599.884600][ T5408] __sys_sendmsg+0x145/0x1f0 [ 599.884688][ T5408] do_syscall_64+0x117/0xfc0 [ 599.884774][ T5408] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 599.884879][ T5408] [ 599.884962][ T5408] Freed by task 5493: [ 599.885030][ T5408] kasan_save_stack+0x2f/0x50 [ 599.885118][ T5408] kasan_save_track+0x14/0x30 [ 599.885203][ T5408] kasan_save_free_info+0x3b/0x60 [ 599.885290][ T5408] __kasan_slab_free+0x43/0x70 [ 599.885374][ T5408] kfree+0x123/0x5a0 [ 599.885475][ T5408] unregister_netdevice_many_notify+0xe38/0x1d80 [ 599.885578][ T5408] rtnl_dellink+0x4a0/0xae0 [ 599.885661][ T5408] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 599.885745][ T5408] netlink_rcv_skb+0x14e/0x3a0 [ 599.885829][ T5408] netlink_unicast+0x4af/0x780 [ 599.885910][ T5408] netlink_sendmsg+0x735/0xc60 [ 599.885990][ T5408] ____sys_sendmsg+0x419/0x850 [ 599.886069][ T5408] ___sys_sendmsg+0x14e/0x1d0 [ 599.886150][ T5408] __sys_sendmsg+0x145/0x1f0 [ 599.886232][ T5408] do_syscall_64+0x117/0xfc0 [ 599.886312][ T5408] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 599.886413][ T5408] [ 599.886456][ T5408] The buggy address belongs to the object at ff1100000c761340 [ 599.886456][ T5408] which belongs to the cache kmalloc-64 of size 64 [ 599.886703][ T5408] The buggy address is located 16 bytes inside of [ 599.886703][ T5408] freed 64-byte region [ff1100000c761340, ff1100000c761380) [ 599.886950][ T5408] [ 599.886993][ T5408] The buggy address belongs to the physical page: [ 599.887104][ T5408] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xc761 [ 599.887256][ T5408] flags: 0x80000000000000(node=0|zone=1) [ 599.887346][ T5408] page_type: f5(slab) [ 599.887414][ T5408] raw: 0080000000000000 ff1100000103cac0 ffd400000031d8d0 ffd400000045ad10 [ 599.887572][ T5408] raw: 0000000000000000 0000000000100010 00000000f5000000 0000000000000000 [ 599.887771][ T5408] page dumped because: kasan: bad access detected [ 599.887882][ T5408] [ 599.887924][ T5408] Memory state around the buggy address: [ 599.888008][ T5408] ff1100000c761200: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 599.888131][ T5408] ff1100000c761280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 599.888267][ T5408] >ff1100000c761300: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 599.888397][ T5408] ^ [ 599.888503][ T5408] ff1100000c761380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 599.888631][ T5408] ff1100000c761400: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 599.888759][ T5408] ================================================================== [ 599.889736][ T5408] Disabling lock debugging due to kernel taint [ 600.042969][ T6125] br2: port 1(lag2.200) entered disabled state [ 600.058280][ T6126] br1: port 1(lag2.100) entered disabled state [ 600.111375][ T6129] lag2.200: left allmulticast mode [ 600.111558][ T6129] lag2.200: left promiscuous mode [ 600.111880][ T6129] br2: port 1(lag2.200) entered disabled state [ 600.167116][ T6131] lag2.100: left allmulticast mode [ 600.167266][ T6131] lag2: left allmulticast mode [ 600.167371][ T6131] veth1: left allmulticast mode [ 600.167479][ T6131] veth7: left allmulticast mode [ 600.167639][ T6131] lag2.100: left promiscuous mode [ 600.167735][ T6131] lag2: left promiscuous mode [ 600.167821][ T6131] veth1: left promiscuous mode [ 600.168020][ T6131] veth7: left promiscuous mode [ 600.168894][ T6131] br1: port 1(lag2.100) entered disabled state [ 600.301496][ T6135] lag2: Port device veth7 removed [ 600.317149][ T6136] lag2: Port device veth1 removed [ 600.713099][ T6151] lag4: Port device veth5 removed [ 600.730702][ T6152] lag4: Port device veth3 removed [ 600.798897][ T5408] teamd (5408) used greatest stack depth: 23856 bytes left [ 601.137027][ T6167] lag1: Port device veth6 removed [ 601.155210][ T6168] lag1: Port device veth0 removed