[ 760.412249][ T8066] lag1: Mode changed to "loadbalance" [ 760.449697][ T8067] 8021q: adding VLAN 0 to HW filter on device lag1 [ 760.611072][ T8076] lag1: Port device veth0 added [ 760.635810][ T8077] lag1: Port device veth6 added [ 760.802090][ T8083] 8021q: adding VLAN 0 to HW filter on device lag1 [ 761.091258][ T8095] lag4: Mode changed to "loadbalance" [ 761.132343][ T8096] 8021q: adding VLAN 0 to HW filter on device lag4 [ 761.297642][ T8103] lag4: Port device veth3 added [ 761.322015][ T8104] lag4: Port device veth5 added [ 761.495208][ T8110] 8021q: adding VLAN 0 to HW filter on device lag4 [ 761.794006][ T8122] lag2: Mode changed to "loadbalance" [ 761.826942][ T8124] 8021q: adding VLAN 0 to HW filter on device lag2 [ 761.992653][ T8132] lag2: Port device veth1 added [ 762.027503][ T8133] lag2: Port device veth7 added [ 762.126246][ T8139] br1: port 1(lag2) entered blocking state [ 762.126499][ T8139] br1: port 1(lag2) entered disabled state [ 762.126769][ T8139] lag2: entered allmulticast mode [ 762.126944][ T8139] veth1: entered allmulticast mode [ 762.127128][ T8139] veth7: entered allmulticast mode [ 762.129648][ T8139] veth1: entered promiscuous mode [ 762.129921][ T8139] veth7: entered promiscuous mode [ 762.222810][ T8143] br1: port 1(lag2) entered blocking state [ 762.223016][ T8143] br1: port 1(lag2) entered forwarding state [ 762.358785][ T8149] lag3: Mode changed to "loadbalance" [ 762.391544][ T8152] 8021q: adding VLAN 0 to HW filter on device lag3 [ 762.530019][ T8159] lag3: Port device veth2 added [ 762.557722][ T8160] lag3: Port device veth4 added [ 770.295251][ T8231] veth7: left allmulticast mode [ 770.296379][ T8231] lag2: Port device veth7 removed [ 770.328691][ T8232] veth7: left promiscuous mode [ 782.667030][ T8284] veth7: entered allmulticast mode [ 782.667219][ T8284] veth7: entered promiscuous mode [ 782.668450][ T8284] lag2: Port device veth7 added [ 782.781114][ T8295] veth1: left allmulticast mode [ 782.782894][ T8295] lag2: Port device veth1 removed [ 782.806691][ T8296] veth1: left promiscuous mode [ 795.147623][ T39] br1: port 1(lag2) entered disabled state [ 795.168120][ T8348] veth7: left allmulticast mode [ 795.169412][ T8348] lag2: Port device veth7 removed [ 795.191361][ T8349] veth7: left promiscuous mode [ 795.282552][ T8359] veth1: entered allmulticast mode [ 795.282730][ T8359] veth1: entered promiscuous mode [ 795.283695][ T8359] lag2: Port device veth1 added [ 795.297276][ T48] br1: port 1(lag2) entered blocking state [ 795.297488][ T48] br1: port 1(lag2) entered forwarding state [ 795.405933][ T8370] veth7: entered allmulticast mode [ 795.406123][ T8370] veth7: entered promiscuous mode [ 795.407083][ T8370] lag2: Port device veth7 added [ 807.728431][ T8422] lag2: left allmulticast mode [ 807.728673][ T8422] veth1: left allmulticast mode [ 807.728871][ T8422] veth7: left allmulticast mode [ 807.729238][ T8422] br1: port 1(lag2) entered disabled state [ 807.731383][ T8422] veth1: left promiscuous mode [ 807.731751][ T8422] veth7: left promiscuous mode [ 809.797677][ T8424] br1: port 1(lag2) entered blocking state [ 809.797904][ T8424] br1: port 1(lag2) entered disabled state [ 809.798120][ T8424] lag2: entered allmulticast mode [ 809.798252][ T8424] veth1: entered allmulticast mode [ 809.798388][ T8424] veth7: entered allmulticast mode [ 809.801349][ T8424] br1: port 1(lag2) entered blocking state [ 809.801575][ T8424] br1: port 1(lag2) entered forwarding state [ 809.802279][ T8424] veth1: entered promiscuous mode [ 809.802474][ T8424] veth7: entered promiscuous mode [ 822.138849][ T8476] lag3: Port device veth2 removed [ 834.513025][ T8529] lag3: Port device veth2 added [ 834.634267][ T8540] lag3: Port device veth4 removed [ 846.971266][ T8593] lag3: Port device veth2 removed [ 847.091906][ T8604] lag3: Port device veth4 added [ 847.213132][ T8615] lag3: Port device veth2 added [ 859.522990][ T8667] br1: port 2(lag3) entered blocking state [ 859.523207][ T8667] br1: port 2(lag3) entered disabled state [ 859.523401][ T8667] lag3: entered allmulticast mode [ 859.524096][ T8667] veth4: entered allmulticast mode [ 859.524245][ T8667] veth2: entered allmulticast mode [ 859.525997][ T8667] lag3: entered promiscuous mode [ 859.526145][ T8667] veth4: entered promiscuous mode [ 859.526432][ T8667] veth2: entered promiscuous mode [ 859.527436][ T8667] lag2: entered promiscuous mode [ 859.528350][ T8667] br1: port 2(lag3) entered blocking state [ 859.528530][ T8667] br1: port 2(lag3) entered forwarding state [ 861.571538][ T8669] lag3: left allmulticast mode [ 861.571757][ T8669] veth4: left allmulticast mode [ 861.571947][ T8669] veth2: left allmulticast mode [ 861.572183][ T8669] lag3: left promiscuous mode [ 861.572360][ T8669] veth4: left promiscuous mode [ 861.573540][ T8669] veth2: left promiscuous mode [ 861.574057][ T8669] br1: port 2(lag3) entered disabled state [ 861.574888][ T8669] lag2: left promiscuous mode [ 861.575081][ T8669] veth1: left promiscuous mode [ 861.576114][ T8669] veth7: left promiscuous mode [ 861.576631][ T8669] veth1: entered promiscuous mode [ 861.576848][ T8669] veth7: entered promiscuous mode [ 874.052045][ T8725] lag3: Port device veth4 removed [ 874.077335][ T8726] lag3: Port device veth2 removed [ 874.143062][ T8122] ================================================================== [ 874.143204][ T8122] BUG: KASAN: slab-use-after-free in rtnl_fill_prop_list+0x5ad/0x600 [ 874.143339][ T8122] Read of size 8 at addr ff11000001d16c50 by task teamd/8122 [ 874.143463][ T8122] [ 874.143512][ T8122] CPU: 3 UID: 0 PID: 8122 Comm: teamd Not tainted 7.1.0-rc3-virtme #1 PREEMPT(full) [ 874.143515][ T8122] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 874.143517][ T8122] Call Trace: [ 874.143519][ T8122] [ 874.143520][ T8122] dump_stack_lvl+0x6f/0xa0 [ 874.143526][ T8122] print_address_description.constprop.0+0x56/0x2d0 [ 874.143531][ T8122] print_report+0xfc/0x1fa [ 874.143533][ T8122] ? __virt_addr_valid+0x102/0x440 [ 874.143537][ T8122] ? __virt_addr_valid+0x1da/0x440 [ 874.143540][ T8122] kasan_report+0x108/0x130 [ 874.143542][ T8122] ? rtnl_fill_prop_list+0x5ad/0x600 [ 874.143544][ T8122] ? rtnl_fill_prop_list+0x5ad/0x600 [ 874.143552][ T8122] rtnl_fill_prop_list+0x5ad/0x600 [ 874.143554][ T8122] ? __asan_memcpy+0x3c/0x60 [ 874.143557][ T8122] rtnl_fill_ifinfo.isra.0+0x3dc/0x2a80 [ 874.143559][ T8122] ? rcu_read_lock_any_held+0x3c/0x90 [ 874.143562][ T8122] ? validate_chain+0x38b/0xc20 [ 874.143565][ T8122] ? rtnl_fill_vf+0x450/0x450 [ 874.143567][ T8122] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 874.143568][ T8122] ? lockdep_hardirqs_on+0x8c/0x130 [ 874.143572][ T8122] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 874.143574][ T8122] ? __lock_acquire+0x508/0xc10 [ 874.143576][ T8122] ? rtnl_fill_vfinfo+0x609/0xf70 [ 874.143578][ T8122] ? lock_acquire.part.0+0xbc/0x260 [ 874.143579][ T8122] ? find_held_lock+0x2b/0x80 [ 874.143582][ T8122] ? __lock_release.isra.0+0x6b/0x1a0 [ 874.143584][ T8122] ? mark_held_locks+0x40/0x70 [ 874.143586][ T8122] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 874.143587][ T8122] ? lockdep_hardirqs_on+0x8c/0x130 [ 874.143588][ T8122] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 874.143591][ T8122] rtnl_getlink+0xa48/0xe50 [ 874.143593][ T8122] ? find_held_lock+0x2b/0x80 [ 874.143595][ T8122] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 874.143597][ T8122] ? mark_usage+0x61/0x170 [ 874.143598][ T8122] ? __lock_release.isra.0+0x6b/0x1a0 [ 874.143600][ T8122] ? __lock_acquire+0x508/0xc10 [ 874.143607][ T8122] ? lock_acquire.part.0+0xbc/0x260 [ 874.143609][ T8122] ? find_held_lock+0x2b/0x80 [ 874.143611][ T8122] ? mark_usage+0x61/0x170 [ 874.143612][ T8122] ? __lock_release.isra.0+0x6b/0x1a0 [ 874.143613][ T8122] ? __lock_acquire+0x508/0xc10 [ 874.143615][ T8122] ? bpf_address_lookup+0x282/0x290 [ 874.143618][ T8122] ? lock_acquire.part.0+0xbc/0x260 [ 874.143619][ T8122] ? find_held_lock+0x2b/0x80 [ 874.143621][ T8122] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 874.143623][ T8122] ? __lock_release.isra.0+0x6b/0x1a0 [ 874.143625][ T8122] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 874.143626][ T8122] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 874.143628][ T8122] ? validate_chain+0x38b/0xc20 [ 874.143629][ T8122] ? rtnl_link_fill+0x900/0x900 [ 874.143631][ T8122] ? __lock_acquire+0x508/0xc10 [ 874.143633][ T8122] ? lock_acquire.part.0+0xbc/0x260 [ 874.143634][ T8122] ? find_held_lock+0x2b/0x80 [ 874.143637][ T8122] netlink_rcv_skb+0x14e/0x3a0 [ 874.143640][ T8122] ? rtnl_link_fill+0x900/0x900 [ 874.143641][ T8122] ? netlink_ack+0xcd0/0xcd0 [ 874.143645][ T8122] ? netlink_deliver_tap+0xc5/0x330 [ 874.143646][ T8122] ? netlink_deliver_tap+0x13c/0x330 [ 874.143649][ T8122] netlink_unicast+0x4af/0x780 [ 874.143651][ T8122] ? netlink_attachskb+0x800/0x800 [ 874.143652][ T8122] ? trace_irq_enable.constprop.0+0x9b/0x180 [ 874.143656][ T8122] ? __lock_acquire+0x508/0xc10 [ 874.143658][ T8122] netlink_sendmsg+0x735/0xc60 [ 874.143660][ T8122] ? netlink_unicast+0x780/0x780 [ 874.143662][ T8122] ? __might_fault+0x97/0x140 [ 874.143666][ T8122] ____sys_sendmsg+0x419/0x850 [ 874.143670][ T8122] ? copy_msghdr_from_user+0x2a0/0x460 [ 874.143672][ T8122] ? get_timestamp.constprop.0+0x3a0/0x3a0 [ 874.143674][ T8122] ? move_addr_to_kernel+0x40/0x40 [ 874.143677][ T8122] ___sys_sendmsg+0x14e/0x1d0 [ 874.143679][ T8122] ? copy_msghdr_from_user+0x460/0x460 [ 874.143681][ T8122] ? kfree+0x22/0x5a0 [ 874.143688][ T8122] __sys_sendmsg+0x145/0x1f0 [ 874.143691][ T8122] ? __sys_sendmsg_sock+0x20/0x20 [ 874.143694][ T8122] ? rcu_is_watching+0x15/0xd0 [ 874.143697][ T8122] do_syscall_64+0x117/0xfc0 [ 874.143699][ T8122] ? irq_exit_rcu+0x1a/0x30 [ 874.143702][ T8122] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 874.143704][ T8122] RIP: 0033:0x7fb0e367d08e [ 874.143707][ T8122] Code: 4d 89 d8 e8 94 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 874.143709][ T8122] RSP: 002b:00007ffc1e36f320 EFLAGS: 00000202 ORIG_RAX: 000000000000002e [ 874.143713][ T8122] RAX: ffffffffffffffda RBX: 00005635e4cd8330 RCX: 00007fb0e367d08e [ 874.143714][ T8122] RDX: 0000000000000000 RSI: 00007ffc1e36f3c0 RDI: 0000000000000005 [ 874.143715][ T8122] RBP: 00007ffc1e36f330 R08: 0000000000000000 R09: 0000000000000000 [ 874.143716][ T8122] R10: 0000000000000000 R11: 0000000000000202 R12: 00005635e4cdf200 [ 874.143717][ T8122] R13: 00007ffc1e36f3c0 R14: 00005635e4cd8240 R15: 00007ffc1e36f500 [ 874.143720][ T8122] [ 874.143721][ T8122] [ 874.151237][ T8122] Allocated by task 8149: [ 874.151302][ T8122] kasan_save_stack+0x2f/0x50 [ 874.151390][ T8122] kasan_save_track+0x14/0x30 [ 874.151471][ T8122] __kasan_kmalloc+0x7b/0x90 [ 874.151557][ T8122] register_netdevice+0x48b/0x1980 [ 874.151639][ T8122] team_newlink+0xa2/0x1a0 [ 874.151722][ T8122] rtnl_newlink_create+0x2da/0x780 [ 874.151803][ T8122] __rtnl_newlink+0x22b/0xa50 [ 874.151884][ T8122] rtnl_newlink+0x8d1/0xee0 [ 874.152007][ T8122] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 874.152089][ T8122] netlink_rcv_skb+0x14e/0x3a0 [ 874.152174][ T8122] netlink_unicast+0x4af/0x780 [ 874.152255][ T8122] netlink_sendmsg+0x735/0xc60 [ 874.152374][ T8122] ____sys_sendmsg+0x419/0x850 [ 874.152457][ T8122] ___sys_sendmsg+0x14e/0x1d0 [ 874.152538][ T8122] __sys_sendmsg+0x145/0x1f0 [ 874.152627][ T8122] do_syscall_64+0x117/0xfc0 [ 874.152750][ T8122] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 874.152855][ T8122] [ 874.152902][ T8122] Freed by task 8149: [ 874.152970][ T8122] kasan_save_stack+0x2f/0x50 [ 874.153052][ T8122] kasan_save_track+0x14/0x30 [ 874.153174][ T8122] kasan_save_free_info+0x3b/0x60 [ 874.153254][ T8122] __kasan_slab_free+0x43/0x70 [ 874.153335][ T8122] kfree+0x123/0x5a0 [ 874.153396][ T8122] unregister_netdevice_many_notify+0xe38/0x1d80 [ 874.153539][ T8122] rtnl_dellink+0x4a0/0xae0 [ 874.153621][ T8122] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 874.153709][ T8122] netlink_rcv_skb+0x14e/0x3a0 [ 874.153788][ T8122] netlink_unicast+0x4af/0x780 [ 874.153909][ T8122] netlink_sendmsg+0x735/0xc60 [ 874.153989][ T8122] ____sys_sendmsg+0x419/0x850 [ 874.154077][ T8122] ___sys_sendmsg+0x14e/0x1d0 [ 874.154156][ T8122] __sys_sendmsg+0x145/0x1f0 [ 874.154280][ T8122] do_syscall_64+0x117/0xfc0 [ 874.154361][ T8122] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 874.154459][ T8122] [ 874.154501][ T8122] The buggy address belongs to the object at ff11000001d16c40 [ 874.154501][ T8122] which belongs to the cache kmalloc-64 of size 64 [ 874.154702][ T8122] The buggy address is located 16 bytes inside of [ 874.154702][ T8122] freed 64-byte region [ff11000001d16c40, ff11000001d16c80) [ 874.154903][ T8122] [ 874.154945][ T8122] The buggy address belongs to the physical page: [ 874.155046][ T8122] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1d16 [ 874.155193][ T8122] flags: 0x80000000000000(node=0|zone=1) [ 874.155279][ T8122] page_type: f5(slab) [ 874.155346][ T8122] raw: 0080000000000000 ff1100000103cac0 ffd400000009a390 ffd400000059bad0 [ 874.155495][ T8122] raw: 0000000000000000 0000000000100010 00000000f5000000 0000000000000000 [ 874.155642][ T8122] page dumped because: kasan: bad access detected [ 874.155743][ T8122] [ 874.155784][ T8122] Memory state around the buggy address: [ 874.155864][ T8122] ff11000001d16b00: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 874.155986][ T8122] ff11000001d16b80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 874.156105][ T8122] >ff11000001d16c00: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 874.156225][ T8122] ^ [ 874.156326][ T8122] ff11000001d16c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 874.156444][ T8122] ff11000001d16d00: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 874.156569][ T8122] ================================================================== [ 874.156703][ T8122] Disabling lock debugging due to kernel taint [ 874.297381][ T60] br1: port 1(lag2) entered disabled state [ 874.349459][ T8743] lag2: left allmulticast mode [ 874.349606][ T8743] veth1: left allmulticast mode [ 874.349698][ T8743] veth7: left allmulticast mode [ 874.349834][ T8743] br1: port 1(lag2) entered disabled state [ 874.411782][ T8745] lag2: Port device veth7 removed [ 874.433908][ T8746] lag2: Port device veth1 removed [ 874.790323][ T8759] lag4: Port device veth5 removed [ 874.804839][ T8760] lag4: Port device veth3 removed [ 875.160303][ T8773] lag1: Port device veth6 removed [ 875.184894][ T8774] lag1: Port device veth0 removed