[ 9.587372][ T207] ip (207) used greatest stack depth: 24080 bytes left
[ 13.573096][ T387] ip (387) used greatest stack depth: 23904 bytes left
[ 77.815868][ T2397] awk (2397) used greatest stack depth: 23792 bytes left
[ 128.028280][ T4029] ip (4029) used greatest stack depth: 23680 bytes left
[ 330.111810][ T7408] ip (7408) used greatest stack depth: 23632 bytes left
[ 330.391652][ C0] clocksource: Watchdog remote CPU 3 read timed out
[ 548.388408][ C1] ==================================================================
[ 548.388702][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response.isra.0+0xd84/0x1df0
[ 548.388991][ C1] Read of size 8 at addr ff11000009e933c8 by task kworker/1:1/66
[ 548.389226][ C1]
[ 548.389311][ C1] CPU: 1 UID: 0 PID: 66 Comm: kworker/1:1 Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 548.389314][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 548.389316][ C1] Workqueue: events mptcp_worker
[ 548.389321][ C1] Call Trace:
[ 548.389323][ C1]
[ 548.389325][ C1] dump_stack_lvl+0x6f/0xa0
[ 548.389331][ C1] print_address_description.constprop.0+0x56/0x2d0
[ 548.389335][ C1] print_report+0xfc/0x1fa
[ 548.389337][ C1] ? __virt_addr_valid+0x102/0x440
[ 548.389340][ C1] ? __virt_addr_valid+0x1da/0x440
[ 548.389343][ C1] kasan_report+0x108/0x130
[ 548.389346][ C1] ? tcp_v6_send_response.isra.0+0xd84/0x1df0
[ 548.389348][ C1] ? tcp_v6_send_response.isra.0+0xd84/0x1df0
[ 548.389351][ C1] kasan_check_range+0x130/0x200
[ 548.389353][ C1] tcp_v6_send_response.isra.0+0xd84/0x1df0
[ 548.389356][ C1] ? __xfrm_policy_check2.constprop.0+0x720/0x720
[ 548.389358][ C1] ? do_settimeofday64.part.0+0xd5/0x2d0
[ 548.389362][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 548.389365][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389368][ C1] ? mark_held_locks+0x40/0x70
[ 548.389370][ C1] tcp_v6_rcv+0x230c/0x2fc0
[ 548.389374][ C1] ? tcp_v6_syn_recv_sock+0x1ab0/0x1ab0
[ 548.389376][ C1] ? ipv6_raw_deliver+0x31a/0x870
[ 548.389378][ C1] ? ipv6_raw_deliver+0x324/0x870
[ 548.389380][ C1] ip6_protocol_deliver_rcu+0x15e/0x1330
[ 548.389384][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389386][ C1] ip6_input_finish+0x196/0x590
[ 548.389388][ C1] ip6_input+0x130/0x570
[ 548.389389][ C1] ? ip6_input_finish+0x590/0x590
[ 548.389391][ C1] ? ip6_rcv_core+0xb14/0x1af0
[ 548.389394][ C1] ipv6_rcv+0x13d/0x480
[ 548.389395][ C1] ? ip6_rcv_core+0x1af0/0x1af0
[ 548.389397][ C1] ? mark_usage+0x61/0x170
[ 548.389406][ C1] ? __lock_acquire+0x518/0xc20
[ 548.389408][ C1] ? process_backlog+0x3f1/0x14c0
[ 548.389411][ C1] __netif_receive_skb_one_core+0xfc/0x180
[ 548.389413][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 548.389414][ C1] ? process_backlog+0x3f1/0x14c0
[ 548.389415][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 548.389417][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389420][ C1] process_backlog+0x431/0x14c0
[ 548.389422][ C1] __napi_poll+0xa7/0x3b0
[ 548.389424][ C1] net_rx_action+0x513/0xf50
[ 548.389426][ C1] ? __napi_poll+0x3b0/0x3b0
[ 548.389429][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 548.389430][ C1] ? __rwlock_init+0x150/0x150
[ 548.389433][ C1] ? __run_timers+0xaa0/0xaa0
[ 548.389435][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389437][ C1] ? mark_held_locks+0x40/0x70
[ 548.389439][ C1] handle_softirqs+0x1d3/0x900
[ 548.389442][ C1] ? _local_bh_enable+0xc0/0xc0
[ 548.389443][ C1] ? _local_bh_enable+0xc0/0xc0
[ 548.389444][ C1] ? __dev_queue_xmit+0x964/0x1b80
[ 548.389446][ C1] do_softirq+0xac/0xe0
[ 548.389448][ C1]
[ 548.389449][ C1]
[ 548.389450][ C1] __local_bh_enable_ip+0x118/0x150
[ 548.389452][ C1] __dev_queue_xmit+0x979/0x1b80
[ 548.389455][ C1] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160
[ 548.389457][ C1] ? lockdep_hardirqs_on+0x91/0x130
[ 548.389460][ C1] ? enqueue_to_backlog+0x5f3/0x8c0
[ 548.389464][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 548.389465][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 548.389467][ C1] ? find_held_lock+0x2b/0x80
[ 548.389469][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 548.389471][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389472][ C1] ? mark_held_locks+0x40/0x70
[ 548.389474][ C1] ? __asan_memcpy+0x3c/0x60
[ 548.389476][ C1] ? neigh_hh_output+0x152/0x4c0
[ 548.389479][ C1] ip6_finish_output2+0x96f/0x12a0
[ 548.389481][ C1] ? ip6_dst_lookup+0x80/0x80
[ 548.389482][ C1] ? find_held_lock+0x2b/0x80
[ 548.389484][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 548.389486][ C1] ? ip6_mtu+0x15d/0x310
[ 548.389488][ C1] ip6_finish_output+0x646/0xda0
[ 548.389490][ C1] ip6_output+0x23f/0x7f0
[ 548.389492][ C1] ? ip6_finish_output+0xda0/0xda0
[ 548.389493][ C1] ? find_held_lock+0x2b/0x80
[ 548.389495][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 548.389497][ C1] ? ip6_mtu+0x15d/0x310
[ 548.389499][ C1] ip6_xmit+0xb5a/0x1b70
[ 548.389500][ C1] ? mark_usage+0x61/0x170
[ 548.389501][ C1] ? find_held_lock+0x2b/0x80
[ 548.389503][ C1] ? __lock_acquire+0x518/0xc20
[ 548.389505][ C1] ? ip6_autoflowlabel+0x120/0x120
[ 548.389507][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 548.389508][ C1] ? mark_usage+0x61/0x170
[ 548.389509][ C1] ? __lock_acquire+0x518/0xc20
[ 548.389512][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 548.389513][ C1] ? inet6_csk_xmit+0xfe/0x5f0
[ 548.389515][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389516][ C1] ? lock_acquire+0x13c/0x160
[ 548.389518][ C1] inet6_csk_xmit+0x2f6/0x5f0
[ 548.389520][ C1] __tcp_transmit_skb+0x1b1f/0x3ac0
[ 548.389524][ C1] ? __tcp_select_window+0x1040/0x1040
[ 548.389525][ C1] ? find_held_lock+0x2b/0x80
[ 548.389529][ C1] tcp_write_xmit+0x5a4/0x3080
[ 548.389532][ C1] ? tcp_connect_init+0x1250/0x1250
[ 548.389533][ C1] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 548.389535][ C1] ? tcp_set_state+0x101/0x580
[ 548.389538][ C1] ? find_held_lock+0x2b/0x80
[ 548.389541][ C1] __tcp_push_pending_frames+0x8f/0x3b0
[ 548.389542][ C1] __tcp_close+0x84e/0xe70
[ 548.389544][ C1] ? lockdep_hardirqs_on+0x91/0x130
[ 548.389546][ C1] ? __local_bh_enable_ip+0xaa/0x150
[ 548.389547][ C1] ? __mptcp_retransmit_pending_data+0x2fc/0x430
[ 548.389549][ C1] __mptcp_close_ssk+0x5b4/0x1650
[ 548.389551][ C1] ? mptcp_pm_subflow_check_next+0x251/0x400
[ 548.389554][ C1] ? mptcp_release_cb+0xae0/0xae0
[ 548.389556][ C1] mptcp_pm_rm_addr_or_subflow+0x399/0xac0
[ 548.389559][ C1] ? mptcp_pm_schedule_work+0x150/0x150
[ 548.389561][ C1] mptcp_pm_worker+0x1e2/0x290
[ 548.389563][ C1] ? __local_bh_enable_ip+0xaa/0x150
[ 548.389564][ C1] mptcp_worker+0x149/0x1160
[ 548.389566][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 548.389567][ C1] ? process_one_work+0xdfc/0x1560
[ 548.389570][ C1] ? mptcp_sendmsg+0x1de0/0x1de0
[ 548.389571][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389573][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389574][ C1] ? lock_acquire+0x13c/0x160
[ 548.389576][ C1] ? rcu_is_watching+0x16/0xd0
[ 548.389578][ C1] process_one_work+0xe3e/0x1560
[ 548.389581][ C1] ? __queue_delayed_work+0x470/0x470
[ 548.389583][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 548.389585][ C1] worker_thread+0x4f1/0xd60
[ 548.389588][ C1] ? rescuer_thread+0x1340/0x1340
[ 548.389589][ C1] ? __kthread_parkme+0xbd/0x210
[ 548.389592][ C1] ? rescuer_thread+0x1340/0x1340
[ 548.389593][ C1] ? rescuer_thread+0x1340/0x1340
[ 548.389595][ C1] kthread+0x367/0x460
[ 548.389596][ C1] ? trace_irq_enable.constprop.0+0x9b/0x160
[ 548.389600][ C1] ? kthread_affine_preferred+0x4c0/0x4c0
[ 548.389601][ C1] ret_from_fork+0x474/0x6b0
[ 548.389605][ C1] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120
[ 548.389607][ C1] ? __switch_to+0x5a3/0xe00
[ 548.389610][ C1] ? kthread_affine_preferred+0x4c0/0x4c0
[ 548.389611][ C1] ret_from_fork_asm+0x11/0x20
[ 548.389615][ C1]
[ 548.389615][ C1]
[ 548.412919][ C1] The buggy address belongs to the object at ff11000009e93328
[ 548.412919][ C1] which belongs to the cache tw_sock_TCPv6 of size 280
[ 548.413411][ C1] The buggy address is located 160 bytes inside of
[ 548.413411][ C1] allocated 280-byte region [ff11000009e93328, ff11000009e93440)
[ 548.413850][ C1]
[ 548.413932][ C1] The buggy address belongs to the physical page:
[ 548.414131][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000009e92cc8 pfn:0x9e92
[ 548.414526][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 548.414835][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 548.415100][ C1] page_type: f5(slab)
[ 548.415228][ C1] raw: 0080000000000240 ff11000005b6de40 ff11000005b790c8 ff11000005b790c8
[ 548.415588][ C1] raw: ff11000009e92cc8 0000000000140001 00000000f5000000 0000000000000000
[ 548.415934][ C1] head: 0080000000000240 ff11000005b6de40 ff11000005b790c8 ff11000005b790c8
[ 548.416281][ C1] head: ff11000009e92cc8 0000000000140001 00000000f5000000 0000000000000000
[ 548.416574][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 548.416920][ C1] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 548.417202][ C1] page dumped because: kasan: bad access detected
[ 548.417474][ C1]
[ 548.417555][ C1] Memory state around the buggy address:
[ 548.417768][ C1] ff11000009e93280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 548.418063][ C1] ff11000009e93300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 548.418297][ C1] >ff11000009e93380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 548.418602][ C1] ^
[ 548.418854][ C1] ff11000009e93400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 548.419085][ C1] ff11000009e93480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 548.419376][ C1] ==================================================================
[ 548.419693][ C1] Disabling lock debugging due to kernel taint
[ 951.859672][T27755] pm_nl_ctl (27755) used greatest stack depth: 23192 bytes left