[ 242.713166][ C0] ==================================================================
[ 242.713468][ C0] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0
[ 242.713694][ C0] Read of size 8 at addr ff1100000af6cf38 by task tcp_fastopen_ba/2910
[ 242.713913][ C0]
[ 242.713990][ C0] CPU: 0 UID: 0 PID: 2910 Comm: tcp_fastopen_ba Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 242.713993][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 242.713995][ C0] Call Trace:
[ 242.713997][ C0]
[ 242.713998][ C0] dump_stack_lvl+0x6f/0xa0
[ 242.714003][ C0] print_address_description.constprop.0+0x56/0x2d0
[ 242.714007][ C0] print_report+0xfc/0x1fa
[ 242.714008][ C0] ? __virt_addr_valid+0x102/0x440
[ 242.714011][ C0] ? __virt_addr_valid+0x1da/0x440
[ 242.714013][ C0] kasan_report+0x108/0x130
[ 242.714016][ C0] ? tcp_v6_send_response+0xe7d/0x24e0
[ 242.714018][ C0] ? tcp_v6_send_response+0xe7d/0x24e0
[ 242.714021][ C0] kasan_check_range+0x130/0x200
[ 242.714022][ C0] ? make_kuid+0x13/0x20
[ 242.714025][ C0] tcp_v6_send_response+0xe7d/0x24e0
[ 242.714027][ C0] ? __mod_timer+0x91/0xc60
[ 242.714030][ C0] ? tcp_v6_send_synack+0xe10/0xe10
[ 242.714032][ C0] ? __lock_acquire+0x518/0xc20
[ 242.714035][ C0] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 242.714038][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 242.714040][ C0] ? rcu_is_watching+0x16/0xd0
[ 242.714043][ C0] tcp_v6_rcv+0x24c5/0x3250
[ 242.714047][ C0] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 242.714049][ C0] ? rcu_do_batch+0x2b6/0x1000
[ 242.714051][ C0] ? is_bpf_text_address+0x72/0x110
[ 242.714054][ C0] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 242.714058][ C0] ip6_input_finish+0x196/0x590
[ 242.714059][ C0] ip6_input+0x130/0x570
[ 242.714061][ C0] ? ip6_input_finish+0x590/0x590
[ 242.714062][ C0] ? ip6_rcv_core+0xde3/0x1be0
[ 242.714063][ C0] ? __asan_memset+0x27/0x50
[ 242.714066][ C0] ? ip6_rcv_core+0xded/0x1be0
[ 242.714068][ C0] ipv6_rcv+0x3c1/0x5a0
[ 242.714069][ C0] ? ip6_rcv_core+0x1be0/0x1be0
[ 242.714071][ C0] ? mark_usage+0x61/0x170
[ 242.714073][ C0] ? __lock_acquire+0x518/0xc20
[ 242.714075][ C0] ? process_backlog+0x3f1/0x14c0
[ 242.714078][ C0] __netif_receive_skb_one_core+0xfc/0x180
[ 242.714080][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 242.714082][ C0] ? process_backlog+0x3f1/0x14c0
[ 242.714083][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 242.714085][ C0] ? rcu_is_watching+0x16/0xd0
[ 242.714087][ C0] process_backlog+0x431/0x14c0
[ 242.714090][ C0] __napi_poll+0xa7/0x3b0
[ 242.714092][ C0] net_rx_action+0x513/0xf50
[ 242.714095][ C0] ? do_raw_spin_unlock+0x59/0x250
[ 242.714097][ C0] ? __napi_poll+0x3b0/0x3b0
[ 242.714099][ C0] ? _raw_spin_unlock_irq_enable+0x5b/0x90
[ 242.714102][ C0] ? try_to_wake_up+0x153/0x1130
[ 242.714105][ C0] ? rcu_is_watching+0x16/0xd0
[ 242.714108][ C0] ? rcu_is_watching+0x16/0xd0
[ 242.714109][ C0] ? mark_held_locks+0x40/0x70
[ 242.714111][ C0] handle_softirqs+0x1d3/0x900
[ 242.714114][ C0] ? _local_bh_enable+0xc0/0xc0
[ 242.714116][ C0] ? _local_bh_enable+0xc0/0xc0
[ 242.714118][ C0] ? __dev_queue_xmit+0x974/0x1b90
[ 242.714120][ C0] do_softirq+0xac/0xe0
[ 242.714121][ C0]
[ 242.714122][ C0]
[ 242.714123][ C0] __local_bh_enable_ip+0x118/0x150
[ 242.714125][ C0] __dev_queue_xmit+0x989/0x1b90
[ 242.714127][ C0] ? rcu_read_lock_any_held+0x3c/0x90
[ 242.714130][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 242.714132][ C0] ? lock_acquire.part.0+0x60/0x280
[ 242.714133][ C0] ? find_held_lock+0x2b/0x80
[ 242.714135][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 242.714137][ C0] ? rcu_is_watching+0x16/0xd0
[ 242.714138][ C0] ? mark_held_locks+0x40/0x70
[ 242.714140][ C0] ? __asan_memcpy+0x3c/0x60
[ 242.714141][ C0] ? neigh_hh_output+0x152/0x4c0
[ 242.714144][ C0] ip6_finish_output2+0x9e0/0x13f0
[ 242.714147][ C0] ? ip6_dst_lookup+0x80/0x80
[ 242.714149][ C0] ? find_held_lock+0x2b/0x80
[ 242.714150][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 242.714152][ C0] ? ip6_mtu+0x174/0x410
[ 242.714155][ C0] ip6_finish_output+0x701/0xe80
[ 242.714162][ C0] ip6_output+0x23f/0x7f0
[ 242.714164][ C0] ? ip6_finish_output+0xe80/0xe80
[ 242.714166][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 242.714168][ C0] ? find_held_lock+0x2b/0x80
[ 242.714169][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 242.714172][ C0] ip6_xmit+0xc44/0x1ec0
[ 242.714173][ C0] ? mark_usage+0x61/0x170
[ 242.714175][ C0] ? __lock_acquire+0x518/0xc20
[ 242.714178][ C0] ? ip6_autoflowlabel+0x120/0x120
[ 242.714180][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 242.714181][ C0] ? mark_usage+0x61/0x170
[ 242.714183][ C0] ? __lock_acquire+0x518/0xc20
[ 242.714185][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 242.714187][ C0] ? inet6_csk_xmit+0xfe/0x5f0
[ 242.714189][ C0] ? rcu_is_watching+0x16/0xd0
[ 242.714190][ C0] ? lock_acquire+0x13c/0x160
[ 242.714192][ C0] inet6_csk_xmit+0x2f6/0x5f0
[ 242.714194][ C0] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 242.714199][ C0] ? __lock_acquire+0x518/0xc20
[ 242.714201][ C0] ? __tcp_select_window+0x1040/0x1040
[ 242.714203][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 242.714204][ C0] ? find_held_lock+0x2b/0x80
[ 242.714207][ C0] tcp_write_xmit+0x5a4/0x3080
[ 242.714211][ C0] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 242.714213][ C0] ? skb_attempt_defer_free+0x270/0x790
[ 242.714215][ C0] ? tcp_set_state+0x101/0x580
[ 242.714218][ C0] __tcp_push_pending_frames+0x8f/0x3b0
[ 242.714220][ C0] __tcp_close+0x84e/0xe70
[ 242.714222][ C0] tcp_close+0x23/0xb0
[ 242.714223][ C0] inet_release+0x10a/0x240
[ 242.714226][ C0] ? fcntl_setlk+0xce0/0xce0
[ 242.714229][ C0] __sock_release+0xb8/0x280
[ 242.714232][ C0] sock_close+0x18/0x20
[ 242.714234][ C0] __fput+0x36c/0xad0
[ 242.714237][ C0] fput_close_sync+0xde/0x1b0
[ 242.714239][ C0] ? alloc_file_clone+0xe0/0xe0
[ 242.714241][ C0] ? do_raw_spin_unlock+0x59/0x250
[ 242.714243][ C0] __x64_sys_close+0x8b/0xf0
[ 242.714245][ C0] do_syscall_64+0xff/0x530
[ 242.714246][ C0] ? exc_page_fault+0xee/0x100
[ 242.714248][ C0] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 242.714250][ C0] RIP: 0033:0x7fcdba7e054e
[ 242.714253][ C0] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 242.714255][ C0] RSP: 002b:00007ffeebb97fa0 EFLAGS: 00000202 ORIG_RAX: 0000000000000003
[ 242.714259][ C0] RAX: ffffffffffffffda RBX: 0000000000000010 RCX: 00007fcdba7e054e
[ 242.714260][ C0] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000011
[ 242.714261][ C0] RBP: 00007ffeebb97fb0 R08: 0000000000000000 R09: 0000000000000000
[ 242.714262][ C0] R10: 0000000000000000 R11: 0000000000000202 R12: 00000000000026f7
[ 242.714263][ C0] R13: 0000000000000000 R14: 000000000000001c R15: 000000000000000a
[ 242.714265][ C0]
[ 242.714266][ C0]
[ 242.733089][ C0] The buggy address belongs to the object at ff1100000af6cea8
[ 242.733089][ C0] which belongs to the cache tw_sock_TCPv6 of size 288
[ 242.733493][ C0] The buggy address is located 144 bytes inside of
[ 242.733493][ C0] allocated 288-byte region [ff1100000af6cea8, ff1100000af6cfc8)
[ 242.733894][ C0]
[ 242.733970][ C0] The buggy address belongs to the physical page:
[ 242.734159][ C0] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000af6cb68 pfn:0xaf6c
[ 242.734463][ C0] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 242.734690][ C0] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 242.734884][ C0] page_type: f5(slab)
[ 242.735004][ C0] raw: 0080000000000240 ff11000005e0fe40 ff11000005e170c8 ff11000005e170c8
[ 242.735275][ C0] raw: ff1100000af6cb68 0000000000130007 00000000f5000000 0000000000000000
[ 242.735543][ C0] head: 0080000000000240 ff11000005e0fe40 ff11000005e170c8 ff11000005e170c8
[ 242.735812][ C0] head: ff1100000af6cb68 0000000000130007 00000000f5000000 0000000000000000
[ 242.736083][ C0] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 242.736347][ C0] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 242.736613][ C0] page dumped because: kasan: bad access detected
[ 242.736796][ C0]
[ 242.736872][ C0] Memory state around the buggy address:
[ 242.737016][ C0] ff1100000af6ce00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 242.737244][ C0] ff1100000af6ce80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 242.737466][ C0] >ff1100000af6cf00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 242.737685][ C0] ^
[ 242.737869][ C0] ff1100000af6cf80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 242.738085][ C0] ff1100000af6d000: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 242.738303][ C0] ==================================================================
[ 242.738528][ C0] Disabling lock debugging due to kernel taint