[ 1256.166830][ C1] ==================================================================
[ 1256.167266][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0
[ 1256.167629][ C1] Read of size 8 at addr ff110000109b5278 by task tcp_fastopen_ba/22340
[ 1256.167931][ C1]
[ 1256.168080][ C1] CPU: 1 UID: 0 PID: 22340 Comm: tcp_fastopen_ba Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 1256.168086][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 1256.168088][ C1] Call Trace:
[ 1256.168090][ C1]
[ 1256.168092][ C1] dump_stack_lvl+0x6f/0xa0
[ 1256.168098][ C1] print_address_description.constprop.0+0x56/0x2d0
[ 1256.168104][ C1] print_report+0xfc/0x1fa
[ 1256.168106][ C1] ? __virt_addr_valid+0x102/0x440
[ 1256.168110][ C1] ? __virt_addr_valid+0x1da/0x440
[ 1256.168112][ C1] kasan_report+0x108/0x130
[ 1256.168116][ C1] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1256.168119][ C1] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1256.168123][ C1] kasan_check_range+0x130/0x200
[ 1256.168130][ C1] ? make_kuid+0x13/0x20
[ 1256.168136][ C1] tcp_v6_send_response+0xe7d/0x24e0
[ 1256.168142][ C1] ? __mod_timer+0x3ad/0xc60
[ 1256.168148][ C1] ? tcp_v6_send_synack+0xe10/0xe10
[ 1256.168150][ C1] ? __lock_acquire+0x518/0xc20
[ 1256.168154][ C1] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 1256.168163][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 1256.168166][ C1] ? rcu_is_watching+0x16/0xd0
[ 1256.168171][ C1] tcp_v6_rcv+0x24c5/0x3250
[ 1256.168178][ C1] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 1256.168180][ C1] ? find_held_lock+0x2b/0x80
[ 1256.168186][ C1] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 1256.168192][ C1] ip6_input_finish+0x196/0x590
[ 1256.168195][ C1] ip6_input+0x130/0x570
[ 1256.168196][ C1] ? rcu_read_lock_any_held+0x66/0x90
[ 1256.168200][ C1] ? ip6_input_finish+0x590/0x590
[ 1256.168202][ C1] ? ip6_rcv_core+0xde3/0x1be0
[ 1256.168204][ C1] ? __asan_memset+0x27/0x50
[ 1256.168208][ C1] ? ip6_rcv_core+0xded/0x1be0
[ 1256.168211][ C1] ipv6_rcv+0x3c1/0x5a0
[ 1256.168213][ C1] ? ip6_rcv_core+0x1be0/0x1be0
[ 1256.168215][ C1] ? entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1256.168218][ C1] ? mark_usage+0x61/0x170
[ 1256.168220][ C1] ? __lock_acquire+0x518/0xc20
[ 1256.168224][ C1] ? process_backlog+0x3f1/0x14c0
[ 1256.168227][ C1] __netif_receive_skb_one_core+0xfc/0x180
[ 1256.168230][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 1256.168232][ C1] ? process_backlog+0x3f1/0x14c0
[ 1256.168235][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 1256.168237][ C1] ? rcu_is_watching+0x16/0xd0
[ 1256.168240][ C1] process_backlog+0x431/0x14c0
[ 1256.168243][ C1] ? rcu_read_lock_any_held+0x3c/0x90
[ 1256.168246][ C1] __napi_poll+0xa7/0x3b0
[ 1256.168249][ C1] net_rx_action+0x513/0xf50
[ 1256.168253][ C1] ? __lock_acquire+0x518/0xc20
[ 1256.168255][ C1] ? __napi_poll+0x3b0/0x3b0
[ 1256.168261][ C1] ? ktime_get_update_offsets_now+0x2a8/0x490
[ 1256.168264][ C1] ? mark_held_locks+0x40/0x70
[ 1256.168267][ C1] handle_softirqs+0x1d3/0x900
[ 1256.168271][ C1] ? _local_bh_enable+0xc0/0xc0
[ 1256.168273][ C1] ? do_raw_spin_unlock+0x59/0x250
[ 1256.168276][ C1] ? rcu_is_watching+0x16/0xd0
[ 1256.168278][ C1] ? __dev_queue_xmit+0x974/0x1b90
[ 1256.168281][ C1] do_softirq+0xac/0xe0
[ 1256.168283][ C1]
[ 1256.168284][ C1]
[ 1256.168285][ C1] __local_bh_enable_ip+0x118/0x150
[ 1256.168288][ C1] __dev_queue_xmit+0x989/0x1b90
[ 1256.168290][ C1] ? __lock_acquire+0x518/0xc20
[ 1256.168294][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 1256.168297][ C1] ? lock_acquire.part.0+0x60/0x280
[ 1256.168299][ C1] ? find_held_lock+0x2b/0x80
[ 1256.168301][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 1256.168303][ C1] ? rcu_is_watching+0x16/0xd0
[ 1256.168305][ C1] ? mark_held_locks+0x40/0x70
[ 1256.168308][ C1] ? __asan_memcpy+0x3c/0x60
[ 1256.168310][ C1] ? neigh_hh_output+0x152/0x4c0
[ 1256.168313][ C1] ip6_finish_output2+0x9e0/0x13f0
[ 1256.168316][ C1] ? ip6_dst_lookup+0x80/0x80
[ 1256.168318][ C1] ? find_held_lock+0x2b/0x80
[ 1256.168321][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 1256.168323][ C1] ? ip6_mtu+0x174/0x410
[ 1256.168328][ C1] ip6_finish_output+0x701/0xe80
[ 1256.168331][ C1] ip6_output+0x23f/0x7f0
[ 1256.168334][ C1] ? ip6_finish_output+0xe80/0xe80
[ 1256.168337][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 1256.168339][ C1] ? find_held_lock+0x2b/0x80
[ 1256.168342][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 1256.168346][ C1] ip6_xmit+0xc44/0x1ec0
[ 1256.168348][ C1] ? mark_usage+0x61/0x170
[ 1256.168351][ C1] ? __lock_acquire+0x518/0xc20
[ 1256.168355][ C1] ? ip6_autoflowlabel+0x120/0x120
[ 1256.168358][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 1256.168360][ C1] ? mark_usage+0x61/0x170
[ 1256.168363][ C1] ? __lock_acquire+0x518/0xc20
[ 1256.168366][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 1256.168368][ C1] ? inet6_csk_xmit+0xfe/0x5f0
[ 1256.168371][ C1] ? rcu_is_watching+0x16/0xd0
[ 1256.168373][ C1] ? lock_acquire+0x13c/0x160
[ 1256.168376][ C1] inet6_csk_xmit+0x2f6/0x5f0
[ 1256.168380][ C1] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 1256.168385][ C1] ? __lock_acquire+0x518/0xc20
[ 1256.168388][ C1] ? __tcp_select_window+0x1040/0x1040
[ 1256.168391][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 1256.168393][ C1] ? find_held_lock+0x2b/0x80
[ 1256.168398][ C1] tcp_write_xmit+0x5a4/0x3080
[ 1256.168403][ C1] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 1256.168406][ C1] ? skb_attempt_defer_free+0x270/0x790
[ 1256.168409][ C1] ? tcp_set_state+0x101/0x580
[ 1256.168412][ C1] __tcp_push_pending_frames+0x8f/0x3b0
[ 1256.168415][ C1] __tcp_close+0x84e/0xe70
[ 1256.168418][ C1] tcp_close+0x23/0xb0
[ 1256.168420][ C1] inet_release+0x10a/0x240
[ 1256.168424][ C1] ? fcntl_setlk+0xce0/0xce0
[ 1256.168428][ C1] __sock_release+0xb8/0x280
[ 1256.168432][ C1] sock_close+0x18/0x20
[ 1256.168434][ C1] __fput+0x36c/0xad0
[ 1256.168438][ C1] fput_close_sync+0xde/0x1b0
[ 1256.168441][ C1] ? alloc_file_clone+0xe0/0xe0
[ 1256.168443][ C1] ? do_raw_spin_unlock+0x59/0x250
[ 1256.168446][ C1] __x64_sys_close+0x8b/0xf0
[ 1256.168449][ C1] do_syscall_64+0xff/0x530
[ 1256.168452][ C1] ? exc_page_fault+0xee/0x100
[ 1256.168455][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1256.168457][ C1] RIP: 0033:0x7fecfbad854e
[ 1256.168462][ C1] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 1256.168464][ C1] RSP: 002b:00007ffe2a1cda40 EFLAGS: 00000202 ORIG_RAX: 0000000000000003
[ 1256.168469][ C1] RAX: ffffffffffffffda RBX: 0000000000000010 RCX: 00007fecfbad854e
[ 1256.168471][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000011
[ 1256.168472][ C1] RBP: 00007ffe2a1cda50 R08: 0000000000000000 R09: 0000000000000000
[ 1256.168473][ C1] R10: 0000000000000000 R11: 0000000000000202 R12: 00000000000026bb
[ 1256.168475][ C1] R13: 0000000000000000 R14: 000000000000001c R15: 000000000000000a
[ 1256.168478][ C1]
[ 1256.168480][ C1]
[ 1256.195495][ C1] The buggy address belongs to the object at ff110000109b51e8
[ 1256.195495][ C1] which belongs to the cache tw_sock_TCPv6 of size 288
[ 1256.196336][ C1] The buggy address is located 144 bytes inside of
[ 1256.196336][ C1] allocated 288-byte region [ff110000109b51e8, ff110000109b5308)
[ 1256.196894][ C1]
[ 1256.197037][ C1] The buggy address belongs to the physical page:
[ 1256.197236][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff110000109b4ea8 pfn:0x109b4
[ 1256.197669][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 1256.197983][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 1256.198251][ C1] page_type: f5(slab)
[ 1256.198418][ C1] raw: 0080000000000240 ff11000006925e40 ff1100000692d0c8 ff1100000692d0c8
[ 1256.198789][ C1] raw: ff110000109b4ea8 0000000000130009 00000000f5000000 0000000000000000
[ 1256.199218][ C1] head: 0080000000000240 ff11000006925e40 ff1100000692d0c8 ff1100000692d0c8
[ 1256.199799][ C1] head: ff110000109b4ea8 0000000000130009 00000000f5000000 0000000000000000
[ 1256.200127][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 1256.200590][ C1] head: ff11000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 1256.201154][ C1] page dumped because: kasan: bad access detected
[ 1256.201516][ C1]
[ 1256.201633][ C1] Memory state around the buggy address:
[ 1256.201852][ C1] ff110000109b5100: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1256.202237][ C1] ff110000109b5180: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1256.202677][ C1] >ff110000109b5200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1256.203041][ C1] ^
[ 1256.203343][ C1] ff110000109b5280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1256.203726][ C1] ff110000109b5300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1256.204099][ C1] ==================================================================
[ 1256.204513][ C1] Disabling lock debugging due to kernel taint