[ 194.005316][ C3] ==================================================================
[ 194.005632][ C3] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0
[ 194.005879][ C3] Read of size 8 at addr ff1100000976ba98 by task reuseport_bpf/5114
[ 194.006134][ C3]
[ 194.006224][ C3] CPU: 3 UID: 0 PID: 5114 Comm: reuseport_bpf Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 194.006228][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 194.006230][ C3] Call Trace:
[ 194.006232][ C3]
[ 194.006233][ C3] dump_stack_lvl+0x6f/0xa0
[ 194.006238][ C3] print_address_description.constprop.0+0x56/0x2d0
[ 194.006243][ C3] print_report+0xfc/0x1fa
[ 194.006244][ C3] ? __virt_addr_valid+0x102/0x440
[ 194.006247][ C3] ? __virt_addr_valid+0x1da/0x440
[ 194.006249][ C3] kasan_report+0x108/0x130
[ 194.006252][ C3] ? tcp_v6_send_response+0xe7d/0x24e0
[ 194.006254][ C3] ? tcp_v6_send_response+0xe7d/0x24e0
[ 194.006257][ C3] kasan_check_range+0x130/0x200
[ 194.006258][ C3] ? make_kuid+0x13/0x20
[ 194.006261][ C3] tcp_v6_send_response+0xe7d/0x24e0
[ 194.006263][ C3] ? __mod_timer+0x3ad/0xc60
[ 194.006266][ C3] ? tcp_v6_send_synack+0xe10/0xe10
[ 194.006268][ C3] ? __lock_acquire+0x518/0xc20
[ 194.006271][ C3] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 194.006274][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 194.006276][ C3] ? rcu_is_watching+0x16/0xd0
[ 194.006279][ C3] tcp_v6_rcv+0x24c5/0x3250
[ 194.006283][ C3] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 194.006287][ C3] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 194.006291][ C3] ip6_input_finish+0x196/0x590
[ 194.006292][ C3] ip6_input+0x130/0x570
[ 194.006293][ C3] ? ip6_input_finish+0x590/0x590
[ 194.006294][ C3] ? ip6_rcv_core+0xde3/0x1be0
[ 194.006296][ C3] ? __asan_memset+0x27/0x50
[ 194.006298][ C3] ? ip6_rcv_core+0xded/0x1be0
[ 194.006300][ C3] ipv6_rcv+0x3c1/0x5a0
[ 194.006301][ C3] ? ip6_rcv_core+0x1be0/0x1be0
[ 194.006303][ C3] ? rcu_is_watching+0x16/0xd0
[ 194.006304][ C3] ? __update_load_avg_cfs_rq+0x36c/0x10c0
[ 194.006307][ C3] ? mark_usage+0x61/0x170
[ 194.006308][ C3] ? __lock_acquire+0x518/0xc20
[ 194.006310][ C3] ? irq_matrix_free+0x487/0x600
[ 194.006313][ C3] ? process_backlog+0x3f1/0x14c0
[ 194.006317][ C3] __netif_receive_skb_one_core+0xfc/0x180
[ 194.006319][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 194.006320][ C3] ? process_backlog+0x3f1/0x14c0
[ 194.006322][ C3] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 194.006324][ C3] ? rcu_is_watching+0x16/0xd0
[ 194.006326][ C3] process_backlog+0x431/0x14c0
[ 194.006329][ C3] __napi_poll+0xa7/0x3b0
[ 194.006331][ C3] net_rx_action+0x513/0xf50
[ 194.006334][ C3] ? __lock_acquire+0x518/0xc20
[ 194.006335][ C3] ? __napi_poll+0x3b0/0x3b0
[ 194.006339][ C3] ? ktime_get_update_offsets_now+0x2a8/0x490
[ 194.006341][ C3] ? mark_held_locks+0x40/0x70
[ 194.006343][ C3] handle_softirqs+0x1d3/0x900
[ 194.006347][ C3] ? _local_bh_enable+0xc0/0xc0
[ 194.006348][ C3] ? do_raw_spin_unlock+0x59/0x250
[ 194.006351][ C3] ? rcu_is_watching+0x16/0xd0
[ 194.006352][ C3] ? __dev_queue_xmit+0x974/0x1b90
[ 194.006354][ C3] do_softirq+0xac/0xe0
[ 194.006355][ C3]
[ 194.006356][ C3]
[ 194.006357][ C3] __local_bh_enable_ip+0x118/0x150
[ 194.006358][ C3] __dev_queue_xmit+0x989/0x1b90
[ 194.006360][ C3] ? find_held_lock+0x2b/0x80
[ 194.006363][ C3] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 194.006365][ C3] ? lock_acquire.part.0+0x60/0x280
[ 194.006366][ C3] ? find_held_lock+0x2b/0x80
[ 194.006368][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 194.006370][ C3] ? rcu_is_watching+0x16/0xd0
[ 194.006371][ C3] ? mark_held_locks+0x40/0x70
[ 194.006372][ C3] ? __asan_memcpy+0x3c/0x60
[ 194.006374][ C3] ? neigh_hh_output+0x152/0x4c0
[ 194.006377][ C3] ip6_finish_output2+0x9e0/0x13f0
[ 194.006380][ C3] ? ip6_dst_lookup+0x80/0x80
[ 194.006382][ C3] ? find_held_lock+0x2b/0x80
[ 194.006383][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 194.006385][ C3] ? ip6_mtu+0x174/0x410
[ 194.006388][ C3] ip6_finish_output+0x701/0xe80
[ 194.006391][ C3] ip6_output+0x23f/0x7f0
[ 194.006393][ C3] ? ip6_finish_output+0xe80/0xe80
[ 194.006395][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 194.006397][ C3] ? find_held_lock+0x2b/0x80
[ 194.006398][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 194.006400][ C3] ip6_xmit+0xc44/0x1ec0
[ 194.006402][ C3] ? mark_usage+0x61/0x170
[ 194.006404][ C3] ? __lock_acquire+0x518/0xc20
[ 194.006406][ C3] ? ip6_autoflowlabel+0x120/0x120
[ 194.006408][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 194.006410][ C3] ? mark_usage+0x61/0x170
[ 194.006412][ C3] ? __lock_acquire+0x518/0xc20
[ 194.006414][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 194.006415][ C3] ? inet6_csk_xmit+0xfe/0x5f0
[ 194.006418][ C3] ? rcu_is_watching+0x16/0xd0
[ 194.006419][ C3] ? lock_acquire+0x13c/0x160
[ 194.006421][ C3] inet6_csk_xmit+0x2f6/0x5f0
[ 194.006424][ C3] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 194.006428][ C3] ? __lock_acquire+0x518/0xc20
[ 194.006430][ C3] ? __tcp_select_window+0x1040/0x1040
[ 194.006432][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 194.006433][ C3] ? find_held_lock+0x2b/0x80
[ 194.006436][ C3] tcp_write_xmit+0x5a4/0x3080
[ 194.006440][ C3] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 194.006442][ C3] ? tcp_set_state+0x101/0x580
[ 194.006445][ C3] __tcp_push_pending_frames+0x8f/0x3b0
[ 194.006447][ C3] __tcp_close+0x84e/0xe70
[ 194.006448][ C3] ? mark_held_locks+0x40/0x70
[ 194.006450][ C3] tcp_close+0x23/0xb0
[ 194.006452][ C3] inet_release+0x10a/0x240
[ 194.006455][ C3] ? fcntl_setlk+0xce0/0xce0
[ 194.006458][ C3] __sock_release+0xb8/0x280
[ 194.006461][ C3] sock_close+0x18/0x20
[ 194.006462][ C3] __fput+0x36c/0xad0
[ 194.006465][ C3] fput_close_sync+0xde/0x1b0
[ 194.006467][ C3] ? alloc_file_clone+0xe0/0xe0
[ 194.006469][ C3] ? do_raw_spin_unlock+0x59/0x250
[ 194.006471][ C3] __x64_sys_close+0x8b/0xf0
[ 194.006473][ C3] do_syscall_64+0xff/0x530
[ 194.006476][ C3] ? irq_exit_rcu+0x1a/0x30
[ 194.006477][ C3] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 194.006480][ C3] RIP: 0033:0x7f64c27f654e
[ 194.006483][ C3] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 194.006484][ C3] RSP: 002b:00007ffc2f3e3d80 EFLAGS: 00000202 ORIG_RAX: 0000000000000003
[ 194.006488][ C3] RAX: ffffffffffffffda RBX: 00007ffc2f3e3ec0 RCX: 00007f64c27f654e
[ 194.006489][ C3] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000036
[ 194.006490][ C3] RBP: 00007ffc2f3e3d90 R08: 0000000000000000 R09: 0000000000000000
[ 194.006491][ C3] R10: 0000000000000000 R11: 0000000000000202 R12: 00000000000023fd
[ 194.006492][ C3] R13: 000000000000000a R14: 0000000000000036 R15: 000000000000000a
[ 194.006494][ C3]
[ 194.006495][ C3]
[ 194.027109][ C3] The buggy address belongs to the object at ff1100000976ba08
[ 194.027109][ C3] which belongs to the cache tw_sock_TCPv6 of size 288
[ 194.027567][ C3] The buggy address is located 144 bytes inside of
[ 194.027567][ C3] allocated 288-byte region [ff1100000976ba08, ff1100000976bb28)
[ 194.027999][ C3]
[ 194.028081][ C3] The buggy address belongs to the physical page:
[ 194.028278][ C3] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000976b6c8 pfn:0x976a
[ 194.028609][ C3] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 194.028863][ C3] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 194.029070][ C3] page_type: f5(slab)
[ 194.029199][ C3] raw: 0080000000000240 ff11000006313e40 ff1100000631b0c8 ff1100000631b0c8
[ 194.029495][ C3] raw: ff1100000976b6c8 000000000013000e 00000000f5000000 0000000000000000
[ 194.029789][ C3] head: 0080000000000240 ff11000006313e40 ff1100000631b0c8 ff1100000631b0c8
[ 194.030100][ C3] head: ff1100000976b6c8 000000000013000e 00000000f5000000 0000000000000000
[ 194.030390][ C3] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 194.030677][ C3] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 194.030963][ C3] page dumped because: kasan: bad access detected
[ 194.031163][ C3]
[ 194.031244][ C3] Memory state around the buggy address:
[ 194.031402][ C3] ff1100000976b980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 194.031654][ C3] ff1100000976ba00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 194.031890][ C3] >ff1100000976ba80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 194.032121][ C3] ^
[ 194.032277][ C3] ff1100000976bb00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 194.032509][ C3] ff1100000976bb80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 194.032753][ C3] ==================================================================
[ 194.032995][ C3] Disabling lock debugging due to kernel taint