[ 97.669838][ C3] ================================================================== [ 97.670164][ C3] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0 [ 97.670418][ C3] Read of size 8 at addr ff1100000d2a6578 by task reuseport_bpf/2032 [ 97.670658][ C3] [ 97.670741][ C3] CPU: 3 UID: 0 PID: 2032 Comm: reuseport_bpf Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 97.670745][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 97.670747][ C3] Call Trace: [ 97.670749][ C3] [ 97.670750][ C3] dump_stack_lvl+0x6f/0xa0 [ 97.670755][ C3] print_address_description.constprop.0+0x56/0x2d0 [ 97.670759][ C3] print_report+0xfc/0x1fa [ 97.670760][ C3] ? __virt_addr_valid+0x102/0x440 [ 97.670763][ C3] ? __virt_addr_valid+0x1da/0x440 [ 97.670765][ C3] kasan_report+0x108/0x130 [ 97.670768][ C3] ? tcp_v6_send_response+0xe7d/0x24e0 [ 97.670770][ C3] ? tcp_v6_send_response+0xe7d/0x24e0 [ 97.670773][ C3] kasan_check_range+0x130/0x200 [ 97.670774][ C3] ? make_kuid+0x13/0x20 [ 97.670777][ C3] tcp_v6_send_response+0xe7d/0x24e0 [ 97.670779][ C3] ? __mod_timer+0x3ad/0xc60 [ 97.670783][ C3] ? tcp_v6_send_synack+0xe10/0xe10 [ 97.670784][ C3] ? __lock_acquire+0x518/0xc20 [ 97.670787][ C3] ? logarithmic_accumulation.constprop.0+0x115/0x350 [ 97.670790][ C3] ? __lock_release.isra.0+0x69/0x1a0 [ 97.670792][ C3] ? rcu_is_watching+0x16/0xd0 [ 97.670795][ C3] tcp_v6_rcv+0x24c5/0x3250 [ 97.670799][ C3] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90 [ 97.670802][ C3] ? __lock_acquire+0x518/0xc20 [ 97.670804][ C3] ip6_protocol_deliver_rcu+0x15c/0x1480 [ 97.670808][ C3] ip6_input_finish+0x196/0x590 [ 97.670809][ C3] ip6_input+0x130/0x570 [ 97.670810][ C3] ? find_held_lock+0x2b/0x80 [ 97.670812][ C3] ? ip6_input_finish+0x590/0x590 [ 97.670813][ C3] ? ip6_rcv_core+0xde3/0x1be0 [ 97.670814][ C3] ? __asan_memset+0x27/0x50 [ 97.670817][ C3] ? ip6_rcv_core+0xded/0x1be0 [ 97.670819][ C3] ipv6_rcv+0x3c1/0x5a0 [ 97.670820][ C3] ? ip6_rcv_core+0x1be0/0x1be0 [ 97.670821][ C3] ? rcu_is_watching+0x16/0xd0 [ 97.670822][ C3] ? __update_load_avg_cfs_rq+0x36c/0x10c0 [ 97.670825][ C3] ? mark_usage+0x61/0x170 [ 97.670827][ C3] ? __lock_acquire+0x518/0xc20 [ 97.670829][ C3] ? irq_matrix_free+0x487/0x600 [ 97.670832][ C3] ? process_backlog+0x3f1/0x14c0 [ 97.670835][ C3] __netif_receive_skb_one_core+0xfc/0x180 [ 97.670837][ C3] ? lock_acquire.part.0+0xd4/0x280 [ 97.670839][ C3] ? process_backlog+0x3f1/0x14c0 [ 97.670841][ C3] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 97.670843][ C3] ? rcu_is_watching+0x16/0xd0 [ 97.670844][ C3] process_backlog+0x431/0x14c0 [ 97.670847][ C3] ? rcu_read_lock_any_held+0x3c/0x90 [ 97.670849][ C3] __napi_poll+0xa7/0x3b0 [ 97.670851][ C3] net_rx_action+0x513/0xf50 [ 97.670854][ C3] ? __lock_acquire+0x518/0xc20 [ 97.670856][ C3] ? __napi_poll+0x3b0/0x3b0 [ 97.670860][ C3] ? ktime_get_update_offsets_now+0x2a8/0x490 [ 97.670862][ C3] ? mark_held_locks+0x40/0x70 [ 97.670864][ C3] handle_softirqs+0x1d3/0x900 [ 97.670867][ C3] ? _local_bh_enable+0xc0/0xc0 [ 97.670869][ C3] ? do_raw_spin_unlock+0x59/0x250 [ 97.670871][ C3] ? rcu_is_watching+0x16/0xd0 [ 97.670872][ C3] ? __dev_queue_xmit+0x974/0x1b90 [ 97.670874][ C3] do_softirq+0xac/0xe0 [ 97.670876][ C3] [ 97.670876][ C3] [ 97.670877][ C3] __local_bh_enable_ip+0x118/0x150 [ 97.670879][ C3] __dev_queue_xmit+0x989/0x1b90 [ 97.670881][ C3] ? find_held_lock+0x2b/0x80 [ 97.670883][ C3] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 97.670885][ C3] ? lock_acquire.part.0+0x60/0x280 [ 97.670886][ C3] ? find_held_lock+0x2b/0x80 [ 97.670888][ C3] ? __lock_release.isra.0+0x69/0x1a0 [ 97.670889][ C3] ? rcu_is_watching+0x16/0xd0 [ 97.670891][ C3] ? mark_held_locks+0x40/0x70 [ 97.670892][ C3] ? __asan_memcpy+0x3c/0x60 [ 97.670894][ C3] ? neigh_hh_output+0x152/0x4c0 [ 97.670897][ C3] ip6_finish_output2+0x9e0/0x13f0 [ 97.670900][ C3] ? ip6_dst_lookup+0x80/0x80 [ 97.670902][ C3] ? find_held_lock+0x2b/0x80 [ 97.670903][ C3] ? __lock_release.isra.0+0x69/0x1a0 [ 97.670905][ C3] ? ip6_mtu+0x174/0x410 [ 97.670908][ C3] ip6_finish_output+0x701/0xe80 [ 97.670910][ C3] ip6_output+0x23f/0x7f0 [ 97.670913][ C3] ? ip6_finish_output+0xe80/0xe80 [ 97.670914][ C3] ? lock_acquire.part.0+0xd4/0x280 [ 97.670916][ C3] ? find_held_lock+0x2b/0x80 [ 97.670918][ C3] ? __lock_release.isra.0+0x69/0x1a0 [ 97.670920][ C3] ip6_xmit+0xc44/0x1ec0 [ 97.670922][ C3] ? mark_usage+0x61/0x170 [ 97.670924][ C3] ? __lock_acquire+0x518/0xc20 [ 97.670926][ C3] ? ip6_autoflowlabel+0x120/0x120 [ 97.670928][ C3] ? __lock_release.isra.0+0x69/0x1a0 [ 97.670930][ C3] ? mark_usage+0x61/0x170 [ 97.670931][ C3] ? __lock_acquire+0x518/0xc20 [ 97.670934][ C3] ? lock_acquire.part.0+0xd4/0x280 [ 97.670935][ C3] ? inet6_csk_xmit+0xfe/0x5f0 [ 97.670937][ C3] ? rcu_is_watching+0x16/0xd0 [ 97.670939][ C3] ? lock_acquire+0x13c/0x160 [ 97.670941][ C3] inet6_csk_xmit+0x2f6/0x5f0 [ 97.670943][ C3] __tcp_transmit_skb+0x1c3e/0x3cd0 [ 97.670947][ C3] ? __lock_acquire+0x518/0xc20 [ 97.670949][ C3] ? __tcp_select_window+0x1040/0x1040 [ 97.670951][ C3] ? lock_acquire.part.0+0xd4/0x280 [ 97.670953][ C3] ? find_held_lock+0x2b/0x80 [ 97.670956][ C3] tcp_write_xmit+0x5a4/0x3080 [ 97.670960][ C3] ? tcp_retrans_try_collapse+0x1090/0x1090 [ 97.670962][ C3] ? tcp_set_state+0x101/0x580 [ 97.670964][ C3] __tcp_push_pending_frames+0x8f/0x3b0 [ 97.670966][ C3] __tcp_close+0x84e/0xe70 [ 97.670968][ C3] ? mark_held_locks+0x40/0x70 [ 97.670970][ C3] tcp_close+0x23/0xb0 [ 97.670971][ C3] inet_release+0x10a/0x240 [ 97.670974][ C3] ? fcntl_setlk+0xce0/0xce0 [ 97.670977][ C3] __sock_release+0xb8/0x280 [ 97.670981][ C3] sock_close+0x18/0x20 [ 97.670982][ C3] __fput+0x36c/0xad0 [ 97.670985][ C3] fput_close_sync+0xde/0x1b0 [ 97.670987][ C3] ? alloc_file_clone+0xe0/0xe0 [ 97.670989][ C3] ? do_raw_spin_unlock+0x59/0x250 [ 97.670991][ C3] __x64_sys_close+0x8b/0xf0 [ 97.670993][ C3] do_syscall_64+0xff/0x530 [ 97.670995][ C3] ? irq_exit_rcu+0x1a/0x30 [ 97.670997][ C3] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 97.670999][ C3] RIP: 0033:0x7f691a4f254e [ 97.671002][ C3] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 97.671004][ C3] RSP: 002b:00007fff0c298ef0 EFLAGS: 00000202 ORIG_RAX: 0000000000000003 [ 97.671007][ C3] RAX: ffffffffffffffda RBX: 00007fff0c299030 RCX: 00007f691a4f254e [ 97.671008][ C3] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000039 [ 97.671009][ C3] RBP: 00007fff0c298f00 R08: 0000000000000000 R09: 0000000000000000 [ 97.671010][ C3] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000002409 [ 97.671011][ C3] R13: 000000000000000a R14: 0000000000000039 R15: 000000000000000a [ 97.671014][ C3] [ 97.671014][ C3] [ 97.692527][ C3] The buggy address belongs to the object at ff1100000d2a64e8 [ 97.692527][ C3] which belongs to the cache tw_sock_TCPv6 of size 288 [ 97.692979][ C3] The buggy address is located 144 bytes inside of [ 97.692979][ C3] allocated 288-byte region [ff1100000d2a64e8, ff1100000d2a6608) [ 97.693435][ C3] [ 97.693521][ C3] The buggy address belongs to the physical page: [ 97.693742][ C3] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000d2a61a8 pfn:0xd2a6 [ 97.694097][ C3] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 97.694363][ C3] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 97.694581][ C3] page_type: f5(slab) [ 97.694714][ C3] raw: 0080000000000240 ff110000062e5e40 ff110000063990c8 ff110000063990c8 [ 97.695016][ C3] raw: ff1100000d2a61a8 0000000000130001 00000000f5000000 0000000000000000 [ 97.695315][ C3] head: 0080000000000240 ff110000062e5e40 ff110000063990c8 ff110000063990c8 [ 97.695637][ C3] head: ff1100000d2a61a8 0000000000130001 00000000f5000000 0000000000000000 [ 97.696034][ C3] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 97.696360][ C3] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 97.696676][ C3] page dumped because: kasan: bad access detected [ 97.696894][ C3] [ 97.696974][ C3] Memory state around the buggy address: [ 97.697145][ C3] ff1100000d2a6400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 97.697388][ C3] ff1100000d2a6480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 97.697627][ C3] >ff1100000d2a6500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 97.697874][ C3] ^ [ 97.698110][ C3] ff1100000d2a6580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 97.698352][ C3] ff1100000d2a6600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 97.698592][ C3] ================================================================== [ 97.698836][ C3] Disabling lock debugging due to kernel taint [ 98.420194][ C0] clocksource: Watchdog remote CPU 2 read timed out