[ 216.407009][ C2] ================================================================== [ 216.407355][ C2] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0 [ 216.407605][ C2] Read of size 8 at addr ff1100000f760578 by task msg_zerocopy/1120 [ 216.407852][ C2] [ 216.407943][ C2] CPU: 2 UID: 0 PID: 1120 Comm: msg_zerocopy Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 216.407947][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 216.407949][ C2] Call Trace: [ 216.407950][ C2] [ 216.407952][ C2] dump_stack_lvl+0x6f/0xa0 [ 216.407957][ C2] print_address_description.constprop.0+0x56/0x2d0 [ 216.407961][ C2] print_report+0xfc/0x1fa [ 216.407963][ C2] ? __virt_addr_valid+0x102/0x440 [ 216.407966][ C2] ? __virt_addr_valid+0x1da/0x440 [ 216.407967][ C2] kasan_report+0x108/0x130 [ 216.407970][ C2] ? tcp_v6_send_response+0xe7d/0x24e0 [ 216.407972][ C2] ? tcp_v6_send_response+0xe7d/0x24e0 [ 216.407975][ C2] kasan_check_range+0x130/0x200 [ 216.407977][ C2] ? make_kuid+0x13/0x20 [ 216.407980][ C2] tcp_v6_send_response+0xe7d/0x24e0 [ 216.407981][ C2] ? __mod_timer+0x3ad/0xc60 [ 216.407985][ C2] ? tcp_v6_send_synack+0xe10/0xe10 [ 216.407987][ C2] ? __lock_acquire+0x518/0xc20 [ 216.407990][ C2] ? logarithmic_accumulation.constprop.0+0x115/0x350 [ 216.407993][ C2] ? __lock_release.isra.0+0x69/0x1a0 [ 216.407994][ C2] ? rcu_is_watching+0x16/0xd0 [ 216.407997][ C2] tcp_v6_rcv+0x24c5/0x3250 [ 216.408001][ C2] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90 [ 216.408005][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480 [ 216.408009][ C2] ip6_input_finish+0x196/0x590 [ 216.408010][ C2] ip6_input+0x130/0x570 [ 216.408012][ C2] ? ip6_input_finish+0x590/0x590 [ 216.408014][ C2] ? ip6_rcv_core+0xe22/0x1be0 [ 216.408016][ C2] ipv6_rcv+0x3c1/0x5a0 [ 216.408017][ C2] ? ip6_rcv_core+0x1be0/0x1be0 [ 216.408018][ C2] ? rcu_is_watching+0x16/0xd0 [ 216.408019][ C2] ? __update_load_avg_cfs_rq+0x36c/0x10c0 [ 216.408022][ C2] ? mark_usage+0x61/0x170 [ 216.408024][ C2] ? __lock_acquire+0x518/0xc20 [ 216.408025][ C2] ? irq_matrix_free+0x487/0x600 [ 216.408029][ C2] ? process_backlog+0x3f1/0x14c0 [ 216.408032][ C2] __netif_receive_skb_one_core+0xfc/0x180 [ 216.408034][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 216.408036][ C2] ? process_backlog+0x3f1/0x14c0 [ 216.408038][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 216.408040][ C2] ? rcu_is_watching+0x16/0xd0 [ 216.408042][ C2] process_backlog+0x431/0x14c0 [ 216.408044][ C2] __napi_poll+0xa7/0x3b0 [ 216.408047][ C2] net_rx_action+0x513/0xf50 [ 216.408049][ C2] ? __lock_acquire+0x518/0xc20 [ 216.408051][ C2] ? __napi_poll+0x3b0/0x3b0 [ 216.408055][ C2] ? ktime_get_update_offsets_now+0x2a8/0x490 [ 216.408057][ C2] ? mark_held_locks+0x40/0x70 [ 216.408059][ C2] handle_softirqs+0x1d3/0x900 [ 216.408062][ C2] ? _local_bh_enable+0xc0/0xc0 [ 216.408064][ C2] ? do_raw_spin_unlock+0x59/0x250 [ 216.408066][ C2] ? rcu_is_watching+0x16/0xd0 [ 216.408067][ C2] ? __dev_queue_xmit+0x974/0x1b90 [ 216.408069][ C2] do_softirq+0xac/0xe0 [ 216.408071][ C2] [ 216.408072][ C2] [ 216.408072][ C2] __local_bh_enable_ip+0x118/0x150 [ 216.408074][ C2] __dev_queue_xmit+0x989/0x1b90 [ 216.408076][ C2] ? __lock_acquire+0x518/0xc20 [ 216.408078][ C2] ? irq_matrix_allocated+0xfe/0x120 [ 216.408081][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 216.408082][ C2] ? find_held_lock+0x2b/0x80 [ 216.408084][ C2] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 216.408086][ C2] ? __asan_memcpy+0x3c/0x60 [ 216.408089][ C2] ? eth_header+0x14c/0x180 [ 216.408091][ C2] ? neigh_resolve_output.part.0+0x344/0x740 [ 216.408095][ C2] ip6_finish_output2+0x48d/0x13f0 [ 216.408098][ C2] ? ip6_dst_lookup+0x80/0x80 [ 216.408100][ C2] ? find_held_lock+0x2b/0x80 [ 216.408102][ C2] ? __lock_release.isra.0+0x69/0x1a0 [ 216.408104][ C2] ? ip6_mtu+0x174/0x410 [ 216.408107][ C2] ip6_finish_output+0x701/0xe80 [ 216.408109][ C2] ip6_output+0x23f/0x7f0 [ 216.408111][ C2] ? ip6_finish_output+0xe80/0xe80 [ 216.408113][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 216.408115][ C2] ? find_held_lock+0x2b/0x80 [ 216.408116][ C2] ? __lock_release.isra.0+0x69/0x1a0 [ 216.408119][ C2] ip6_xmit+0xc44/0x1ec0 [ 216.408121][ C2] ? find_held_lock+0x2b/0x80 [ 216.408123][ C2] ? ip6_autoflowlabel+0x120/0x120 [ 216.408125][ C2] ? find_held_lock+0x2b/0x80 [ 216.408127][ C2] ? mark_usage+0x61/0x170 [ 216.408128][ C2] ? __lock_acquire+0x518/0xc20 [ 216.408131][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 216.408132][ C2] ? inet6_csk_xmit+0xfe/0x5f0 [ 216.408135][ C2] ? rcu_is_watching+0x16/0xd0 [ 216.408136][ C2] ? inet6_csk_route_socket+0x749/0xb60 [ 216.408137][ C2] ? lock_acquire+0x13c/0x160 [ 216.408139][ C2] inet6_csk_xmit+0x2f6/0x5f0 [ 216.408142][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0 [ 216.408146][ C2] ? __lock_acquire+0x518/0xc20 [ 216.408148][ C2] ? __tcp_select_window+0x1040/0x1040 [ 216.408150][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 216.408152][ C2] ? find_held_lock+0x2b/0x80 [ 216.408155][ C2] tcp_write_xmit+0x5a4/0x3080 [ 216.408159][ C2] ? tcp_retrans_try_collapse+0x1090/0x1090 [ 216.408161][ C2] ? tcp_set_state+0x101/0x580 [ 216.408163][ C2] __tcp_push_pending_frames+0x8f/0x3b0 [ 216.408165][ C2] __tcp_close+0x84e/0xe70 [ 216.408167][ C2] ? mark_held_locks+0x40/0x70 [ 216.408169][ C2] tcp_close+0x23/0xb0 [ 216.408171][ C2] inet_release+0x10a/0x240 [ 216.408173][ C2] ? fcntl_setlk+0xce0/0xce0 [ 216.408176][ C2] __sock_release+0xb8/0x280 [ 216.408179][ C2] sock_close+0x18/0x20 [ 216.408181][ C2] __fput+0x36c/0xad0 [ 216.408184][ C2] fput_close_sync+0xde/0x1b0 [ 216.408186][ C2] ? alloc_file_clone+0xe0/0xe0 [ 216.408188][ C2] ? do_raw_spin_unlock+0x59/0x250 [ 216.408190][ C2] __x64_sys_close+0x8b/0xf0 [ 216.408192][ C2] do_syscall_64+0xff/0x530 [ 216.408195][ C2] ? irq_exit_rcu+0x1a/0x30 [ 216.408196][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 216.408199][ C2] RIP: 0033:0x7fd80d6f854e [ 216.408203][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 216.408205][ C2] RSP: 002b:00007ffd60d1ec80 EFLAGS: 00000202 ORIG_RAX: 0000000000000003 [ 216.408209][ C2] RAX: ffffffffffffffda RBX: 0000000000000006 RCX: 00007fd80d6f854e [ 216.408210][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000006 [ 216.408211][ C2] RBP: 00007ffd60d1ec90 R08: 0000000000000000 R09: 0000000000000000 [ 216.408211][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 000000000000000a [ 216.408212][ C2] R13: 00007ffd60d1edb0 R14: 0000000000000001 R15: 000001a05db05aed [ 216.408215][ C2] [ 216.408216][ C2] [ 216.428521][ C2] The buggy address belongs to the object at ff1100000f7604e8 [ 216.428521][ C2] which belongs to the cache tw_sock_TCPv6 of size 288 [ 216.429068][ C2] The buggy address is located 144 bytes inside of [ 216.429068][ C2] allocated 288-byte region [ff1100000f7604e8, ff1100000f760608) [ 216.429552][ C2] [ 216.429635][ C2] The buggy address belongs to the physical page: [ 216.429897][ C2] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000f7601a8 pfn:0xf760 [ 216.430288][ C2] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 216.430594][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 216.430808][ C2] page_type: f5(slab) [ 216.430996][ C2] raw: 0080000000000240 ff110000063c5e40 ff110000063cd0c8 ff110000063cd0c8 [ 216.431353][ C2] raw: ff1100000f7601a8 0000000000130001 00000000f5000000 0000000000000000 [ 216.431638][ C2] head: 0080000000000240 ff110000063c5e40 ff110000063cd0c8 ff110000063cd0c8 [ 216.431992][ C2] head: ff1100000f7601a8 0000000000130001 00000000f5000000 0000000000000000 [ 216.432338][ C2] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 216.432676][ C2] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 216.433028][ C2] page dumped because: kasan: bad access detected [ 216.433285][ C2] [ 216.433365][ C2] Memory state around the buggy address: [ 216.433520][ C2] ff1100000f760400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 216.433818][ C2] ff1100000f760480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 216.434108][ C2] >ff1100000f760500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 216.434397][ C2] ^ [ 216.434635][ C2] ff1100000f760580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 216.434927][ C2] ff1100000f760600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 216.435216][ C2] ================================================================== [ 216.435555][ C2] Disabling lock debugging due to kernel taint