[ 421.319326][ C2] ================================================================== [ 421.319646][ C2] BUG: KASAN: slab-use-after-free in tcp_v6_send_response+0xe7d/0x24e0 [ 421.319888][ C2] Read of size 8 at addr ff1100000cdf6d98 by task msg_zerocopy/4629 [ 421.320127][ C2] [ 421.320210][ C2] CPU: 2 UID: 0 PID: 4629 Comm: msg_zerocopy Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 421.320213][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 421.320215][ C2] Call Trace: [ 421.320217][ C2] [ 421.320218][ C2] dump_stack_lvl+0x6f/0xa0 [ 421.320223][ C2] print_address_description.constprop.0+0x56/0x2d0 [ 421.320227][ C2] print_report+0xfc/0x1fa [ 421.320229][ C2] ? __virt_addr_valid+0x102/0x440 [ 421.320232][ C2] ? __virt_addr_valid+0x1da/0x440 [ 421.320233][ C2] kasan_report+0x108/0x130 [ 421.320236][ C2] ? tcp_v6_send_response+0xe7d/0x24e0 [ 421.320239][ C2] ? tcp_v6_send_response+0xe7d/0x24e0 [ 421.320241][ C2] kasan_check_range+0x130/0x200 [ 421.320243][ C2] ? make_kuid+0x13/0x20 [ 421.320246][ C2] tcp_v6_send_response+0xe7d/0x24e0 [ 421.320247][ C2] ? __mod_timer+0x3ad/0xc60 [ 421.320251][ C2] ? tcp_v6_send_synack+0xe10/0xe10 [ 421.320253][ C2] ? __lock_acquire+0x518/0xc20 [ 421.320256][ C2] ? logarithmic_accumulation.constprop.0+0x115/0x350 [ 421.320259][ C2] ? __lock_release.isra.0+0x69/0x1a0 [ 421.320260][ C2] ? rcu_is_watching+0x16/0xd0 [ 421.320263][ C2] tcp_v6_rcv+0x24c5/0x3250 [ 421.320267][ C2] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90 [ 421.320271][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480 [ 421.320275][ C2] ip6_input_finish+0x196/0x590 [ 421.320276][ C2] ip6_input+0x130/0x570 [ 421.320277][ C2] ? ip6_input_finish+0x590/0x590 [ 421.320279][ C2] ? ip6_rcv_core+0xe22/0x1be0 [ 421.320281][ C2] ipv6_rcv+0x3c1/0x5a0 [ 421.320283][ C2] ? ip6_rcv_core+0x1be0/0x1be0 [ 421.320284][ C2] ? rcu_is_watching+0x16/0xd0 [ 421.320285][ C2] ? __update_load_avg_cfs_rq+0x36c/0x10c0 [ 421.320288][ C2] ? mark_usage+0x61/0x170 [ 421.320290][ C2] ? __lock_acquire+0x518/0xc20 [ 421.320291][ C2] ? irq_matrix_free+0x487/0x600 [ 421.320295][ C2] ? process_backlog+0x3f1/0x14c0 [ 421.320298][ C2] __netif_receive_skb_one_core+0xfc/0x180 [ 421.320300][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 421.320301][ C2] ? process_backlog+0x3f1/0x14c0 [ 421.320303][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 421.320305][ C2] ? rcu_is_watching+0x16/0xd0 [ 421.320307][ C2] process_backlog+0x431/0x14c0 [ 421.320310][ C2] __napi_poll+0xa7/0x3b0 [ 421.320312][ C2] net_rx_action+0x513/0xf50 [ 421.320315][ C2] ? __lock_acquire+0x518/0xc20 [ 421.320317][ C2] ? __napi_poll+0x3b0/0x3b0 [ 421.320321][ C2] ? ktime_get_update_offsets_now+0x2a8/0x490 [ 421.320323][ C2] ? mark_held_locks+0x40/0x70 [ 421.320325][ C2] handle_softirqs+0x1d3/0x900 [ 421.320328][ C2] ? _local_bh_enable+0xc0/0xc0 [ 421.320329][ C2] ? do_raw_spin_unlock+0x59/0x250 [ 421.320332][ C2] ? rcu_is_watching+0x16/0xd0 [ 421.320333][ C2] ? __dev_queue_xmit+0x974/0x1b90 [ 421.320335][ C2] do_softirq+0xac/0xe0 [ 421.320336][ C2] [ 421.320337][ C2] [ 421.320338][ C2] __local_bh_enable_ip+0x118/0x150 [ 421.320339][ C2] __dev_queue_xmit+0x989/0x1b90 [ 421.320341][ C2] ? __lock_acquire+0x518/0xc20 [ 421.320344][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 421.320345][ C2] ? find_held_lock+0x2b/0x80 [ 421.320347][ C2] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 421.320349][ C2] ? __asan_memcpy+0x3c/0x60 [ 421.320351][ C2] ? eth_header+0x14c/0x180 [ 421.320354][ C2] ? neigh_resolve_output.part.0+0x344/0x740 [ 421.320358][ C2] ip6_finish_output2+0x48d/0x13f0 [ 421.320361][ C2] ? ip6_dst_lookup+0x80/0x80 [ 421.320363][ C2] ? find_held_lock+0x2b/0x80 [ 421.320365][ C2] ? __lock_release.isra.0+0x69/0x1a0 [ 421.320367][ C2] ? ip6_mtu+0x174/0x410 [ 421.320370][ C2] ip6_finish_output+0x701/0xe80 [ 421.320372][ C2] ip6_output+0x23f/0x7f0 [ 421.320374][ C2] ? ip6_finish_output+0xe80/0xe80 [ 421.320376][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 421.320378][ C2] ? find_held_lock+0x2b/0x80 [ 421.320380][ C2] ? __lock_release.isra.0+0x69/0x1a0 [ 421.320382][ C2] ip6_xmit+0xc44/0x1ec0 [ 421.320384][ C2] ? find_held_lock+0x2b/0x80 [ 421.320386][ C2] ? ip6_autoflowlabel+0x120/0x120 [ 421.320388][ C2] ? find_held_lock+0x2b/0x80 [ 421.320390][ C2] ? mark_usage+0x61/0x170 [ 421.320391][ C2] ? __lock_acquire+0x518/0xc20 [ 421.320393][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 421.320395][ C2] ? inet6_csk_xmit+0xfe/0x5f0 [ 421.320397][ C2] ? rcu_is_watching+0x16/0xd0 [ 421.320398][ C2] ? inet6_csk_route_socket+0x749/0xb60 [ 421.320400][ C2] ? lock_acquire+0x13c/0x160 [ 421.320402][ C2] inet6_csk_xmit+0x2f6/0x5f0 [ 421.320405][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0 [ 421.320409][ C2] ? __lock_acquire+0x518/0xc20 [ 421.320411][ C2] ? __tcp_select_window+0x1040/0x1040 [ 421.320413][ C2] ? lock_acquire.part.0+0xd4/0x280 [ 421.320415][ C2] ? find_held_lock+0x2b/0x80 [ 421.320418][ C2] tcp_write_xmit+0x5a4/0x3080 [ 421.320422][ C2] ? tcp_retrans_try_collapse+0x1090/0x1090 [ 421.320424][ C2] ? tcp_set_state+0x101/0x580 [ 421.320426][ C2] __tcp_push_pending_frames+0x8f/0x3b0 [ 421.320428][ C2] __tcp_close+0x84e/0xe70 [ 421.320430][ C2] ? mark_held_locks+0x40/0x70 [ 421.320432][ C2] tcp_close+0x23/0xb0 [ 421.320433][ C2] inet_release+0x10a/0x240 [ 421.320436][ C2] ? fcntl_setlk+0xce0/0xce0 [ 421.320439][ C2] __sock_release+0xb8/0x280 [ 421.320443][ C2] sock_close+0x18/0x20 [ 421.320444][ C2] __fput+0x36c/0xad0 [ 421.320447][ C2] fput_close_sync+0xde/0x1b0 [ 421.320449][ C2] ? alloc_file_clone+0xe0/0xe0 [ 421.320451][ C2] ? do_raw_spin_unlock+0x59/0x250 [ 421.320453][ C2] __x64_sys_close+0x8b/0xf0 [ 421.320455][ C2] do_syscall_64+0xff/0x530 [ 421.320457][ C2] ? irq_exit_rcu+0x1a/0x30 [ 421.320459][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 421.320461][ C2] RIP: 0033:0x7f939a3af54e [ 421.320464][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 421.320466][ C2] RSP: 002b:00007fffc1a3de20 EFLAGS: 00000202 ORIG_RAX: 0000000000000003 [ 421.320470][ C2] RAX: ffffffffffffffda RBX: 0000000000000006 RCX: 00007f939a3af54e [ 421.320471][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000006 [ 421.320472][ C2] RBP: 00007fffc1a3de30 R08: 0000000000000000 R09: 0000000000000000 [ 421.320473][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 000000000000000a [ 421.320473][ C2] R13: 00007fffc1a3df50 R14: 0000000000000001 R15: 000001a05da438e9 [ 421.320476][ C2] [ 421.320476][ C2] [ 421.340634][ C2] Allocated by task 1280: [ 421.340761][ C2] kasan_save_stack+0x2f/0x50 [ 421.340930][ C2] kasan_save_track+0x14/0x30 [ 421.341145][ C2] __kasan_slab_alloc+0x60/0x70 [ 421.341302][ C2] kmem_cache_alloc_noprof+0x21f/0x5c0 [ 421.341518][ C2] inet_twsk_alloc+0x123/0x9e0 [ 421.341681][ C2] tcp_time_wait+0x5d/0x11f0 [ 421.341893][ C2] tcp_fin+0x377/0x470 [ 421.342009][ C2] tcp_data_queue+0xc1d/0x2050 [ 421.342222][ C2] tcp_rcv_state_process+0x759/0x24e0 [ 421.342378][ C2] tcp_v6_do_rcv+0x654/0x1640 [ 421.342593][ C2] tcp_v6_rcv+0x1b27/0x3250 [ 421.342751][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480 [ 421.342963][ C2] ip6_input_finish+0x196/0x590 [ 421.343118][ C2] ip6_input+0x130/0x570 [ 421.343294][ C2] ipv6_rcv+0x3c1/0x5a0 [ 421.343411][ C2] __netif_receive_skb_one_core+0xfc/0x180 [ 421.343669][ C2] process_backlog+0x431/0x14c0 [ 421.343825][ C2] __napi_poll+0xa7/0x3b0 [ 421.344002][ C2] net_rx_action+0x513/0xf50 [ 421.344160][ C2] handle_softirqs+0x1d3/0x900 [ 421.344376][ C2] do_softirq+0xac/0xe0 [ 421.344495][ C2] __local_bh_enable_ip+0x118/0x150 [ 421.344658][ C2] __dev_queue_xmit+0x989/0x1b90 [ 421.344871][ C2] ip6_finish_output2+0x48d/0x13f0 [ 421.345030][ C2] ip6_finish_output+0x701/0xe80 [ 421.345244][ C2] ip6_output+0x23f/0x7f0 [ 421.345361][ C2] ip6_xmit+0xc44/0x1ec0 [ 421.345539][ C2] inet6_csk_xmit+0x2f6/0x5f0 [ 421.345701][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0 [ 421.345917][ C2] tcp_write_xmit+0x5a4/0x3080 [ 421.346073][ C2] __tcp_push_pending_frames+0x8f/0x3b0 [ 421.346288][ C2] __tcp_close+0x84e/0xe70 [ 421.346445][ C2] tcp_close+0x23/0xb0 [ 421.346620][ C2] inet_release+0x10a/0x240 [ 421.346779][ C2] __sock_release+0xb8/0x280 [ 421.346992][ C2] sock_close+0x18/0x20 [ 421.347111][ C2] __fput+0x36c/0xad0 [ 421.347229][ C2] fput_close_sync+0xde/0x1b0 [ 421.347442][ C2] __x64_sys_close+0x8b/0xf0 [ 421.347598][ C2] do_syscall_64+0xff/0x530 [ 421.347816][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 421.348012][ C2] [ 421.348151][ C2] Freed by task 23: [ 421.348273][ C2] kasan_save_stack+0x2f/0x50 [ 421.348491][ C2] kasan_save_track+0x14/0x30 [ 421.348651][ C2] kasan_save_free_info+0x3b/0x60 [ 421.348864][ C2] __kasan_slab_free+0x43/0x70 [ 421.349019][ C2] slab_free_after_rcu_debug+0xa6/0x100 [ 421.349234][ C2] rcu_do_batch+0x2b6/0x1000 [ 421.349394][ C2] rcu_core+0x34e/0x8e0 [ 421.349512][ C2] handle_softirqs+0x1d3/0x900 [ 421.349730][ C2] run_ksoftirqd+0x39/0x60 [ 421.349886][ C2] smpboot_thread_fn+0x2fb/0x9b0 [ 421.350102][ C2] kthread+0x367/0x460 [ 421.350222][ C2] ret_from_fork+0x474/0x6b0 [ 421.350439][ C2] ret_from_fork_asm+0x11/0x20 [ 421.350595][ C2] [ 421.350735][ C2] Last potentially related work creation: [ 421.350894][ C2] kasan_save_stack+0x2f/0x50 [ 421.351113][ C2] kasan_record_aux_stack+0x9b/0xc0 [ 421.351272][ C2] kmem_cache_free+0x37a/0x550 [ 421.351495][ C2] inet_twsk_put+0x11b/0x1a0 [ 421.351657][ C2] inet_twsk_purge+0x4dd/0x670 [ 421.351876][ C2] tcp_twsk_purge+0x123/0x1a0 [ 421.352034][ C2] tcp_sk_exit_batch+0x2b/0x160 [ 421.352254][ C2] ops_undo_list+0x2ce/0x8f0 [ 421.352414][ C2] cleanup_net+0x431/0x940 [ 421.352633][ C2] process_one_work+0xe3e/0x1560 [ 421.352793][ C2] worker_thread+0x4f1/0xd60 [ 421.353012][ C2] kthread+0x367/0x460 [ 421.353132][ C2] ret_from_fork+0x474/0x6b0 [ 421.353289][ C2] ret_from_fork_asm+0x11/0x20 [ 421.353507][ C2] [ 421.353591][ C2] The buggy address belongs to the object at ff1100000cdf6d08 [ 421.353591][ C2] which belongs to the cache tw_sock_TCPv6 of size 288 [ 421.354130][ C2] The buggy address is located 144 bytes inside of [ 421.354130][ C2] freed 288-byte region [ff1100000cdf6d08, ff1100000cdf6e28) [ 421.354581][ C2] [ 421.354666][ C2] The buggy address belongs to the physical page: [ 421.354919][ C2] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000cdf7048 pfn:0xcdf6 [ 421.355303][ C2] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 421.355546][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 421.355756][ C2] page_type: f5(slab) [ 421.355883][ C2] raw: 0080000000000240 ff11000006325e40 ff110000063d90c8 ff110000063d90c8 [ 421.356171][ C2] raw: ff1100000cdf7048 0000000000130001 00000000f5000000 0000000000000000 [ 421.356515][ C2] head: 0080000000000240 ff11000006325e40 ff110000063d90c8 ff110000063d90c8 [ 421.356867][ C2] head: ff1100000cdf7048 0000000000130001 00000000f5000000 0000000000000000 [ 421.357207][ C2] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 421.357553][ C2] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 421.357900][ C2] page dumped because: kasan: bad access detected [ 421.358101][ C2] [ 421.358237][ C2] Memory state around the buggy address: [ 421.358395][ C2] ff1100000cdf6c80: fb fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 421.358691][ C2] ff1100000cdf6d00: fc fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 421.358982][ C2] >ff1100000cdf6d80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 421.359211][ C2] ^ [ 421.359421][ C2] ff1100000cdf6e00: fb fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc [ 421.359713][ C2] ff1100000cdf6e80: fc fc fc fc fc fa fb fb fb fb fb fb fb fb fb fb [ 421.359942][ C2] ================================================================== [ 421.360274][ C2] Disabling lock debugging due to kernel taint