[ 950.677741][T29310] eth1: renamed from tmp
[ 969.671724][T29864] eth1: renamed from tmp
[ 988.643793][T30419] eth1: renamed from tmp
[ 1007.950798][T30949] eth1: renamed from tmp
[ 1027.306785][T31480] eth1: renamed from tmp
[ 1113.865681][ T391] eth1: renamed from tmp
[ 1122.571777][ T682] eth2: renamed from tmp
[ 1177.501867][ C2] ==================================================================
[ 1177.502160][ C2] BUG: KASAN: slab-use-after-free in tcp_v6_send_response+0xe7d/0x24e0
[ 1177.502405][ C2] Read of size 8 at addr ff11000017c36a58 by task nettest/1084
[ 1177.502649][ C2]
[ 1177.502737][ C2] CPU: 2 UID: 0 PID: 1084 Comm: nettest Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 1177.502741][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 1177.502743][ C2] Call Trace:
[ 1177.502744][ C2]
[ 1177.502745][ C2] dump_stack_lvl+0x6f/0xa0
[ 1177.502750][ C2] print_address_description.constprop.0+0x56/0x2d0
[ 1177.502754][ C2] print_report+0xfc/0x1fa
[ 1177.502755][ C2] ? __virt_addr_valid+0x102/0x440
[ 1177.502758][ C2] ? __virt_addr_valid+0x1da/0x440
[ 1177.502760][ C2] kasan_report+0x108/0x130
[ 1177.502763][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1177.502765][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1177.502768][ C2] kasan_check_range+0x130/0x200
[ 1177.502770][ C2] ? make_kuid+0x13/0x20
[ 1177.502772][ C2] tcp_v6_send_response+0xe7d/0x24e0
[ 1177.502774][ C2] ? __mod_timer+0x3ad/0xc60
[ 1177.502778][ C2] ? tcp_v6_send_synack+0xe10/0xe10
[ 1177.502780][ C2] ? __lock_acquire+0x518/0xc20
[ 1177.502783][ C2] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 1177.502786][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1177.502788][ C2] ? rcu_is_watching+0x16/0xd0
[ 1177.502790][ C2] tcp_v6_rcv+0x24c5/0x3250
[ 1177.502794][ C2] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 1177.502798][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 1177.502802][ C2] ip6_input_finish+0x196/0x590
[ 1177.502803][ C2] ip6_input+0x130/0x570
[ 1177.502805][ C2] ? ip6_input_finish+0x590/0x590
[ 1177.502806][ C2] ? ip6_rcv_core+0xe22/0x1be0
[ 1177.502808][ C2] ipv6_rcv+0x3c1/0x5a0
[ 1177.502810][ C2] ? ip6_rcv_core+0x1be0/0x1be0
[ 1177.502811][ C2] ? rcu_is_watching+0x16/0xd0
[ 1177.502812][ C2] ? __update_load_avg_cfs_rq+0x36c/0x10c0
[ 1177.502815][ C2] ? mark_usage+0x61/0x170
[ 1177.502816][ C2] ? __lock_acquire+0x518/0xc20
[ 1177.502818][ C2] ? irq_matrix_free+0x487/0x600
[ 1177.502821][ C2] ? process_backlog+0x3f1/0x14c0
[ 1177.502824][ C2] __netif_receive_skb_one_core+0xfc/0x180
[ 1177.502826][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1177.502828][ C2] ? process_backlog+0x3f1/0x14c0
[ 1177.502830][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 1177.502832][ C2] ? rcu_is_watching+0x16/0xd0
[ 1177.502833][ C2] process_backlog+0x431/0x14c0
[ 1177.502836][ C2] __napi_poll+0xa7/0x3b0
[ 1177.502838][ C2] net_rx_action+0x513/0xf50
[ 1177.502841][ C2] ? __napi_poll+0x3b0/0x3b0
[ 1177.502843][ C2] ? find_held_lock+0x2b/0x80
[ 1177.502847][ C2] ? rcu_is_watching+0x16/0xd0
[ 1177.502848][ C2] ? mark_held_locks+0x40/0x70
[ 1177.502850][ C2] handle_softirqs+0x1d3/0x900
[ 1177.502853][ C2] ? _local_bh_enable+0xc0/0xc0
[ 1177.502855][ C2] ? rcu_is_watching+0x16/0xd0
[ 1177.502856][ C2] ? trace_csd_function_exit+0xb3/0x180
[ 1177.502859][ C2] ? __dev_queue_xmit+0x974/0x1b90
[ 1177.502860][ C2] do_softirq+0xac/0xe0
[ 1177.502862][ C2]
[ 1177.502863][ C2]
[ 1177.502863][ C2] __local_bh_enable_ip+0x118/0x150
[ 1177.502865][ C2] __dev_queue_xmit+0x989/0x1b90
[ 1177.502868][ C2] ? cleanup_srcu_struct+0x8b1/0xad0
[ 1177.502870][ C2] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 1177.502872][ C2] ? lock_acquire.part.0+0x60/0x280
[ 1177.502873][ C2] ? find_held_lock+0x2b/0x80
[ 1177.502875][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1177.502877][ C2] ? rcu_is_watching+0x16/0xd0
[ 1177.502878][ C2] ? mark_held_locks+0x40/0x70
[ 1177.502879][ C2] ? __asan_memcpy+0x3c/0x60
[ 1177.502882][ C2] ? neigh_hh_output+0x152/0x4c0
[ 1177.502885][ C2] ip6_finish_output2+0x9e0/0x13f0
[ 1177.502888][ C2] ? ip6_dst_lookup+0x80/0x80
[ 1177.502889][ C2] ? find_held_lock+0x2b/0x80
[ 1177.502891][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1177.502893][ C2] ? ip6_mtu+0x174/0x410
[ 1177.502896][ C2] ip6_finish_output+0x701/0xe80
[ 1177.502898][ C2] ip6_output+0x23f/0x7f0
[ 1177.502900][ C2] ? ip6_finish_output+0xe80/0xe80
[ 1177.502902][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1177.502904][ C2] ? find_held_lock+0x2b/0x80
[ 1177.502905][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1177.502908][ C2] ip6_xmit+0xc44/0x1ec0
[ 1177.502909][ C2] ? mark_usage+0x61/0x170
[ 1177.502911][ C2] ? __lock_acquire+0x518/0xc20
[ 1177.502914][ C2] ? ip6_autoflowlabel+0x120/0x120
[ 1177.502916][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1177.502917][ C2] ? mark_usage+0x61/0x170
[ 1177.502919][ C2] ? __lock_acquire+0x518/0xc20
[ 1177.502921][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1177.502923][ C2] ? inet6_csk_xmit+0xfe/0x5f0
[ 1177.502925][ C2] ? rcu_is_watching+0x16/0xd0
[ 1177.502926][ C2] ? lock_acquire+0x13c/0x160
[ 1177.502928][ C2] inet6_csk_xmit+0x2f6/0x5f0
[ 1177.502930][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 1177.502935][ C2] ? __lock_acquire+0x518/0xc20
[ 1177.502936][ C2] ? __tcp_select_window+0x1040/0x1040
[ 1177.502939][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1177.502940][ C2] ? find_held_lock+0x2b/0x80
[ 1177.502943][ C2] tcp_write_xmit+0x5a4/0x3080
[ 1177.502950][ C2] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 1177.502953][ C2] ? tcp_set_state+0x101/0x580
[ 1177.502955][ C2] __tcp_push_pending_frames+0x8f/0x3b0
[ 1177.502957][ C2] __tcp_close+0x84e/0xe70
[ 1177.502959][ C2] ? mark_held_locks+0x40/0x70
[ 1177.502961][ C2] tcp_close+0x23/0xb0
[ 1177.502962][ C2] inet_release+0x10a/0x240
[ 1177.502965][ C2] ? fcntl_setlk+0xce0/0xce0
[ 1177.502969][ C2] __sock_release+0xb8/0x280
[ 1177.502972][ C2] sock_close+0x18/0x20
[ 1177.502973][ C2] __fput+0x36c/0xad0
[ 1177.502976][ C2] fput_close_sync+0xde/0x1b0
[ 1177.502978][ C2] ? alloc_file_clone+0xe0/0xe0
[ 1177.502980][ C2] ? do_raw_spin_unlock+0x59/0x250
[ 1177.502982][ C2] __x64_sys_close+0x8b/0xf0
[ 1177.502984][ C2] do_syscall_64+0xff/0x530
[ 1177.502986][ C2] ? exc_page_fault+0xee/0x100
[ 1177.502989][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1177.502991][ C2] RIP: 0033:0x7f1d86afe54e
[ 1177.502994][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 1177.502996][ C2] RSP: 002b:00007ffeee8245a0 EFLAGS: 00000202 ORIG_RAX: 0000000000000003
[ 1177.502999][ C2] RAX: ffffffffffffffda RBX: 00007ffeee824730 RCX: 00007f1d86afe54e
[ 1177.503001][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000005
[ 1177.503002][ C2] RBP: 00007ffeee8245b0 R08: 0000000000000000 R09: 0000000000000000
[ 1177.503002][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 00007ffeee8249b8
[ 1177.503003][ C2] R13: 0000000000000004 R14: 00007ffeee824640 R15: 000000000000001c
[ 1177.503006][ C2]
[ 1177.503006][ C2]
[ 1177.523821][ C2] Allocated by task 31693:
[ 1177.524046][ C2] kasan_save_stack+0x2f/0x50
[ 1177.524213][ C2] kasan_save_track+0x14/0x30
[ 1177.524428][ C2] __kasan_slab_alloc+0x60/0x70
[ 1177.524586][ C2] kmem_cache_alloc_noprof+0x21f/0x5c0
[ 1177.524803][ C2] inet_twsk_alloc+0x123/0x9e0
[ 1177.524967][ C2] tcp_time_wait+0x5d/0x11f0
[ 1177.525191][ C2] tcp_fin+0x377/0x470
[ 1177.525311][ C2] tcp_data_queue+0xc1d/0x2050
[ 1177.525524][ C2] tcp_rcv_state_process+0x759/0x24e0
[ 1177.525685][ C2] tcp_v6_do_rcv+0x654/0x1640
[ 1177.525899][ C2] tcp_v6_rcv+0x1b27/0x3250
[ 1177.526061][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 1177.526219][ C2] ip6_input_finish+0x196/0x590
[ 1177.526379][ C2] ip6_input+0x130/0x570
[ 1177.526560][ C2] ipv6_rcv+0x3c1/0x5a0
[ 1177.526679][ C2] __netif_receive_skb_one_core+0xfc/0x180
[ 1177.526936][ C2] process_backlog+0x431/0x14c0
[ 1177.527099][ C2] __napi_poll+0xa7/0x3b0
[ 1177.527277][ C2] net_rx_action+0x513/0xf50
[ 1177.527436][ C2] handle_softirqs+0x1d3/0x900
[ 1177.527650][ C2] do_softirq+0xac/0xe0
[ 1177.527769][ C2] __local_bh_enable_ip+0x118/0x150
[ 1177.527928][ C2] __dev_queue_xmit+0x989/0x1b90
[ 1177.528147][ C2] ip6_finish_output2+0x48d/0x13f0
[ 1177.528308][ C2] ip6_finish_output+0x701/0xe80
[ 1177.528525][ C2] ip6_output+0x23f/0x7f0
[ 1177.528645][ C2] ip6_xmit+0xc44/0x1ec0
[ 1177.528823][ C2] inet6_csk_xmit+0x2f6/0x5f0
[ 1177.528986][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 1177.529201][ C2] tcp_write_xmit+0x5a4/0x3080
[ 1177.529361][ C2] __tcp_push_pending_frames+0x8f/0x3b0
[ 1177.529579][ C2] __tcp_close+0x84e/0xe70
[ 1177.529736][ C2] tcp_close+0x23/0xb0
[ 1177.529914][ C2] inet_release+0x10a/0x240
[ 1177.530076][ C2] __sock_release+0xb8/0x280
[ 1177.530293][ C2] sock_close+0x18/0x20
[ 1177.530412][ C2] __fput+0x36c/0xad0
[ 1177.530530][ C2] fput_close_sync+0xde/0x1b0
[ 1177.530746][ C2] __x64_sys_close+0x8b/0xf0
[ 1177.530905][ C2] do_syscall_64+0xff/0x530
[ 1177.531127][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1177.531326][ C2]
[ 1177.531465][ C2] Freed by task 0:
[ 1177.531589][ C2] kasan_save_stack+0x2f/0x50
[ 1177.531811][ C2] kasan_save_track+0x14/0x30
[ 1177.531973][ C2] kasan_save_free_info+0x3b/0x60
[ 1177.532192][ C2] __kasan_slab_free+0x43/0x70
[ 1177.532350][ C2] slab_free_after_rcu_debug+0xa6/0x100
[ 1177.532570][ C2] rcu_do_batch+0x2b6/0x1000
[ 1177.532729][ C2] rcu_core+0x34e/0x8e0
[ 1177.532849][ C2] handle_softirqs+0x1d3/0x900
[ 1177.533073][ C2] __irq_exit_rcu+0x145/0x1c0
[ 1177.533233][ C2] irq_exit_rcu+0xe/0x30
[ 1177.533411][ C2] sysvec_apic_timer_interrupt+0x9d/0xe0
[ 1177.533569][ C2] asm_sysvec_apic_timer_interrupt+0x1a/0x20
[ 1177.533828][ C2]
[ 1177.533911][ C2] Last potentially related work creation:
[ 1177.534137][ C2] kasan_save_stack+0x2f/0x50
[ 1177.534302][ C2] kasan_record_aux_stack+0x9b/0xc0
[ 1177.534521][ C2] kmem_cache_free+0x37a/0x550
[ 1177.534681][ C2] inet_twsk_put+0x11b/0x1a0
[ 1177.534904][ C2] call_timer_fn+0x160/0x4d0
[ 1177.535076][ C2] __run_timers+0x68f/0xaa0
[ 1177.535299][ C2] run_timer_softirq+0xf0/0x160
[ 1177.535462][ C2] handle_softirqs+0x1d3/0x900
[ 1177.535679][ C2] __irq_exit_rcu+0x145/0x1c0
[ 1177.535838][ C2] irq_exit_rcu+0xe/0x30
[ 1177.536020][ C2] sysvec_apic_timer_interrupt+0x9d/0xe0
[ 1177.536180][ C2] asm_sysvec_apic_timer_interrupt+0x1a/0x20
[ 1177.536440][ C2]
[ 1177.536523][ C2] The buggy address belongs to the object at ff11000017c369c8
[ 1177.536523][ C2] which belongs to the cache tw_sock_TCPv6 of size 288
[ 1177.537020][ C2] The buggy address is located 144 bytes inside of
[ 1177.537020][ C2] freed 288-byte region [ff11000017c369c8, ff11000017c36ae8)
[ 1177.537526][ C2]
[ 1177.537608][ C2] The buggy address belongs to the physical page:
[ 1177.537812][ C2] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000017c36348 pfn:0x17c36
[ 1177.538201][ C2] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 1177.538508][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 1177.538774][ C2] page_type: f5(slab)
[ 1177.538903][ C2] raw: 0080000000000240 ff110000063ede40 ffd4000000af5a10 ff110000063f50c8
[ 1177.539261][ C2] raw: ff11000017c36348 0000000000130004 00000000f5000000 0000000000000000
[ 1177.539608][ C2] head: 0080000000000240 ff110000063ede40 ffd4000000af5a10 ff110000063f50c8
[ 1177.539958][ C2] head: ff11000017c36348 0000000000130004 00000000f5000000 0000000000000000
[ 1177.540303][ C2] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 1177.540648][ C2] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 1177.540935][ C2] page dumped because: kasan: bad access detected
[ 1177.541197][ C2]
[ 1177.541278][ C2] Memory state around the buggy address:
[ 1177.541490][ C2] ff11000017c36900: fb fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc
[ 1177.541786][ C2] ff11000017c36980: fc fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb
[ 1177.542029][ C2] >ff11000017c36a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 1177.542323][ C2] ^
[ 1177.542580][ C2] ff11000017c36a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc
[ 1177.542813][ C2] ff11000017c36b00: fc fc fc fc fc fc fc fc fc fc fc fc fc fa fb fb
[ 1177.543110][ C2] ==================================================================
[ 1177.543447][ C2] Disabling lock debugging due to kernel taint
[ 1187.981131][ T1699] eth1: renamed from tmp
[ 1222.106208][ T3585] eth1: renamed from tmp
[ 1239.315177][ T4534] eth1: renamed from tmp
[ 1244.183413][ T4741] eth1: renamed from tmp
[ 1250.413589][ T5013] eth1: renamed from tmp
[ 1257.635223][ T5149] eth1: renamed from tmp
[ 1262.886224][ T5286] eth1: renamed from tmp
[ 1270.173168][ T5429] eth1: renamed from tmp
[ 1277.618203][ T5572] eth1: renamed from tmp
[ 1284.877257][ T5715] eth1: renamed from tmp
[ 1292.121350][ T5858] eth1: renamed from tmp
[ 1299.351112][ T6001] eth1: renamed from tmp
[ 1306.612356][ T6144] eth1: renamed from tmp
[ 1313.833207][ T6286] eth1: renamed from tmp
[ 1321.058167][ T6428] eth1: renamed from tmp
[ 1328.314141][ T6571] eth1: renamed from tmp
[ 1335.616229][ T6715] eth1: renamed from tmp
[ 1342.925316][ T6859] eth1: renamed from tmp
[ 1350.252084][ T7002] eth1: renamed from tmp
[ 1357.559221][ T7145] eth1: renamed from tmp
[ 1364.813600][ T7288] eth1: renamed from tmp
[ 1372.079549][ T7432] eth1: renamed from tmp
[ 1379.372115][ T7575] eth1: renamed from tmp
[ 1386.645233][ T7718] eth1: renamed from tmp
[ 1393.918263][ T7861] eth1: renamed from tmp
[ 1401.202568][ T8005] eth1: renamed from tmp
[ 1408.466136][ T8148] eth1: renamed from tmp
[ 1415.733192][ T8291] eth1: renamed from tmp
[ 1422.991578][ T8433] eth1: renamed from tmp
[ 1430.258241][ T8575] eth1: renamed from tmp
[ 1437.527423][ T8718] eth1: renamed from tmp
[ 1444.800196][ T8861] eth1: renamed from tmp
[ 1452.054184][ T9004] eth1: renamed from tmp
[ 1459.337330][ T9147] eth1: renamed from tmp
[ 1466.592311][ T9290] eth1: renamed from tmp
[ 1473.862140][ T9433] eth1: renamed from tmp
[ 1481.111172][ T9576] eth1: renamed from tmp
[ 1489.703172][ T9748] eth1: renamed from tmp
[ 1498.315166][ T9920] eth1: renamed from tmp
[ 1506.925719][T10091] eth1: renamed from tmp
[ 1515.492357][T10262] eth1: renamed from tmp
[ 1524.089181][T10433] eth1: renamed from tmp
[ 1532.657194][T10604] eth1: renamed from tmp
[ 1541.227176][T10774] eth1: renamed from tmp
[ 1549.822166][T10944] eth1: renamed from tmp
[ 1558.412222][T11115] eth1: renamed from tmp
[ 1567.038301][T11286] eth1: renamed from tmp
[ 1575.614139][T11457] eth1: renamed from tmp
[ 1584.193330][T11628] eth1: renamed from tmp
[ 1593.759338][T11799] eth1: renamed from tmp
[ 1602.469669][T11970] eth1: renamed from tmp
[ 1611.298139][T12141] eth1: renamed from tmp