[ 11.115274][ T242] ip (242) used greatest stack depth: 23664 bytes left
[ 11.183471][ T245] eth1: renamed from tmp
[ 30.912206][ T800] eth1: renamed from tmp
[ 50.352178][ T1320] ip (1320) used greatest stack depth: 23296 bytes left
[ 51.504324][ T1356] eth1: renamed from tmp
[ 72.722358][ T1886] eth1: renamed from tmp
[ 104.173816][ T2417] eth1: renamed from tmp
[ 159.037398][ C3] ==================================================================
[ 159.037819][ C3] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0
[ 159.038213][ C3] Read of size 8 at addr ff1100000587e118 by task nettest/3229
[ 159.038601][ C3]
[ 159.038741][ C3] CPU: 3 UID: 0 PID: 3229 Comm: nettest Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 159.038746][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 159.038749][ C3] Call Trace:
[ 159.038750][ C3]
[ 159.038752][ C3] dump_stack_lvl+0x6f/0xa0
[ 159.038758][ C3] print_address_description.constprop.0+0x56/0x2d0
[ 159.038764][ C3] print_report+0xfc/0x1fa
[ 159.038767][ C3] ? __virt_addr_valid+0x102/0x440
[ 159.038771][ C3] ? __virt_addr_valid+0x1da/0x440
[ 159.038774][ C3] kasan_report+0x108/0x130
[ 159.038778][ C3] ? tcp_v6_send_response+0xe7d/0x24e0
[ 159.038782][ C3] ? tcp_v6_send_response+0xe7d/0x24e0
[ 159.038786][ C3] kasan_check_range+0x130/0x200
[ 159.038789][ C3] ? make_kuid+0x13/0x20
[ 159.038793][ C3] tcp_v6_send_response+0xe7d/0x24e0
[ 159.038796][ C3] ? __mod_timer+0x3ad/0xc60
[ 159.038802][ C3] ? tcp_v6_send_synack+0xe10/0xe10
[ 159.038804][ C3] ? __lock_acquire+0x518/0xc20
[ 159.038808][ C3] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 159.038814][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 159.038816][ C3] ? rcu_is_watching+0x16/0xd0
[ 159.038821][ C3] tcp_v6_rcv+0x24c5/0x3250
[ 159.038828][ C3] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 159.038832][ C3] ? rcu_do_batch+0x2b6/0x1000
[ 159.038835][ C3] ? is_bpf_text_address+0x72/0x110
[ 159.038840][ C3] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 159.038846][ C3] ip6_input_finish+0x196/0x590
[ 159.038849][ C3] ip6_input+0x130/0x570
[ 159.038852][ C3] ? ip6_input_finish+0x590/0x590
[ 159.038855][ C3] ? ip6_rcv_core+0xe22/0x1be0
[ 159.038859][ C3] ipv6_rcv+0x3c1/0x5a0
[ 159.038861][ C3] ? ip6_rcv_core+0x1be0/0x1be0
[ 159.038869][ C3] ? step_into_slowpath+0x4c8/0x1240
[ 159.038873][ C3] ? path_lookupat+0x480/0xbf0
[ 159.038876][ C3] ? filename_lookup+0x1e7/0x4c0
[ 159.038879][ C3] ? mark_usage+0x61/0x170
[ 159.038882][ C3] ? __lock_acquire+0x518/0xc20
[ 159.038886][ C3] ? process_backlog+0x3f1/0x14c0
[ 159.038890][ C3] __netif_receive_skb_one_core+0xfc/0x180
[ 159.038893][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 159.038896][ C3] ? process_backlog+0x3f1/0x14c0
[ 159.038899][ C3] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 159.038902][ C3] ? rcu_is_watching+0x16/0xd0
[ 159.038906][ C3] process_backlog+0x431/0x14c0
[ 159.038910][ C3] __napi_poll+0xa7/0x3b0
[ 159.038914][ C3] net_rx_action+0x513/0xf50
[ 159.038918][ C3] ? __napi_poll+0x3b0/0x3b0
[ 159.038922][ C3] ? find_held_lock+0x2b/0x80
[ 159.038928][ C3] ? rcu_is_watching+0x16/0xd0
[ 159.038930][ C3] ? mark_held_locks+0x40/0x70
[ 159.038934][ C3] handle_softirqs+0x1d3/0x900
[ 159.038939][ C3] ? _local_bh_enable+0xc0/0xc0
[ 159.038941][ C3] ? rcu_is_watching+0x16/0xd0
[ 159.038944][ C3] ? trace_csd_function_exit+0xb3/0x180
[ 159.038948][ C3] ? __dev_queue_xmit+0x974/0x1b90
[ 159.038951][ C3] do_softirq+0xac/0xe0
[ 159.038953][ C3]
[ 159.038955][ C3]
[ 159.038956][ C3] __local_bh_enable_ip+0x118/0x150
[ 159.038959][ C3] __dev_queue_xmit+0x989/0x1b90
[ 159.038962][ C3] ? __lock_acquire+0x518/0xc20
[ 159.038966][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 159.038969][ C3] ? find_held_lock+0x2b/0x80
[ 159.038971][ C3] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 159.038975][ C3] ? __asan_memcpy+0x3c/0x60
[ 159.038978][ C3] ? eth_header+0x14c/0x180
[ 159.038982][ C3] ? neigh_resolve_output.part.0+0x344/0x740
[ 159.038988][ C3] ip6_finish_output2+0x48d/0x13f0
[ 159.038993][ C3] ? ip6_dst_lookup+0x80/0x80
[ 159.038996][ C3] ? find_held_lock+0x2b/0x80
[ 159.038999][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 159.039002][ C3] ? ip6_mtu+0x174/0x410
[ 159.039007][ C3] ip6_finish_output+0x701/0xe80
[ 159.039011][ C3] ip6_output+0x23f/0x7f0
[ 159.039015][ C3] ? ip6_finish_output+0xe80/0xe80
[ 159.039018][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 159.039020][ C3] ? find_held_lock+0x2b/0x80
[ 159.039023][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 159.039027][ C3] ip6_xmit+0xc44/0x1ec0
[ 159.039030][ C3] ? mark_usage+0x61/0x170
[ 159.039033][ C3] ? __lock_acquire+0x518/0xc20
[ 159.039037][ C3] ? ip6_autoflowlabel+0x120/0x120
[ 159.039041][ C3] ? __lock_release.isra.0+0x69/0x1a0
[ 159.039043][ C3] ? mark_usage+0x61/0x170
[ 159.039046][ C3] ? __lock_acquire+0x518/0xc20
[ 159.039050][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 159.039053][ C3] ? inet6_csk_xmit+0xfe/0x5f0
[ 159.039056][ C3] ? rcu_is_watching+0x16/0xd0
[ 159.039058][ C3] ? lock_acquire+0x13c/0x160
[ 159.039062][ C3] inet6_csk_xmit+0x2f6/0x5f0
[ 159.039066][ C3] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 159.039073][ C3] ? __lock_acquire+0x518/0xc20
[ 159.039076][ C3] ? __tcp_select_window+0x1040/0x1040
[ 159.039079][ C3] ? lock_acquire.part.0+0xd4/0x280
[ 159.039082][ C3] ? find_held_lock+0x2b/0x80
[ 159.039088][ C3] tcp_write_xmit+0x5a4/0x3080
[ 159.039094][ C3] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 159.039098][ C3] ? tcp_set_state+0x101/0x580
[ 159.039102][ C3] __tcp_push_pending_frames+0x8f/0x3b0
[ 159.039105][ C3] __tcp_close+0x84e/0xe70
[ 159.039108][ C3] ? mark_held_locks+0x40/0x70
[ 159.039111][ C3] tcp_close+0x23/0xb0
[ 159.039114][ C3] inet_release+0x10a/0x240
[ 159.039118][ C3] ? fcntl_setlk+0xce0/0xce0
[ 159.039122][ C3] __sock_release+0xb8/0x280
[ 159.039127][ C3] sock_close+0x18/0x20
[ 159.039129][ C3] __fput+0x36c/0xad0
[ 159.039134][ C3] fput_close_sync+0xde/0x1b0
[ 159.039137][ C3] ? alloc_file_clone+0xe0/0xe0
[ 159.039140][ C3] ? do_raw_spin_unlock+0x59/0x250
[ 159.039144][ C3] __x64_sys_close+0x8b/0xf0
[ 159.039146][ C3] do_syscall_64+0xff/0x530
[ 159.039150][ C3] ? exc_page_fault+0xee/0x100
[ 159.039153][ C3] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 159.039156][ C3] RIP: 0033:0x7f118c1f554e
[ 159.039161][ C3] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 159.039163][ C3] RSP: 002b:00007fffbad111a0 EFLAGS: 00000202 ORIG_RAX: 0000000000000003
[ 159.039168][ C3] RAX: ffffffffffffffda RBX: 00007fffbad11330 RCX: 00007f118c1f554e
[ 159.039170][ C3] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000005
[ 159.039172][ C3] RBP: 00007fffbad111b0 R08: 0000000000000000 R09: 0000000000000000
[ 159.039173][ C3] R10: 0000000000000000 R11: 0000000000000202 R12: 00007fffbad115b8
[ 159.039175][ C3] R13: 0000000000000004 R14: 00007fffbad11240 R15: 000000000000001c
[ 159.039179][ C3]
[ 159.039180][ C3]
[ 159.073570][ C3] Allocated by task 736:
[ 159.073773][ C3] kasan_save_stack+0x2f/0x50
[ 159.074147][ C3] kasan_save_track+0x14/0x30
[ 159.074408][ C3] __kasan_slab_alloc+0x60/0x70
[ 159.074771][ C3] kmem_cache_alloc_noprof+0x21f/0x5c0
[ 159.075037][ C3] __alloc_object+0x30/0x260
[ 159.075398][ C3] __create_object+0x30/0x110
[ 159.075657][ C3] kmem_cache_alloc_lru_noprof+0x463/0x5c0
[ 159.076093][ C3] __d_alloc+0x3a/0x8e0
[ 159.076290][ C3] d_alloc_parallel+0xd7/0x1130
[ 159.076648][ C3] __lookup_slow+0x80/0x270
[ 159.076914][ C3] lookup_slow+0x54/0x80
[ 159.077209][ C3] link_path_walk+0xe94/0x1830
[ 159.077467][ C3] path_lookupat+0x63/0xbf0
[ 159.077828][ C3] filename_lookup+0x1e7/0x4c0
[ 159.078094][ C3] vfs_statx+0xd7/0x3b0
[ 159.078292][ C3] vfs_fstatat+0x4d/0x90
[ 159.078586][ C3] __do_sys_newfstatat+0xa0/0xf0
[ 159.078847][ C3] do_syscall_64+0xff/0x530
[ 159.079210][ C3] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 159.079543][ C3]
[ 159.079778][ C3] The buggy address belongs to the object at ff1100000587e008
[ 159.079778][ C3] which belongs to the cache kmemleak_object of size 240
[ 159.080584][ C3] The buggy address is located 32 bytes to the right of
[ 159.080584][ C3] allocated 240-byte region [ff1100000587e008, ff1100000587e0f8)
[ 159.081402][ C3]
[ 159.081636][ C3] The buggy address belongs to the physical page:
[ 159.081966][ C3] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x587e
[ 159.082541][ C3] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 159.082942][ C3] flags: 0x80000000000040(head|node=0|zone=1)
[ 159.083388][ C3] page_type: f5(slab)
[ 159.083594][ C3] raw: 0080000000000040 ff1100000103fe40 dead000000000100 dead000000000122
[ 159.084186][ C3] raw: 0000000000000000 0000000000190019 00000000f5000000 0000000000000000
[ 159.084766][ C3] head: 0080000000000040 ff1100000103fe40 dead000000000100 dead000000000122
[ 159.085349][ C3] head: 0000000000000000 0000000000190019 00000000f5000000 0000000000000000
[ 159.085816][ C3] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 159.086390][ C3] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 159.086974][ C3] page dumped because: kasan: bad access detected
[ 159.087403][ C3]
[ 159.087533][ C3] Memory state around the buggy address:
[ 159.087892][ C3] ff1100000587e000: fc 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 159.088277][ C3] ff1100000587e080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fc
[ 159.088762][ C3] >ff1100000587e100: fc fc fc fc fc fc fc fc fc 00 00 00 00 00 00 00
[ 159.089246][ C3] ^
[ 159.089503][ C3] ff1100000587e180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 159.089987][ C3] ff1100000587e200: 00 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc
[ 159.090463][ C3] ==================================================================
[ 159.090966][ C3] Disabling lock debugging due to kernel taint
[ 199.298320][ T3792] eth1: renamed from tmp
[ 205.450674][ T4083] eth2: renamed from tmp
[ 269.981291][ T5099] eth1: renamed from tmp
[ 310.839624][ T6987] eth1: renamed from tmp
[ 331.187488][ T7911] ip (7911) used greatest stack depth: 23160 bytes left
[ 331.744628][ T7936] eth1: renamed from tmp
[ 336.851767][ T8145] eth1: renamed from tmp
[ 343.508144][ T8417] eth1: renamed from tmp
[ 350.868690][ T8553] eth1: renamed from tmp
[ 356.693828][ T8690] eth1: renamed from tmp
[ 364.665857][ T8833] eth1: renamed from tmp
[ 372.219127][ T8976] eth1: renamed from tmp
[ 379.604675][ T9119] eth1: renamed from tmp
[ 387.002703][ T9262] eth1: renamed from tmp
[ 394.395688][ T9405] eth1: renamed from tmp
[ 401.755863][ T9548] eth1: renamed from tmp
[ 409.117677][ T9690] eth1: renamed from tmp
[ 416.496215][ T9833] eth1: renamed from tmp
[ 423.954522][ T9976] eth1: renamed from tmp
[ 431.392813][T10119] eth1: renamed from tmp
[ 438.800740][T10262] eth1: renamed from tmp
[ 446.169665][T10405] eth1: renamed from tmp
[ 453.587326][T10548] eth1: renamed from tmp
[ 460.976151][T10691] eth1: renamed from tmp
[ 468.369753][T10834] eth1: renamed from tmp
[ 475.779717][T10977] eth1: renamed from tmp
[ 483.208749][T11120] eth1: renamed from tmp
[ 490.605749][T11263] eth1: renamed from tmp
[ 497.960877][T11407] eth1: renamed from tmp
[ 505.312618][T11550] eth1: renamed from tmp
[ 512.703752][T11693] eth1: renamed from tmp
[ 520.101743][T11836] eth1: renamed from tmp
[ 527.492772][T11978] eth1: renamed from tmp
[ 534.870069][T12121] eth1: renamed from tmp
[ 542.249841][T12264] eth1: renamed from tmp
[ 549.644668][T12407] eth1: renamed from tmp
[ 557.044807][T12551] eth1: renamed from tmp
[ 564.442730][T12694] eth1: renamed from tmp
[ 571.813732][T12837] eth1: renamed from tmp
[ 579.238749][T12980] eth1: renamed from tmp
[ 588.183474][T13151] eth1: renamed from tmp
[ 597.158700][T13322] eth1: renamed from tmp
[ 606.066757][T13493] eth1: renamed from tmp
[ 614.821793][T13664] eth1: renamed from tmp
[ 623.899683][T13835] eth1: renamed from tmp
[ 632.660769][T14006] eth1: renamed from tmp
[ 641.507677][T14176] eth1: renamed from tmp
[ 650.742467][T14346] eth1: renamed from tmp
[ 659.617769][T14517] eth1: renamed from tmp
[ 668.398790][T14689] eth1: renamed from tmp
[ 677.124677][T14860] eth1: renamed from tmp
[ 685.895685][T15031] eth1: renamed from tmp
[ 694.651686][T15202] eth1: renamed from tmp
[ 703.414961][T15373] eth1: renamed from tmp
[ 712.204679][T15544] eth1: renamed from tmp