[ 1217.743114][ C2] ==================================================================
[ 1217.743425][ C2] BUG: KASAN: slab-use-after-free in tcp_v6_send_response+0xe7d/0x24e0
[ 1217.743676][ C2] Read of size 8 at addr ff1100000ef175b8 by task ipv6_flowlabel_/25441
[ 1217.743911][ C2]
[ 1217.743998][ C2] CPU: 2 UID: 0 PID: 25441 Comm: ipv6_flowlabel_ Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 1217.744001][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 1217.744003][ C2] Call Trace:
[ 1217.744004][ C2]
[ 1217.744006][ C2] dump_stack_lvl+0x6f/0xa0
[ 1217.744010][ C2] print_address_description.constprop.0+0x56/0x2d0
[ 1217.744015][ C2] print_report+0xfc/0x1fa
[ 1217.744016][ C2] ? __virt_addr_valid+0x102/0x440
[ 1217.744019][ C2] ? __virt_addr_valid+0x1da/0x440
[ 1217.744021][ C2] kasan_report+0x108/0x130
[ 1217.744024][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1217.744026][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1217.744028][ C2] kasan_check_range+0x130/0x200
[ 1217.744030][ C2] ? make_kuid+0x13/0x20
[ 1217.744033][ C2] tcp_v6_send_response+0xe7d/0x24e0
[ 1217.744035][ C2] ? __mod_timer+0x91/0xc60
[ 1217.744038][ C2] ? tcp_v6_send_synack+0xe10/0xe10
[ 1217.744040][ C2] ? __lock_acquire+0x518/0xc20
[ 1217.744043][ C2] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 1217.744046][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1217.744048][ C2] ? rcu_is_watching+0x16/0xd0
[ 1217.744051][ C2] tcp_v6_rcv+0x24c5/0x3250
[ 1217.744055][ C2] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 1217.744056][ C2] ? find_held_lock+0x2b/0x80
[ 1217.744060][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 1217.744063][ C2] ip6_input_finish+0x196/0x590
[ 1217.744065][ C2] ip6_input+0x130/0x570
[ 1217.744066][ C2] ? rcu_read_lock_any_held+0x66/0x90
[ 1217.744069][ C2] ? ip6_input_finish+0x590/0x590
[ 1217.744070][ C2] ? ip6_rcv_core+0xde3/0x1be0
[ 1217.744071][ C2] ? __asan_memset+0x27/0x50
[ 1217.744074][ C2] ? ip6_rcv_core+0xded/0x1be0
[ 1217.744075][ C2] ipv6_rcv+0x3c1/0x5a0
[ 1217.744077][ C2] ? ip6_rcv_core+0x1be0/0x1be0
[ 1217.744078][ C2] ? do_syscall_64+0xff/0x530
[ 1217.744080][ C2] ? entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1217.744083][ C2] ? mark_usage+0x61/0x170
[ 1217.744084][ C2] ? __lock_acquire+0x518/0xc20
[ 1217.744087][ C2] ? process_backlog+0x3f1/0x14c0
[ 1217.744090][ C2] __netif_receive_skb_one_core+0xfc/0x180
[ 1217.744092][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1217.744094][ C2] ? process_backlog+0x3f1/0x14c0
[ 1217.744096][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 1217.744098][ C2] ? rcu_is_watching+0x16/0xd0
[ 1217.744099][ C2] process_backlog+0x431/0x14c0
[ 1217.744102][ C2] __napi_poll+0xa7/0x3b0
[ 1217.744104][ C2] net_rx_action+0x513/0xf50
[ 1217.744107][ C2] ? __napi_poll+0x3b0/0x3b0
[ 1217.744109][ C2] ? trace_rcu_batch_end+0x310/0x310
[ 1217.744113][ C2] ? __run_timers+0xaa0/0xaa0
[ 1217.744116][ C2] ? mark_held_locks+0x40/0x70
[ 1217.744118][ C2] handle_softirqs+0x1d3/0x900
[ 1217.744121][ C2] ? _local_bh_enable+0xc0/0xc0
[ 1217.744122][ C2] ? _local_bh_enable+0xc0/0xc0
[ 1217.744124][ C2] ? __dev_queue_xmit+0x974/0x1b90
[ 1217.744126][ C2] do_softirq+0xac/0xe0
[ 1217.744128][ C2]
[ 1217.744128][ C2]
[ 1217.744129][ C2] __local_bh_enable_ip+0x118/0x150
[ 1217.744131][ C2] __dev_queue_xmit+0x989/0x1b90
[ 1217.744133][ C2] ? rcu_lockdep_current_cpu_online+0x3f/0x1b0
[ 1217.744136][ C2] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 1217.744137][ C2] ? lock_acquire.part.0+0x60/0x280
[ 1217.744139][ C2] ? find_held_lock+0x2b/0x80
[ 1217.744141][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1217.744142][ C2] ? rcu_is_watching+0x16/0xd0
[ 1217.744143][ C2] ? mark_held_locks+0x40/0x70
[ 1217.744145][ C2] ? __asan_memcpy+0x3c/0x60
[ 1217.744147][ C2] ? neigh_hh_output+0x152/0x4c0
[ 1217.744150][ C2] ip6_finish_output2+0x9e0/0x13f0
[ 1217.744153][ C2] ? ip6_dst_lookup+0x80/0x80
[ 1217.744155][ C2] ? find_held_lock+0x2b/0x80
[ 1217.744156][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1217.744158][ C2] ? ip6_mtu+0x174/0x410
[ 1217.744161][ C2] ip6_finish_output+0x701/0xe80
[ 1217.744163][ C2] ip6_output+0x23f/0x7f0
[ 1217.744166][ C2] ? ip6_finish_output+0xe80/0xe80
[ 1217.744168][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1217.744169][ C2] ? find_held_lock+0x2b/0x80
[ 1217.744171][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1217.744173][ C2] ip6_xmit+0xc44/0x1ec0
[ 1217.744175][ C2] ? mark_usage+0x61/0x170
[ 1217.744177][ C2] ? __lock_acquire+0x518/0xc20
[ 1217.744179][ C2] ? ip6_autoflowlabel+0x120/0x120
[ 1217.744181][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1217.744183][ C2] ? mark_usage+0x61/0x170
[ 1217.744184][ C2] ? __lock_acquire+0x518/0xc20
[ 1217.744186][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1217.744188][ C2] ? inet6_csk_xmit+0xfe/0x5f0
[ 1217.744190][ C2] ? rcu_is_watching+0x16/0xd0
[ 1217.744191][ C2] ? lock_acquire+0x13c/0x160
[ 1217.744193][ C2] inet6_csk_xmit+0x2f6/0x5f0
[ 1217.744196][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 1217.744200][ C2] ? __lock_acquire+0x518/0xc20
[ 1217.744202][ C2] ? __tcp_select_window+0x1040/0x1040
[ 1217.744204][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1217.744206][ C2] ? find_held_lock+0x2b/0x80
[ 1217.744209][ C2] tcp_write_xmit+0x5a4/0x3080
[ 1217.744213][ C2] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 1217.744215][ C2] ? skb_attempt_defer_free+0x270/0x790
[ 1217.744217][ C2] ? tcp_set_state+0x101/0x580
[ 1217.744219][ C2] __tcp_push_pending_frames+0x8f/0x3b0
[ 1217.744221][ C2] __tcp_close+0x84e/0xe70
[ 1217.744223][ C2] tcp_close+0x23/0xb0
[ 1217.744225][ C2] inet_release+0x10a/0x240
[ 1217.744228][ C2] ? fcntl_setlk+0xce0/0xce0
[ 1217.744231][ C2] __sock_release+0xb8/0x280
[ 1217.744234][ C2] sock_close+0x18/0x20
[ 1217.744235][ C2] __fput+0x36c/0xad0
[ 1217.744238][ C2] fput_close_sync+0xde/0x1b0
[ 1217.744240][ C2] ? alloc_file_clone+0xe0/0xe0
[ 1217.744242][ C2] ? do_raw_spin_unlock+0x59/0x250
[ 1217.744244][ C2] __x64_sys_close+0x8b/0xf0
[ 1217.744246][ C2] do_syscall_64+0xff/0x530
[ 1217.744247][ C2] ? exc_page_fault+0xee/0x100
[ 1217.744249][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1217.744251][ C2] RIP: 0033:0x7f26c64b154e
[ 1217.744254][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 1217.744255][ C2] RSP: 002b:00007ffc11391dc0 EFLAGS: 00000202 ORIG_RAX: 0000000000000003
[ 1217.744259][ C2] RAX: ffffffffffffffda RBX: 00007f26c6434000 RCX: 00007f26c64b154e
[ 1217.744260][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000006
[ 1217.744261][ C2] RBP: 00007ffc11391dd0 R08: 0000000000000000 R09: 0000000000000000
[ 1217.744262][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 000000000040c1a0
[ 1217.744263][ C2] R13: 000000000040c1a0 R14: 0000000000000007 R15: 0000000000000005
[ 1217.744265][ C2]
[ 1217.744266][ C2]
[ 1217.765614][ C2] Allocated by task 3365:
[ 1217.765737][ C2] kasan_save_stack+0x2f/0x50
[ 1217.765958][ C2] kasan_save_track+0x14/0x30
[ 1217.766117][ C2] __kasan_slab_alloc+0x60/0x70
[ 1217.766332][ C2] kmem_cache_alloc_noprof+0x21f/0x5c0
[ 1217.766488][ C2] inet_twsk_alloc+0x123/0x9e0
[ 1217.766703][ C2] tcp_time_wait+0x5d/0x11f0
[ 1217.766862][ C2] tcp_fin+0x377/0x470
[ 1217.766984][ C2] tcp_data_queue+0xc1d/0x2050
[ 1217.767196][ C2] tcp_rcv_state_process+0x759/0x24e0
[ 1217.767354][ C2] tcp_v6_do_rcv+0x654/0x1640
[ 1217.767567][ C2] tcp_v6_rcv+0x1b27/0x3250
[ 1217.767729][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 1217.767947][ C2] ip6_input_finish+0x196/0x590
[ 1217.768104][ C2] ip6_input+0x130/0x570
[ 1217.768282][ C2] ipv6_rcv+0x3c1/0x5a0
[ 1217.768403][ C2] __netif_receive_skb_one_core+0xfc/0x180
[ 1217.768656][ C2] process_backlog+0x431/0x14c0
[ 1217.768814][ C2] __napi_poll+0xa7/0x3b0
[ 1217.768996][ C2] net_rx_action+0x513/0xf50
[ 1217.769154][ C2] handle_softirqs+0x1d3/0x900
[ 1217.769369][ C2] do_softirq+0xac/0xe0
[ 1217.769488][ C2] __local_bh_enable_ip+0x118/0x150
[ 1217.769703][ C2] __dev_queue_xmit+0x989/0x1b90
[ 1217.769860][ C2] ip6_finish_output2+0x9e0/0x13f0
[ 1217.770075][ C2] ip6_finish_output+0x701/0xe80
[ 1217.770230][ C2] ip6_output+0x23f/0x7f0
[ 1217.770347][ C2] ip6_xmit+0xc44/0x1ec0
[ 1217.770523][ C2] inet6_csk_xmit+0x2f6/0x5f0
[ 1217.770684][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 1217.770897][ C2] tcp_write_xmit+0x5a4/0x3080
[ 1217.771056][ C2] __tcp_push_pending_frames+0x8f/0x3b0
[ 1217.771268][ C2] inet_shutdown+0x248/0x360
[ 1217.771427][ C2] __sys_shutdown+0x10b/0x190
[ 1217.771641][ C2] __x64_sys_shutdown+0x52/0x90
[ 1217.771797][ C2] do_syscall_64+0xff/0x530
[ 1217.772013][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1217.772210][ C2]
[ 1217.772345][ C2] Freed by task 0:
[ 1217.772467][ C2] kasan_save_stack+0x2f/0x50
[ 1217.772684][ C2] kasan_save_track+0x14/0x30
[ 1217.772840][ C2] kasan_save_free_info+0x3b/0x60
[ 1217.773056][ C2] __kasan_slab_free+0x43/0x70
[ 1217.773210][ C2] slab_free_after_rcu_debug+0xa6/0x100
[ 1217.773422][ C2] rcu_do_batch+0x2b6/0x1000
[ 1217.773582][ C2] rcu_core+0x34e/0x8e0
[ 1217.773699][ C2] handle_softirqs+0x1d3/0x900
[ 1217.773916][ C2] __irq_exit_rcu+0x145/0x1c0
[ 1217.774076][ C2] irq_exit_rcu+0xe/0x30
[ 1217.774249][ C2] sysvec_apic_timer_interrupt+0x9d/0xe0
[ 1217.774409][ C2] asm_sysvec_apic_timer_interrupt+0x1a/0x20
[ 1217.774662][ C2]
[ 1217.774743][ C2] Last potentially related work creation:
[ 1217.774962][ C2] kasan_save_stack+0x2f/0x50
[ 1217.775127][ C2] kasan_record_aux_stack+0x9b/0xc0
[ 1217.775343][ C2] kmem_cache_free+0x37a/0x550
[ 1217.775501][ C2] inet_twsk_put+0x11b/0x1a0
[ 1217.775716][ C2] inet_twsk_purge+0x4dd/0x670
[ 1217.775875][ C2] tcp_twsk_purge+0x123/0x1a0
[ 1217.776094][ C2] tcp_sk_exit_batch+0x2b/0x160
[ 1217.776250][ C2] ops_undo_list+0x2ce/0x8f0
[ 1217.776467][ C2] cleanup_net+0x431/0x940
[ 1217.776625][ C2] process_one_work+0xe3e/0x1560
[ 1217.776840][ C2] worker_thread+0x4f1/0xd60
[ 1217.777001][ C2] kthread+0x367/0x460
[ 1217.777180][ C2] ret_from_fork+0x474/0x6b0
[ 1217.777342][ C2] ret_from_fork_asm+0x11/0x20
[ 1217.777557][ C2]
[ 1217.777639][ C2] The buggy address belongs to the object at ff1100000ef17528
[ 1217.777639][ C2] which belongs to the cache tw_sock_TCPv6 of size 288
[ 1217.778125][ C2] The buggy address is located 144 bytes inside of
[ 1217.778125][ C2] freed 288-byte region [ff1100000ef17528, ff1100000ef17648)
[ 1217.778568][ C2]
[ 1217.778704][ C2] The buggy address belongs to the physical page:
[ 1217.778902][ C2] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000ef16d08 pfn:0xef16
[ 1217.779289][ C2] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 1217.779591][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 1217.779855][ C2] page_type: f5(slab)
[ 1217.779985][ C2] raw: 0080000000000240 ff11000006319e40 ffd4000000304d90 ff110000063210c8
[ 1217.780332][ C2] raw: ff1100000ef16d08 0000000000130001 00000000f5000000 0000000000000000
[ 1217.780675][ C2] head: 0080000000000240 ff11000006319e40 ffd4000000304d90 ff110000063210c8
[ 1217.781023][ C2] head: ff1100000ef16d08 0000000000130001 00000000f5000000 0000000000000000
[ 1217.781364][ C2] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 1217.781647][ C2] head: ff11000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 1217.781995][ C2] page dumped because: kasan: bad access detected
[ 1217.782250][ C2]
[ 1217.782330][ C2] Memory state around the buggy address:
[ 1217.782542][ C2] ff1100000ef17480: fb fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc
[ 1217.782777][ C2] ff1100000ef17500: fc fc fc fc fc fa fb fb fb fb fb fb fb fb fb fb
[ 1217.783069][ C2] >ff1100000ef17580: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 1217.783352][ C2] ^
[ 1217.783603][ C2] ff1100000ef17600: fb fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc
[ 1217.783832][ C2] ff1100000ef17680: fc fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb
[ 1217.784123][ C2] ==================================================================
[ 1217.784462][ C2] Disabling lock debugging due to kernel taint