[ 43.170069][ T293] ip (293) used greatest stack depth: 24032 bytes left
[ 49.664138][ C2] ==================================================================
[ 49.664451][ C2] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0
[ 49.664680][ C2] Read of size 8 at addr ff110000142e0718 by task msg_zerocopy/332
[ 49.664900][ C2]
[ 49.664977][ C2] CPU: 2 UID: 0 PID: 332 Comm: msg_zerocopy Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 49.664980][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 49.664982][ C2] Call Trace:
[ 49.664984][ C2]
[ 49.664985][ C2] dump_stack_lvl+0x6f/0xa0
[ 49.664990][ C2] print_address_description.constprop.0+0x56/0x2d0
[ 49.664995][ C2] print_report+0xfc/0x1fa
[ 49.664996][ C2] ? __virt_addr_valid+0x102/0x440
[ 49.664999][ C2] ? __virt_addr_valid+0x1da/0x440
[ 49.665001][ C2] kasan_report+0x108/0x130
[ 49.665004][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 49.665006][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 49.665008][ C2] kasan_check_range+0x130/0x200
[ 49.665010][ C2] ? make_kuid+0x13/0x20
[ 49.665013][ C2] tcp_v6_send_response+0xe7d/0x24e0
[ 49.665015][ C2] ? __mod_timer+0x3ad/0xc60
[ 49.665019][ C2] ? tcp_v6_send_synack+0xe10/0xe10
[ 49.665020][ C2] ? __lock_acquire+0x518/0xc20
[ 49.665024][ C2] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 49.665027][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 49.665029][ C2] ? rcu_is_watching+0x16/0xd0
[ 49.665032][ C2] tcp_v6_rcv+0x24c5/0x3250
[ 49.665036][ C2] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 49.665039][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 49.665043][ C2] ip6_input_finish+0x196/0x590
[ 49.665045][ C2] ip6_input+0x130/0x570
[ 49.665046][ C2] ? ip6_input_finish+0x590/0x590
[ 49.665048][ C2] ? ip6_rcv_core+0xe22/0x1be0
[ 49.665050][ C2] ipv6_rcv+0x3c1/0x5a0
[ 49.665052][ C2] ? ip6_rcv_core+0x1be0/0x1be0
[ 49.665053][ C2] ? rcu_is_watching+0x16/0xd0
[ 49.665054][ C2] ? __update_load_avg_cfs_rq+0x36c/0x10c0
[ 49.665057][ C2] ? mark_usage+0x61/0x170
[ 49.665059][ C2] ? __lock_acquire+0x518/0xc20
[ 49.665060][ C2] ? irq_matrix_free+0x487/0x600
[ 49.665064][ C2] ? process_backlog+0x3f1/0x14c0
[ 49.665067][ C2] __netif_receive_skb_one_core+0xfc/0x180
[ 49.665069][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 49.665071][ C2] ? process_backlog+0x3f1/0x14c0
[ 49.665073][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 49.665075][ C2] ? rcu_is_watching+0x16/0xd0
[ 49.665077][ C2] process_backlog+0x431/0x14c0
[ 49.665080][ C2] __napi_poll+0xa7/0x3b0
[ 49.665082][ C2] net_rx_action+0x513/0xf50
[ 49.665085][ C2] ? __lock_acquire+0x518/0xc20
[ 49.665087][ C2] ? __napi_poll+0x3b0/0x3b0
[ 49.665090][ C2] ? ktime_get_update_offsets_now+0x2a8/0x490
[ 49.665093][ C2] ? mark_held_locks+0x40/0x70
[ 49.665095][ C2] handle_softirqs+0x1d3/0x900
[ 49.665098][ C2] ? _local_bh_enable+0xc0/0xc0
[ 49.665099][ C2] ? do_raw_spin_unlock+0x59/0x250
[ 49.665102][ C2] ? rcu_is_watching+0x16/0xd0
[ 49.665103][ C2] ? __dev_queue_xmit+0x974/0x1b90
[ 49.665105][ C2] do_softirq+0xac/0xe0
[ 49.665107][ C2]
[ 49.665107][ C2]
[ 49.665108][ C2] __local_bh_enable_ip+0x118/0x150
[ 49.665110][ C2] __dev_queue_xmit+0x989/0x1b90
[ 49.665112][ C2] ? __lock_acquire+0x518/0xc20
[ 49.665114][ C2] ? irq_matrix_allocated+0x108/0x120
[ 49.665116][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 49.665118][ C2] ? find_held_lock+0x2b/0x80
[ 49.665120][ C2] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 49.665122][ C2] ? __asan_memcpy+0x3c/0x60
[ 49.665125][ C2] ? eth_header+0x14c/0x180
[ 49.665128][ C2] ? neigh_resolve_output.part.0+0x344/0x740
[ 49.665131][ C2] ip6_finish_output2+0x48d/0x13f0
[ 49.665135][ C2] ? ip6_dst_lookup+0x80/0x80
[ 49.665137][ C2] ? find_held_lock+0x2b/0x80
[ 49.665138][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 49.665140][ C2] ? ip6_mtu+0x174/0x410
[ 49.665143][ C2] ip6_finish_output+0x701/0xe80
[ 49.665146][ C2] ip6_output+0x23f/0x7f0
[ 49.665148][ C2] ? ip6_finish_output+0xe80/0xe80
[ 49.665150][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 49.665152][ C2] ? find_held_lock+0x2b/0x80
[ 49.665153][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 49.665156][ C2] ip6_xmit+0xc44/0x1ec0
[ 49.665158][ C2] ? mark_usage+0x61/0x170
[ 49.665159][ C2] ? __lock_acquire+0x518/0xc20
[ 49.665162][ C2] ? ip6_autoflowlabel+0x120/0x120
[ 49.665164][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 49.665166][ C2] ? mark_usage+0x61/0x170
[ 49.665167][ C2] ? __lock_acquire+0x518/0xc20
[ 49.665170][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 49.665171][ C2] ? inet6_csk_xmit+0xfe/0x5f0
[ 49.665173][ C2] ? rcu_is_watching+0x16/0xd0
[ 49.665175][ C2] ? lock_acquire+0x13c/0x160
[ 49.665177][ C2] inet6_csk_xmit+0x2f6/0x5f0
[ 49.665179][ C2] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 49.665184][ C2] ? __lock_acquire+0x518/0xc20
[ 49.665186][ C2] ? __tcp_select_window+0x1040/0x1040
[ 49.665188][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 49.665189][ C2] ? find_held_lock+0x2b/0x80
[ 49.665193][ C2] tcp_write_xmit+0x5a4/0x3080
[ 49.665196][ C2] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 49.665199][ C2] ? tcp_set_state+0x101/0x580
[ 49.665201][ C2] __tcp_push_pending_frames+0x8f/0x3b0
[ 49.665203][ C2] __tcp_close+0x84e/0xe70
[ 49.665205][ C2] ? mark_held_locks+0x40/0x70
[ 49.665207][ C2] tcp_close+0x23/0xb0
[ 49.665208][ C2] inet_release+0x10a/0x240
[ 49.665211][ C2] ? fcntl_setlk+0xce0/0xce0
[ 49.665215][ C2] __sock_release+0xb8/0x280
[ 49.665218][ C2] sock_close+0x18/0x20
[ 49.665219][ C2] __fput+0x36c/0xad0
[ 49.665222][ C2] fput_close_sync+0xde/0x1b0
[ 49.665224][ C2] ? alloc_file_clone+0xe0/0xe0
[ 49.665226][ C2] ? do_raw_spin_unlock+0x59/0x250
[ 49.665228][ C2] __x64_sys_close+0x8b/0xf0
[ 49.665230][ C2] do_syscall_64+0xff/0x530
[ 49.665233][ C2] ? irq_exit_rcu+0x1a/0x30
[ 49.665235][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 49.665238][ C2] RIP: 0033:0x7fd6899a054e
[ 49.665241][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 49.665242][ C2] RSP: 002b:00007ffd57473280 EFLAGS: 00000202 ORIG_RAX: 0000000000000003
[ 49.665246][ C2] RAX: ffffffffffffffda RBX: 0000000000000006 RCX: 00007fd6899a054e
[ 49.665248][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000006
[ 49.665248][ C2] RBP: 00007ffd57473290 R08: 0000000000000000 R09: 0000000000000000
[ 49.665249][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 000000000000000a
[ 49.665250][ C2] R13: 00007ffd574733b0 R14: 0000000000000001 R15: 000001a05db0b5c8
[ 49.665253][ C2]
[ 49.665253][ C2]
[ 49.683886][ C2] The buggy address belongs to the object at ff110000142e0688
[ 49.683886][ C2] which belongs to the cache tw_sock_TCPv6 of size 288
[ 49.684397][ C2] The buggy address is located 144 bytes inside of
[ 49.684397][ C2] allocated 288-byte region [ff110000142e0688, ff110000142e07a8)
[ 49.684857][ C2]
[ 49.684932][ C2] The buggy address belongs to the physical page:
[ 49.685169][ C2] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff110000142e0008 pfn:0x142e0
[ 49.685534][ C2] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 49.685821][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 49.686013][ C2] page_type: f5(slab)
[ 49.686189][ C2] raw: 0080000000000240 ff110000063b9e40 ff110000063c10c8 ff110000063c10c8
[ 49.686521][ C2] raw: ff110000142e0008 0000000000130001 00000000f5000000 0000000000000000
[ 49.686847][ C2] head: 0080000000000240 ff110000063b9e40 ff110000063c10c8 ff110000063c10c8
[ 49.687110][ C2] head: ff110000142e0008 0000000000130001 00000000f5000000 0000000000000000
[ 49.687433][ C2] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 49.687751][ C2] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 49.688073][ C2] page dumped because: kasan: bad access detected
[ 49.688319][ C2]
[ 49.688397][ C2] Memory state around the buggy address:
[ 49.688554][ C2] ff110000142e0600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 49.688831][ C2] ff110000142e0680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 49.689101][ C2] >ff110000142e0700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 49.689371][ C2] ^
[ 49.689521][ C2] ff110000142e0780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 49.689794][ C2] ff110000142e0800: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 49.690063][ C2] ==================================================================
[ 49.690323][ C2] Disabling lock debugging due to kernel taint