[ 359.503120][ C0] ==================================================================
[ 359.503409][ C0] BUG: KASAN: slab-use-after-free in tcp_v6_send_response+0xe7d/0x24e0
[ 359.503650][ C0] Read of size 8 at addr ff11000005d7d0d8 by task iperf3/8233
[ 359.503893][ C0]
[ 359.503977][ C0] CPU: 0 UID: 0 PID: 8233 Comm: iperf3 Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 359.503980][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 359.503982][ C0] Call Trace:
[ 359.503984][ C0]
[ 359.503985][ C0] dump_stack_lvl+0x6f/0xa0
[ 359.503990][ C0] print_address_description.constprop.0+0x56/0x2d0
[ 359.503994][ C0] print_report+0xfc/0x1fa
[ 359.503996][ C0] ? __virt_addr_valid+0x102/0x440
[ 359.503999][ C0] ? __virt_addr_valid+0x1da/0x440
[ 359.504001][ C0] kasan_report+0x108/0x130
[ 359.504004][ C0] ? tcp_v6_send_response+0xe7d/0x24e0
[ 359.504006][ C0] ? tcp_v6_send_response+0xe7d/0x24e0
[ 359.504008][ C0] kasan_check_range+0x130/0x200
[ 359.504010][ C0] ? make_kuid+0x13/0x20
[ 359.504013][ C0] tcp_v6_send_response+0xe7d/0x24e0
[ 359.504014][ C0] ? __mod_timer+0x3ad/0xc60
[ 359.504018][ C0] ? tcp_v6_send_synack+0xe10/0xe10
[ 359.504019][ C0] ? __lock_acquire+0x518/0xc20
[ 359.504022][ C0] ? logarithmic_accumulation.constprop.0+0x115/0x350
[ 359.504025][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 359.504027][ C0] ? rcu_is_watching+0x16/0xd0
[ 359.504030][ C0] tcp_v6_rcv+0x24c5/0x3250
[ 359.504034][ C0] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 359.504037][ C0] ? nf_hook_egress+0x430/0x430
[ 359.504040][ C0] ? is_bpf_text_address+0x72/0x110
[ 359.504043][ C0] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 359.504046][ C0] ip6_input_finish+0x196/0x590
[ 359.504048][ C0] ip6_input+0x130/0x570
[ 359.504049][ C0] ? ip6_input_finish+0x590/0x590
[ 359.504051][ C0] ? ip6_rcv_core+0xe22/0x1be0
[ 359.504053][ C0] ipv6_rcv+0x3c1/0x5a0
[ 359.504054][ C0] ? ip6_rcv_core+0x1be0/0x1be0
[ 359.504056][ C0] ? mark_usage+0x61/0x170
[ 359.504058][ C0] ? __lock_acquire+0x518/0xc20
[ 359.504059][ C0] ? irq_matrix_free+0x487/0x600
[ 359.504063][ C0] ? process_backlog+0x3f1/0x14c0
[ 359.504065][ C0] __netif_receive_skb_one_core+0xfc/0x180
[ 359.504067][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 359.504069][ C0] ? process_backlog+0x3f1/0x14c0
[ 359.504071][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 359.504073][ C0] ? rcu_is_watching+0x16/0xd0
[ 359.504075][ C0] process_backlog+0x431/0x14c0
[ 359.504078][ C0] __napi_poll+0xa7/0x3b0
[ 359.504080][ C0] net_rx_action+0x513/0xf50
[ 359.504083][ C0] ? wakeup_preempt_fair+0x572/0x15d0
[ 359.504086][ C0] ? __napi_poll+0x3b0/0x3b0
[ 359.504088][ C0] ? find_held_lock+0x2b/0x80
[ 359.504092][ C0] ? mark_held_locks+0x40/0x70
[ 359.504094][ C0] handle_softirqs+0x1d3/0x900
[ 359.504097][ C0] ? _local_bh_enable+0xc0/0xc0
[ 359.504099][ C0] ? rcu_is_watching+0x16/0xd0
[ 359.504100][ C0] ? trace_csd_function_exit+0xb3/0x180
[ 359.504102][ C0] ? __dev_queue_xmit+0x974/0x1b90
[ 359.504104][ C0] do_softirq+0xac/0xe0
[ 359.504106][ C0]
[ 359.504107][ C0]
[ 359.504107][ C0] __local_bh_enable_ip+0x118/0x150
[ 359.504109][ C0] __dev_queue_xmit+0x989/0x1b90
[ 359.504111][ C0] ? mark_held_locks+0x40/0x70
[ 359.504113][ C0] ? push_cpu_stop+0x9c3/0xc50
[ 359.504115][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 359.504117][ C0] ? lock_acquire.part.0+0x60/0x280
[ 359.504119][ C0] ? find_held_lock+0x2b/0x80
[ 359.504120][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 359.504122][ C0] ? rcu_is_watching+0x16/0xd0
[ 359.504123][ C0] ? mark_held_locks+0x40/0x70
[ 359.504128][ C0] ? __asan_memcpy+0x3c/0x60
[ 359.504131][ C0] ? neigh_hh_output+0x152/0x4c0
[ 359.504134][ C0] ip6_finish_output2+0x9e0/0x13f0
[ 359.504137][ C0] ? ip6_dst_lookup+0x80/0x80
[ 359.504138][ C0] ? find_held_lock+0x2b/0x80
[ 359.504140][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 359.504142][ C0] ? ip6_mtu+0x174/0x410
[ 359.504145][ C0] ip6_finish_output+0x701/0xe80
[ 359.504148][ C0] ip6_output+0x23f/0x7f0
[ 359.504150][ C0] ? ip6_finish_output+0xe80/0xe80
[ 359.504152][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 359.504153][ C0] ? find_held_lock+0x2b/0x80
[ 359.504155][ C0] ? __lock_release.isra.0+0x69/0x1a0
[ 359.504157][ C0] ip6_xmit+0xc44/0x1ec0
[ 359.504159][ C0] ? find_held_lock+0x2b/0x80
[ 359.504162][ C0] ? ip6_autoflowlabel+0x120/0x120
[ 359.504164][ C0] ? find_held_lock+0x2b/0x80
[ 359.504165][ C0] ? mark_usage+0x61/0x170
[ 359.504167][ C0] ? __lock_acquire+0x518/0xc20
[ 359.504169][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 359.504170][ C0] ? inet6_csk_xmit+0xfe/0x5f0
[ 359.504173][ C0] ? rcu_is_watching+0x16/0xd0
[ 359.504174][ C0] ? inet6_csk_route_socket+0x749/0xb60
[ 359.504176][ C0] ? lock_acquire+0x13c/0x160
[ 359.504178][ C0] inet6_csk_xmit+0x2f6/0x5f0
[ 359.504180][ C0] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 359.504185][ C0] ? __lock_acquire+0x518/0xc20
[ 359.504187][ C0] ? __tcp_select_window+0x1040/0x1040
[ 359.504189][ C0] ? lock_acquire.part.0+0xd4/0x280
[ 359.504190][ C0] ? find_held_lock+0x2b/0x80
[ 359.504194][ C0] tcp_write_xmit+0x5a4/0x3080
[ 359.504197][ C0] ? tcp_retrans_try_collapse+0x1090/0x1090
[ 359.504199][ C0] ? skb_attempt_defer_free+0x270/0x790
[ 359.504202][ C0] ? tcp_set_state+0x101/0x580
[ 359.504204][ C0] __tcp_push_pending_frames+0x8f/0x3b0
[ 359.504206][ C0] __tcp_close+0x84e/0xe70
[ 359.504208][ C0] tcp_close+0x23/0xb0
[ 359.504210][ C0] inet_release+0x10a/0x240
[ 359.504213][ C0] ? fcntl_setlk+0xce0/0xce0
[ 359.504216][ C0] __sock_release+0xb8/0x280
[ 359.504219][ C0] sock_close+0x18/0x20
[ 359.504221][ C0] __fput+0x36c/0xad0
[ 359.504224][ C0] fput_close_sync+0xde/0x1b0
[ 359.504226][ C0] ? alloc_file_clone+0xe0/0xe0
[ 359.504228][ C0] ? do_raw_spin_unlock+0x59/0x250
[ 359.504230][ C0] __x64_sys_close+0x8b/0xf0
[ 359.504232][ C0] do_syscall_64+0xff/0x530
[ 359.504234][ C0] ? irq_exit_rcu+0x1a/0x30
[ 359.504236][ C0] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 359.504238][ C0] RIP: 0033:0x7f1e93d6a312
[ 359.504241][ C0] Code: 08 0f 85 71 41 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 bf 01 00
[ 359.504243][ C0] RSP: 002b:00007ffd3814ee78 EFLAGS: 00000246 ORIG_RAX: 0000000000000003
[ 359.504247][ C0] RAX: ffffffffffffffda RBX: 0000561b06801d30 RCX: 00007f1e93d6a312
[ 359.504248][ C0] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000007
[ 359.504249][ C0] RBP: 00007ffd3814eea0 R08: 0000000000000000 R09: 0000000000000000
[ 359.504250][ C0] R10: 0000000000000000 R11: 0000000000000246 R12: 0000561b067ff010
[ 359.504250][ C0] R13: 0000000000000000 R14: 000000000000006d R15: 0000561b067ff010
[ 359.504253][ C0]
[ 359.504254][ C0]
[ 359.524115][ C0] Allocated by task 6363:
[ 359.524243][ C0] kasan_save_stack+0x2f/0x50
[ 359.524407][ C0] kasan_save_track+0x14/0x30
[ 359.524564][ C0] __kasan_slab_alloc+0x60/0x70
[ 359.524721][ C0] kmem_cache_alloc_noprof+0x21f/0x5c0
[ 359.524879][ C0] inet_twsk_alloc+0x123/0x9e0
[ 359.525038][ C0] tcp_time_wait+0x5d/0x11f0
[ 359.525197][ C0] tcp_fin+0x377/0x470
[ 359.525316][ C0] tcp_data_queue+0xc1d/0x2050
[ 359.525473][ C0] tcp_rcv_state_process+0x759/0x24e0
[ 359.525632][ C0] tcp_v6_do_rcv+0x654/0x1640
[ 359.525790][ C0] tcp_v6_rcv+0x1b27/0x3250
[ 359.525947][ C0] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 359.526106][ C0] ip6_input_finish+0x196/0x590
[ 359.526266][ C0] ip6_input+0x130/0x570
[ 359.526385][ C0] ipv6_rcv+0x3c1/0x5a0
[ 359.526502][ C0] __netif_receive_skb_one_core+0xfc/0x180
[ 359.526698][ C0] process_backlog+0x431/0x14c0
[ 359.526857][ C0] __napi_poll+0xa7/0x3b0
[ 359.526975][ C0] net_rx_action+0x513/0xf50
[ 359.527137][ C0] handle_softirqs+0x1d3/0x900
[ 359.527294][ C0] do_softirq+0xac/0xe0
[ 359.527413][ C0] __local_bh_enable_ip+0x118/0x150
[ 359.527569][ C0] __dev_queue_xmit+0x989/0x1b90
[ 359.527726][ C0] ip6_finish_output2+0x9e0/0x13f0
[ 359.527887][ C0] ip6_finish_output+0x701/0xe80
[ 359.528045][ C0] ip6_output+0x23f/0x7f0
[ 359.528167][ C0] ip6_xmit+0xc44/0x1ec0
[ 359.528285][ C0] inet6_csk_xmit+0x2f6/0x5f0
[ 359.528441][ C0] __tcp_transmit_skb+0x1c3e/0x3cd0
[ 359.528597][ C0] tcp_write_xmit+0x5a4/0x3080
[ 359.528753][ C0] __tcp_push_pending_frames+0x8f/0x3b0
[ 359.528908][ C0] __tcp_close+0x84e/0xe70
[ 359.529066][ C0] tcp_close+0x23/0xb0
[ 359.529188][ C0] inet_release+0x10a/0x240
[ 359.529348][ C0] __sock_release+0xb8/0x280
[ 359.529504][ C0] sock_close+0x18/0x20
[ 359.529620][ C0] __fput+0x36c/0xad0
[ 359.529741][ C0] fput_close_sync+0xde/0x1b0
[ 359.529899][ C0] __x64_sys_close+0x8b/0xf0
[ 359.530056][ C0] do_syscall_64+0xff/0x530
[ 359.530218][ C0] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 359.530415][ C0]
[ 359.530496][ C0] Freed by task 33:
[ 359.530618][ C0] kasan_save_stack+0x2f/0x50
[ 359.530777][ C0] kasan_save_track+0x14/0x30
[ 359.530935][ C0] kasan_save_free_info+0x3b/0x60
[ 359.531092][ C0] __kasan_slab_free+0x43/0x70
[ 359.531255][ C0] slab_free_after_rcu_debug+0xa6/0x100
[ 359.531413][ C0] rcu_do_batch+0x2b6/0x1000
[ 359.531570][ C0] rcu_core+0x34e/0x8e0
[ 359.531690][ C0] handle_softirqs+0x1d3/0x900
[ 359.531847][ C0] run_ksoftirqd+0x39/0x60
[ 359.532003][ C0] smpboot_thread_fn+0x2fb/0x9b0
[ 359.532167][ C0] kthread+0x367/0x460
[ 359.532287][ C0] ret_from_fork+0x474/0x6b0
[ 359.532446][ C0] ret_from_fork_asm+0x11/0x20
[ 359.532604][ C0]
[ 359.532688][ C0] Last potentially related work creation:
[ 359.532847][ C0] kasan_save_stack+0x2f/0x50
[ 359.533008][ C0] kasan_record_aux_stack+0x9b/0xc0
[ 359.533171][ C0] kmem_cache_free+0x37a/0x550
[ 359.533332][ C0] inet_twsk_put+0x11b/0x1a0
[ 359.533490][ C0] inet_twsk_purge+0x4dd/0x670
[ 359.533649][ C0] tcp_twsk_purge+0x123/0x1a0
[ 359.533808][ C0] tcp_sk_exit_batch+0x2b/0x160
[ 359.533968][ C0] ops_undo_list+0x2ce/0x8f0
[ 359.534131][ C0] cleanup_net+0x431/0x940
[ 359.534290][ C0] process_one_work+0xe3e/0x1560
[ 359.534451][ C0] worker_thread+0x4f1/0xd60
[ 359.534608][ C0] kthread+0x367/0x460
[ 359.534726][ C0] ret_from_fork+0x474/0x6b0
[ 359.534883][ C0] ret_from_fork_asm+0x11/0x20
[ 359.535043][ C0]
[ 359.535129][ C0] The buggy address belongs to the object at ff11000005d7d048
[ 359.535129][ C0] which belongs to the cache tw_sock_TCPv6 of size 288
[ 359.535558][ C0] The buggy address is located 144 bytes inside of
[ 359.535558][ C0] freed 288-byte region [ff11000005d7d048, ff11000005d7d168)
[ 359.535944][ C0]
[ 359.536025][ C0] The buggy address belongs to the physical page:
[ 359.536229][ C0] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000005d7c828 pfn:0x5d7c
[ 359.536555][ C0] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 359.536798][ C0] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 359.537004][ C0] page_type: f5(slab)
[ 359.537133][ C0] raw: 0080000000000240 ff11000006323e40 ff1100000639b0c8 ff1100000639b0c8
[ 359.537423][ C0] raw: ff11000005d7c828 0000000000130001 00000000f5000000 0000000000000000
[ 359.537707][ C0] head: 0080000000000240 ff11000006323e40 ff1100000639b0c8 ff1100000639b0c8
[ 359.537995][ C0] head: ff11000005d7c828 0000000000130001 00000000f5000000 0000000000000000
[ 359.538283][ C0] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 359.538567][ C0] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 359.538847][ C0] page dumped because: kasan: bad access detected
[ 359.539047][ C0]
[ 359.539130][ C0] Memory state around the buggy address:
[ 359.539287][ C0] ff11000005d7cf80: fb fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc
[ 359.539522][ C0] ff11000005d7d000: fc fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb
[ 359.539754][ C0] >ff11000005d7d080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 359.539985][ C0] ^
[ 359.540185][ C0] ff11000005d7d100: fb fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc
[ 359.540417][ C0] ff11000005d7d180: fc fc fc fc fc fc fc fc fc fc fc fc fc fa fb fb
[ 359.540649][ C0] ==================================================================
[ 359.540894][ C0] Disabling lock debugging due to kernel taint