[ 1283.115461][ C2] ==================================================================
[ 1283.115714][ C2] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe7d/0x24e0
[ 1283.115929][ C2] Read of size 8 at addr ff1100000f6dc578 by task swapper/2/0
[ 1283.116141][ C2]
[ 1283.116216][ C2] CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 1283.116219][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 1283.116221][ C2] Call Trace:
[ 1283.116222][ C2]
[ 1283.116224][ C2] dump_stack_lvl+0x6f/0xa0
[ 1283.116229][ C2] print_address_description.constprop.0+0x56/0x2d0
[ 1283.116233][ C2] print_report+0xfc/0x1fa
[ 1283.116235][ C2] ? __virt_addr_valid+0x102/0x440
[ 1283.116238][ C2] ? __virt_addr_valid+0x1da/0x440
[ 1283.116239][ C2] kasan_report+0x108/0x130
[ 1283.116242][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1283.116244][ C2] ? tcp_v6_send_response+0xe7d/0x24e0
[ 1283.116251][ C2] kasan_check_range+0x130/0x200
[ 1283.116253][ C2] ? make_kuid+0x13/0x20
[ 1283.116255][ C2] tcp_v6_send_response+0xe7d/0x24e0
[ 1283.116259][ C2] ? tcp_v6_send_synack+0xe10/0xe10
[ 1283.116261][ C2] ? mark_usage+0x61/0x170
[ 1283.116265][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1283.116266][ C2] ? tcp_v6_send_reset+0x22d/0x12e0
[ 1283.116268][ C2] tcp_v6_send_reset+0xd6b/0x12e0
[ 1283.116271][ C2] ? mqueue_poll_file+0x8/0x140
[ 1283.116275][ C2] ? trace_fib6_table_lookup+0xd1/0x1c0
[ 1283.116278][ C2] ? tcp_v6_reqsk_send_ack+0x8c0/0x8c0
[ 1283.116279][ C2] ? tcp_timewait_state_process+0x48e/0xf70
[ 1283.116283][ C2] ? ip6_pol_route+0x2e7/0xaa0
[ 1283.116285][ C2] ? __asan_memcpy+0x3c/0x60
[ 1283.116288][ C2] tcp_v6_rcv+0x261f/0x3250
[ 1283.116293][ C2] ? __lock_acquire+0x893/0xc20
[ 1283.116296][ C2] ? tcp_v6_syn_recv_sock+0x1b90/0x1b90
[ 1283.116298][ C2] ? ipv6_raw_deliver+0x369/0x930
[ 1283.116301][ C2] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 1283.116304][ C2] ip6_input_finish+0x196/0x590
[ 1283.116305][ C2] ip6_input+0x130/0x570
[ 1283.116307][ C2] ? ip6_input_finish+0x590/0x590
[ 1283.116308][ C2] ? ip6_rcv_core+0xe22/0x1be0
[ 1283.116310][ C2] ipv6_rcv+0x3c1/0x5a0
[ 1283.116311][ C2] ? ip6_rcv_core+0x1be0/0x1be0
[ 1283.116313][ C2] ? mark_usage+0x61/0x170
[ 1283.116315][ C2] ? __lock_acquire+0x518/0xc20
[ 1283.116317][ C2] ? process_backlog+0x3f1/0x14c0
[ 1283.116320][ C2] __netif_receive_skb_one_core+0xfc/0x180
[ 1283.116322][ C2] ? lock_acquire.part.0+0xd4/0x280
[ 1283.116323][ C2] ? process_backlog+0x3f1/0x14c0
[ 1283.116325][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 1283.116327][ C2] ? rcu_is_watching+0x16/0xd0
[ 1283.116330][ C2] process_backlog+0x431/0x14c0
[ 1283.116332][ C2] __napi_poll+0xa7/0x3b0
[ 1283.116335][ C2] net_rx_action+0x513/0xf50
[ 1283.116338][ C2] ? __lock_acquire+0x518/0xc20
[ 1283.116339][ C2] ? __napi_poll+0x3b0/0x3b0
[ 1283.116341][ C2] ? find_held_lock+0x2b/0x80
[ 1283.116344][ C2] ? _raw_spin_unlock_irq+0x33/0x50
[ 1283.116348][ C2] ? run_timer_softirq+0xf8/0x160
[ 1283.116351][ C2] ? rcu_is_watching+0x16/0xd0
[ 1283.116352][ C2] handle_softirqs+0x1d3/0x900
[ 1283.116355][ C2] ? __lock_release.isra.0+0x69/0x1a0
[ 1283.116357][ C2] ? _local_bh_enable+0xc0/0xc0
[ 1283.116359][ C2] __irq_exit_rcu+0x145/0x1c0
[ 1283.116361][ C2] irq_exit_rcu+0xe/0x30
[ 1283.116362][ C2] sysvec_apic_timer_interrupt+0x9d/0xe0
[ 1283.116365][ C2]
[ 1283.116365][ C2]
[ 1283.116366][ C2] asm_sysvec_apic_timer_interrupt+0x1a/0x20
[ 1283.116369][ C2] RIP: 0010:pv_native_safe_halt+0xf/0x10
[ 1283.116371][ C2] Code: 48 8b 3d 94 e2 67 02 e8 1f 00 00 00 48 2b 05 58 33 a0 00 c3 0f 1f 80 00 00 00 00 f3 0f 1e fa eb 07 0f 00 2d 13 56 0d 00 fb f4 0f 1f 40 d6 48 83 ec 20 8b 17 49 89 f8 83 e2 fe 41 89 d2 0f 01
[ 1283.116373][ C2] RSP: 0018:ffa0000000157e00 EFLAGS: 00000282
[ 1283.116377][ C2] RAX: 0000000004bf0da9 RBX: ff11000001c1c740 RCX: ffffffffab706247
[ 1283.116378][ C2] RDX: ff11000001c1c740 RSI: ffffffffae9116a7 RDI: ffffffffae2949e0
[ 1283.116379][ C2] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
[ 1283.116380][ C2] R10: 0000000000000002 R11: 0000000000000001 R12: 1ff400000002afc3
[ 1283.116381][ C2] R13: 0000000000000000 R14: dffffc0000000000 R15: 0000000000000000
[ 1283.116382][ C2] ? cpuidle_idle_call.constprop.0+0x237/0x410
[ 1283.116386][ C2] default_idle+0x9/0x10
[ 1283.116388][ C2] default_idle_call+0x6e/0xb0
[ 1283.116389][ C2] cpuidle_idle_call.constprop.0+0x237/0x410
[ 1283.116391][ C2] ? arch_cpu_idle_exit+0x40/0x40
[ 1283.116393][ C2] ? mark_tsc_async_resets+0x30/0x30
[ 1283.116396][ C2] ? rcu_is_watching+0x16/0xd0
[ 1283.116397][ C2] do_idle+0xd8/0x190
[ 1283.116399][ C2] cpu_startup_entry+0x53/0x70
[ 1283.116401][ C2] start_secondary+0x204/0x2b0
[ 1283.116403][ C2] ? set_cpu_sibling_map+0x2130/0x2130
[ 1283.116405][ C2] common_startup_64+0x13e/0x148
[ 1283.116409][ C2]
[ 1283.116410][ C2]
[ 1283.128524][ C2] The buggy address belongs to the object at ff1100000f6dc4e8
[ 1283.128524][ C2] which belongs to the cache tw_sock_TCPv6 of size 288
[ 1283.128902][ C2] The buggy address is located 144 bytes inside of
[ 1283.128902][ C2] allocated 288-byte region [ff1100000f6dc4e8, ff1100000f6dc608)
[ 1283.129285][ C2]
[ 1283.129357][ C2] The buggy address belongs to the physical page:
[ 1283.129532][ C2] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000f6dc1a8 pfn:0xf6dc
[ 1283.129819][ C2] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 1283.130034][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 1283.130217][ C2] page_type: f5(slab)
[ 1283.130332][ C2] raw: 0080000000000240 ff11000005e17e40 ff11000005e1f0c8 ff11000005e1f0c8
[ 1283.130587][ C2] raw: ff1100000f6dc1a8 0000000000130001 00000000f5000000 0000000000000000
[ 1283.130834][ C2] head: 0080000000000240 ff11000005e17e40 ff11000005e1f0c8 ff11000005e1f0c8
[ 1283.131088][ C2] head: ff1100000f6dc1a8 0000000000130001 00000000f5000000 0000000000000000
[ 1283.131344][ C2] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 1283.131593][ C2] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 1283.131841][ C2] page dumped because: kasan: bad access detected
[ 1283.132014][ C2]
[ 1283.132086][ C2] Memory state around the buggy address:
[ 1283.132226][ C2] ff1100000f6dc400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1283.132438][ C2] ff1100000f6dc480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1283.132646][ C2] >ff1100000f6dc500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1283.132850][ C2] ^
[ 1283.133058][ C2] ff1100000f6dc580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1283.133270][ C2] ff1100000f6dc600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1283.133473][ C2] ==================================================================
[ 1283.133721][ C2] Disabling lock debugging due to kernel taint