[ 495.938319][ T3178] netdevsim netdevsim13195 eni13195np1: renamed from eth0 [ 496.122957][ T3178] netdevsim netdevsim19551 eni19551np1: renamed from eth0 [ 501.551059][ C1] ================================================================== [ 501.551596][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 501.552031][ C1] Read of size 8 at addr ff110000117632c0 by task socat/3287 [ 501.552297][ C1] [ 501.552391][ C1] CPU: 1 UID: 0 PID: 3287 Comm: socat Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 501.552395][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 501.552397][ C1] Call Trace: [ 501.552398][ C1] [ 501.552400][ C1] dump_stack_lvl+0x6f/0xa0 [ 501.552406][ C1] print_address_description.constprop.0+0x56/0x2d0 [ 501.552411][ C1] print_report+0xfc/0x1fa [ 501.552413][ C1] ? __virt_addr_valid+0x102/0x440 [ 501.552416][ C1] ? __virt_addr_valid+0x1da/0x440 [ 501.552418][ C1] kasan_report+0x108/0x130 [ 501.552422][ C1] ? tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 501.552425][ C1] ? tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 501.552428][ C1] kasan_check_range+0x130/0x200 [ 501.552430][ C1] tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 501.552434][ C1] ? __xfrm_policy_check2.constprop.0+0x720/0x720 [ 501.552437][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 501.552441][ C1] ? rcu_is_watching+0x16/0xd0 [ 501.552444][ C1] ? mark_held_locks+0x40/0x70 [ 501.552446][ C1] tcp_v6_rcv+0x21cb/0x2de0 [ 501.552451][ C1] ? tcp_v6_syn_recv_sock+0x1ab0/0x1ab0 [ 501.552453][ C1] ? ipv6_raw_deliver+0x323/0x890 [ 501.552455][ C1] ? ipv6_raw_deliver+0x32d/0x890 [ 501.552457][ C1] ip6_protocol_deliver_rcu+0x15a/0x1290 [ 501.552461][ C1] ? rcu_is_watching+0x16/0xd0 [ 501.552463][ C1] ip6_input+0x223/0x5f0 [ 501.552465][ C1] ip6_sublist_rcv_finish+0x9e/0x2a0 [ 501.552467][ C1] ip6_list_rcv_finish.constprop.0+0x5a6/0xc10 [ 501.552470][ C1] ? ip6_rcv_finish_core.isra.0+0x5d0/0x5d0 [ 501.552472][ C1] ? update_group_capacity+0x660/0x660 [ 501.552475][ C1] ipv6_list_rcv+0x306/0x4f0 [ 501.552477][ C1] ? ipv6_rcv+0x1b0/0x1b0 [ 501.552479][ C1] ? common_startup_64+0x13e/0x148 [ 501.552483][ C1] __netif_receive_skb_list_core+0x4ac/0x9e0 [ 501.552487][ C1] ? __netif_receive_skb_core.constprop.0+0x2960/0x2960 [ 501.552489][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 501.552491][ C1] ? netif_receive_skb_list_internal+0x2f8/0xe20 [ 501.552493][ C1] ? csum_partial+0xc/0x20 [ 501.552497][ C1] ? lock_acquire+0x13c/0x160 [ 501.552500][ C1] netif_receive_skb_list_internal+0x5f8/0xe20 [ 501.552501][ C1] ? mark_usage+0x61/0x170 [ 501.552504][ C1] ? process_backlog+0x14c0/0x14c0 [ 501.552505][ C1] ? ipv6_gro_receive+0xb58/0x27e0 [ 501.552508][ C1] ? mark_usage+0x61/0x170 [ 501.552510][ C1] ? __lock_acquire+0x518/0xc20 [ 501.552512][ C1] ? reacquire_held_locks+0x1d2/0x240 [ 501.552515][ C1] napi_complete_done+0x1aa/0x8c0 [ 501.552517][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 501.552519][ C1] ? netif_receive_skb_list+0x50/0x50 [ 501.552521][ C1] ? nsim_start_peer_tx_queue.isra.0+0x11a/0x330 [netdevsim] [ 501.552528][ C1] nsim_poll+0x38c/0x570 [netdevsim] [ 501.552533][ C1] ? nsim_start_peer_tx_queue.isra.0+0x330/0x330 [netdevsim] [ 501.552537][ C1] ? rcu_lockdep_current_cpu_online+0x3f/0x1b0 [ 501.552538][ C1] ? rcu_read_lock_any_held+0x3c/0x90 [ 501.552541][ C1] __napi_poll+0xd4/0x3b0 [ 501.552544][ C1] net_rx_action+0x513/0xf50 [ 501.552546][ C1] ? __lock_acquire+0x518/0xc20 [ 501.552548][ C1] ? __napi_poll+0x3b0/0x3b0 [ 501.552552][ C1] ? ktime_get_update_offsets_now+0x2a8/0x490 [ 501.552555][ C1] ? mark_held_locks+0x40/0x70 [ 501.552557][ C1] handle_softirqs+0x1d3/0x900 [ 501.552561][ C1] ? _local_bh_enable+0xc0/0xc0 [ 501.552563][ C1] ? do_raw_spin_unlock+0x59/0x250 [ 501.552565][ C1] ? rcu_is_watching+0x16/0xd0 [ 501.552567][ C1] do_softirq+0xac/0xe0 [ 501.552569][ C1] [ 501.552570][ C1] [ 501.552571][ C1] ? __dev_queue_xmit+0x92b/0x1a10 [ 501.552572][ C1] __local_bh_enable_ip+0x118/0x150 [ 501.552574][ C1] __dev_queue_xmit+0x940/0x1a10 [ 501.552577][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 501.552579][ C1] ? netdev_core_pick_tx+0x2d0/0x2d0 [ 501.552581][ C1] ? __asan_memcpy+0x3c/0x60 [ 501.552582][ C1] ? eth_header+0x14c/0x180 [ 501.552586][ C1] ? neigh_resolve_output.part.0+0x344/0x740 [ 501.552590][ C1] ip6_finish_output+0x1f1/0xc50 [ 501.552592][ C1] ip6_output+0x186/0x4a0 [ 501.552594][ C1] ip6_xmit+0xb66/0x1930 [ 501.552597][ C1] ? ip6_autoflowlabel+0x120/0x120 [ 501.552598][ C1] ? __lock_acquire+0x518/0xc20 [ 501.552601][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 501.552603][ C1] ? inet6_csk_xmit+0xfe/0x5e0 [ 501.552605][ C1] ? rcu_is_watching+0x16/0xd0 [ 501.552606][ C1] ? lock_acquire+0x13c/0x160 [ 501.552608][ C1] inet6_csk_xmit+0x2ea/0x5e0 [ 501.552611][ C1] __tcp_transmit_skb+0x1ad9/0x3a70 [ 501.552615][ C1] ? __tcp_select_window+0xf20/0xf20 [ 501.552616][ C1] ? tcp_mtu_probe+0x19/0x1c80 [ 501.552619][ C1] tcp_write_xmit+0x10d6/0x36d0 [ 501.552621][ C1] ? ip6_mtu+0x167/0x310 [ 501.552624][ C1] ? tcp_connect_init+0x1250/0x1250 [ 501.552626][ C1] ? tcp_retrans_try_collapse+0xee0/0xee0 [ 501.552627][ C1] ? tcp_set_state+0xc0/0x580 [ 501.552631][ C1] __tcp_push_pending_frames+0x8f/0x3b0 [ 501.552633][ C1] inet_shutdown+0x248/0x360 [ 501.552636][ C1] ? vfs_write+0xbd0/0xbd0 [ 501.552639][ C1] __sys_shutdown+0xcf/0x170 [ 501.552642][ C1] __x64_sys_shutdown+0x52/0x90 [ 501.552644][ C1] ? lockdep_hardirqs_on+0x91/0x130 [ 501.552646][ C1] ? do_syscall_64+0xa6/0x530 [ 501.552649][ C1] do_syscall_64+0xff/0x530 [ 501.552651][ C1] ? exc_page_fault+0xee/0x100 [ 501.552653][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 501.552656][ C1] RIP: 0033:0x7f11b06c631b [ 501.552659][ C1] Code: 8b 15 e1 6a 0f 00 f7 d8 64 89 02 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 f3 0f 1e fa b8 30 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d ad 6a 0f 00 f7 d8 64 89 01 48 [ 501.552661][ C1] RSP: 002b:00007fffd8ee7568 EFLAGS: 00000206 ORIG_RAX: 0000000000000030 [ 501.552666][ C1] RAX: ffffffffffffffda RBX: 00005647a526b330 RCX: 00007f11b06c631b [ 501.552668][ C1] RDX: 0000000000000006 RSI: 0000000000000002 RDI: 0000000000000006 [ 501.552669][ C1] RBP: 00007fffd8ee75e0 R08: 0000000000000001 R09: 00005647a526d000 [ 501.552670][ C1] R10: 0000000000000000 R11: 0000000000000206 R12: 00007f11b0573b30 [ 501.552671][ C1] R13: ffffffffffffffff R14: 0000000000000000 R15: 0000000000000000 [ 501.552673][ C1] [ 501.552674][ C1] [ 501.577767][ C1] The buggy address belongs to the object at ff11000011763240 [ 501.577767][ C1] which belongs to the cache tw_sock_TCPv6 of size 296 [ 501.578620][ C1] The buggy address is located 128 bytes inside of [ 501.578620][ C1] allocated 296-byte region [ff11000011763240, ff11000011763368) [ 501.579290][ C1] [ 501.579427][ C1] The buggy address belongs to the physical page: [ 501.579807][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000011762ef0 pfn:0x11762 [ 501.580303][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 501.580638][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 501.580889][ C1] page_type: f5(slab) [ 501.581093][ C1] raw: 0080000000000240 ff11000005bf7b40 ff11000005e30e48 ff11000005e30e48 [ 501.581468][ C1] raw: ff11000011762ef0 0000000000130009 00000000f5000000 0000000000000000 [ 501.581863][ C1] head: 0080000000000240 ff11000005bf7b40 ff11000005e30e48 ff11000005e30e48 [ 501.582181][ C1] head: ff11000011762ef0 0000000000130009 00000000f5000000 0000000000000000 [ 501.582554][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 501.582959][ C1] head: ff11000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 501.583329][ C1] page dumped because: kasan: bad access detected [ 501.583606][ C1] [ 501.583695][ C1] Memory state around the buggy address: [ 501.583874][ C1] ff11000011763180: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 501.584191][ C1] ff11000011763200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 501.584505][ C1] >ff11000011763280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 501.584826][ C1] ^ [ 501.585041][ C1] ff11000011763300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 501.585354][ C1] ff11000011763380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 501.585665][ C1] ================================================================== [ 501.586016][ C1] Disabling lock debugging due to kernel taint