[ 26.954868][ T455] netdevsim netdevsim20713 eni20713np1: renamed from eth0 [ 27.120013][ T455] netdevsim netdevsim974 eni974np1: renamed from eth0 [ 27.436492][ T470] 8021q: adding VLAN 0 to HW filter on device eni20713np1 [ 27.570429][ T473] 8021q: adding VLAN 0 to HW filter on device eth0 [ 29.531929][ T485] iperf3 (485) used greatest stack depth: 23760 bytes left [ 29.672305][ C1] ================================================================== [ 29.672566][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 29.672824][ C1] Read of size 8 at addr ff1100000afd0580 by task ksoftirqd/1/23 [ 29.673036][ C1] [ 29.673114][ C1] CPU: 1 UID: 0 PID: 23 Comm: ksoftirqd/1 Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 29.673118][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 29.673120][ C1] Call Trace: [ 29.673128][ C1] [ 29.673130][ C1] dump_stack_lvl+0x6f/0xa0 [ 29.673136][ C1] print_address_description.constprop.0+0x56/0x2d0 [ 29.673140][ C1] print_report+0xfc/0x1fa [ 29.673142][ C1] ? __virt_addr_valid+0x102/0x440 [ 29.673145][ C1] ? __virt_addr_valid+0x1da/0x440 [ 29.673147][ C1] kasan_report+0x108/0x130 [ 29.673151][ C1] ? tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 29.673153][ C1] ? tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 29.673156][ C1] kasan_check_range+0x130/0x200 [ 29.673158][ C1] tcp_v6_send_response.isra.0+0xd27/0x1a10 [ 29.673162][ C1] ? __xfrm_policy_check2.constprop.0+0x720/0x720 [ 29.673165][ C1] ? tcp_timewait_state_process+0x9eb/0x1730 [ 29.673169][ C1] tcp_v6_send_reset+0x37e/0xdf0 [ 29.673172][ C1] tcp_v6_rcv+0x241f/0x2de0 [ 29.673176][ C1] ? tcp_v6_syn_recv_sock+0x1ab0/0x1ab0 [ 29.673178][ C1] ? ipv6_raw_deliver+0x323/0x890 [ 29.673180][ C1] ? ipv6_raw_deliver+0x32d/0x890 [ 29.673182][ C1] ip6_protocol_deliver_rcu+0x15a/0x1290 [ 29.673186][ C1] ? rcu_is_watching+0x16/0xd0 [ 29.673191][ C1] ip6_input+0x223/0x5f0 [ 29.673194][ C1] ip6_sublist_rcv_finish+0x9e/0x2a0 [ 29.673197][ C1] ip6_list_rcv_finish.constprop.0+0x5a6/0xc10 [ 29.673201][ C1] ? ip6_rcv_finish_core.isra.0+0x5d0/0x5d0 [ 29.673204][ C1] ipv6_list_rcv+0x306/0x4f0 [ 29.673206][ C1] ? ipv6_rcv+0x1b0/0x1b0 [ 29.673207][ C1] ? write_profile+0xf0/0xf0 [ 29.673211][ C1] __netif_receive_skb_list_core+0x4ac/0x9e0 [ 29.673215][ C1] ? __netif_receive_skb_core.constprop.0+0x2960/0x2960 [ 29.673217][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 29.673220][ C1] ? netif_receive_skb_list_internal+0x2f8/0xe20 [ 29.673222][ C1] ? napi_consume_skb+0x18b/0x280 [ 29.673225][ C1] ? lock_acquire+0x13c/0x160 [ 29.673228][ C1] netif_receive_skb_list_internal+0x5f8/0xe20 [ 29.673229][ C1] ? mark_usage+0x61/0x170 [ 29.673231][ C1] ? process_backlog+0x14c0/0x14c0 [ 29.673233][ C1] ? ipv6_gro_receive+0xb58/0x27e0 [ 29.673237][ C1] ? __gro_flush+0x292/0x4a0 [ 29.673241][ C1] napi_complete_done+0x1aa/0x8c0 [ 29.673243][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 29.673245][ C1] ? netif_receive_skb_list+0x50/0x50 [ 29.673247][ C1] ? nsim_start_peer_tx_queue.isra.0+0x11a/0x330 [netdevsim] [ 29.673254][ C1] nsim_poll+0x38c/0x570 [netdevsim] [ 29.673258][ C1] ? nsim_start_peer_tx_queue.isra.0+0x330/0x330 [netdevsim] [ 29.673261][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 29.673264][ C1] ? napi_skb_cache_put+0x311/0x660 [ 29.673266][ C1] __napi_poll+0xd4/0x3b0 [ 29.673268][ C1] net_rx_action+0x513/0xf50 [ 29.673271][ C1] ? __napi_poll+0x3b0/0x3b0 [ 29.673272][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 29.673280][ C1] ? __schedule+0xfa5/0x20e0 [ 29.673283][ C1] ? rcu_is_watching+0x16/0xd0 [ 29.673285][ C1] handle_softirqs+0x1d3/0x900 [ 29.673288][ C1] ? _local_bh_enable+0xc0/0xc0 [ 29.673290][ C1] ? rcu_is_watching+0x16/0xd0 [ 29.673292][ C1] run_ksoftirqd+0x39/0x60 [ 29.673294][ C1] smpboot_thread_fn+0x2fb/0x9b0 [ 29.673297][ C1] ? sort_range+0x20/0x20 [ 29.673299][ C1] kthread+0x367/0x460 [ 29.673302][ C1] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 29.673305][ C1] ? kthread_affine_preferred+0x4c0/0x4c0 [ 29.673307][ C1] ret_from_fork+0x474/0x6b0 [ 29.673311][ C1] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 29.673313][ C1] ? __switch_to+0x5a3/0xe00 [ 29.673316][ C1] ? kthread_affine_preferred+0x4c0/0x4c0 [ 29.673318][ C1] ret_from_fork_asm+0x11/0x20 [ 29.673322][ C1] [ 29.673323][ C1] [ 29.683835][ C1] The buggy address belongs to the object at ff1100000afd0500 [ 29.683835][ C1] which belongs to the cache tw_sock_TCPv6 of size 296 [ 29.684237][ C1] The buggy address is located 128 bytes inside of [ 29.684237][ C1] allocated 296-byte region [ff1100000afd0500, ff1100000afd0628) [ 29.684628][ C1] [ 29.684701][ C1] The buggy address belongs to the physical page: [ 29.684882][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000afd0358 pfn:0xafd0 [ 29.685181][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 29.685409][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 29.685598][ C1] page_type: f5(slab) [ 29.685712][ C1] raw: 0080000000000240 ff11000005df7b40 ff11000005e20e48 ff11000005e20e48 [ 29.685971][ C1] raw: ff1100000afd0358 0000000000130002 00000000f5000000 0000000000000000 [ 29.686238][ C1] head: 0080000000000240 ff11000005df7b40 ff11000005e20e48 ff11000005e20e48 [ 29.686497][ C1] head: ff1100000afd0358 0000000000130002 00000000f5000000 0000000000000000 [ 29.686755][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 29.687015][ C1] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 29.687281][ C1] page dumped because: kasan: bad access detected [ 29.687461][ C1] [ 29.687535][ C1] Memory state around the buggy address: [ 29.687681][ C1] ff1100000afd0480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 29.687896][ C1] ff1100000afd0500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 29.688106][ C1] >ff1100000afd0580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 29.688329][ C1] ^ [ 29.688439][ C1] ff1100000afd0600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 29.688652][ C1] ff1100000afd0680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 29.688863][ C1] ================================================================== [ 29.689085][ C1] Disabling lock debugging due to kernel taint