[ 266.365538][ C1] ==================================================================
[ 266.365868][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe2c/0x2450
[ 266.366114][ C1] Read of size 8 at addr ff1100000d293108 by task bench-lookups_i/2182
[ 266.366358][ C1]
[ 266.366440][ C1] CPU: 1 UID: 0 PID: 2182 Comm: bench-lookups_i Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 266.366443][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 266.366445][ C1] Call Trace:
[ 266.366447][ C1]
[ 266.366448][ C1] dump_stack_lvl+0x6f/0xa0
[ 266.366454][ C1] print_address_description.constprop.0+0x56/0x2d0
[ 266.366459][ C1] print_report+0xfc/0x1fa
[ 266.366460][ C1] ? __virt_addr_valid+0x102/0x440
[ 266.366464][ C1] ? __virt_addr_valid+0x1da/0x440
[ 266.366466][ C1] kasan_report+0x108/0x130
[ 266.366470][ C1] ? tcp_v6_send_response+0xe2c/0x2450
[ 266.366471][ C1] ? tcp_v6_send_response+0xe2c/0x2450
[ 266.366474][ C1] kasan_check_range+0x130/0x200
[ 266.366476][ C1] tcp_v6_send_response+0xe2c/0x2450
[ 266.366477][ C1] ? _raw_spin_unlock_irqrestore+0x40/0x80
[ 266.366481][ C1] ? tcp_v6_send_synack+0xe10/0xe10
[ 266.366482][ C1] ? __lock_acquire+0x518/0xc20
[ 266.366486][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 266.366488][ C1] ? rcu_is_watching+0x16/0xd0
[ 266.366492][ C1] tcp_v6_timewait_ack+0x35b/0x7f0
[ 266.366494][ C1] ? tcp_v6_reqsk_send_ack+0xe00/0xe00
[ 266.366496][ C1] ? __local_bh_enable_ip+0xaa/0x150
[ 266.366499][ C1] ? tcp_ecn_openreq_child+0x14c0/0x14c0
[ 266.366502][ C1] ? ip6_pol_route+0x2e7/0xaa0
[ 266.366505][ C1] ? __asan_memcpy+0x3c/0x60
[ 266.366507][ C1] tcp_v6_rcv+0x217b/0x2dc0
[ 266.366510][ C1] ? tcp_v6_syn_recv_sock+0x1be0/0x1be0
[ 266.366512][ C1] ? ipv6_raw_deliver+0x35f/0x930
[ 266.366514][ C1] ? ipv6_raw_deliver+0x369/0x930
[ 266.366517][ C1] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 266.366521][ C1] ip6_input_finish+0x196/0x590
[ 266.366523][ C1] ip6_input+0x130/0x570
[ 266.366525][ C1] ? ip6_input_finish+0x590/0x590
[ 266.366527][ C1] ? ip6_rcv_core+0xe22/0x1be0
[ 266.366529][ C1] ipv6_rcv+0x3c1/0x5a0
[ 266.366531][ C1] ? ip6_rcv_core+0x1be0/0x1be0
[ 266.366533][ C1] ? rcu_is_watching+0x16/0xd0
[ 266.366534][ C1] ? __update_load_avg_cfs_rq+0x36c/0x10c0
[ 266.366537][ C1] ? mark_usage+0x61/0x170
[ 266.366539][ C1] ? __lock_acquire+0x518/0xc20
[ 266.366540][ C1] ? trace_raw_output_rcu_invoke_kfree_bulk_callback+0x57/0x130
[ 266.366543][ C1] ? process_backlog+0x3f1/0x14c0
[ 266.366547][ C1] __netif_receive_skb_one_core+0xfc/0x180
[ 266.366549][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 266.366550][ C1] ? process_backlog+0x3f1/0x14c0
[ 266.366552][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 266.366554][ C1] ? rcu_is_watching+0x16/0xd0
[ 266.366557][ C1] process_backlog+0x431/0x14c0
[ 266.366560][ C1] __napi_poll+0xa7/0x3b0
[ 266.366562][ C1] net_rx_action+0x513/0xf50
[ 266.366564][ C1] ? __lock_acquire+0x518/0xc20
[ 266.366565][ C1] ? __napi_poll+0x3b0/0x3b0
[ 266.366569][ C1] ? ktime_get_update_offsets_now+0x2a8/0x490
[ 266.366572][ C1] ? mark_held_locks+0x40/0x70
[ 266.366574][ C1] handle_softirqs+0x1d3/0x900
[ 266.366576][ C1] ? _local_bh_enable+0xc0/0xc0
[ 266.366578][ C1] ? do_raw_spin_unlock+0x59/0x250
[ 266.366580][ C1] ? rcu_is_watching+0x16/0xd0
[ 266.366581][ C1] ? __dev_queue_xmit+0x964/0x1b80
[ 266.366583][ C1] do_softirq+0xac/0xe0
[ 266.366585][ C1]
[ 266.366585][ C1]
[ 266.366586][ C1] __local_bh_enable_ip+0x118/0x150
[ 266.366588][ C1] __dev_queue_xmit+0x979/0x1b80
[ 266.366590][ C1] ? rcu_read_lock_any_held+0x3c/0x90
[ 266.366591][ C1] ? validate_chain+0x38b/0xc20
[ 266.366594][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 266.366596][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 266.366597][ C1] ? find_held_lock+0x2b/0x80
[ 266.366599][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 266.366600][ C1] ? rcu_is_watching+0x16/0xd0
[ 266.366602][ C1] ? mark_held_locks+0x40/0x70
[ 266.366603][ C1] ? __asan_memcpy+0x3c/0x60
[ 266.366605][ C1] ? neigh_hh_output+0x152/0x4c0
[ 266.366607][ C1] ip6_finish_output2+0x96f/0x12a0
[ 266.366610][ C1] ? ip6_dst_lookup+0x80/0x80
[ 266.366611][ C1] ? find_held_lock+0x2b/0x80
[ 266.366613][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 266.366614][ C1] ? ip6_mtu+0x15d/0x310
[ 266.366617][ C1] ip6_finish_output+0x646/0xda0
[ 266.366619][ C1] ip6_output+0x23f/0x7f0
[ 266.366621][ C1] ? ip6_finish_output+0xda0/0xda0
[ 266.366622][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 266.366624][ C1] ? find_held_lock+0x2b/0x80
[ 266.366625][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 266.366627][ C1] ip6_xmit+0xc44/0x1ec0
[ 266.366629][ C1] ? mark_usage+0x61/0x170
[ 266.366630][ C1] ? __lock_acquire+0x518/0xc20
[ 266.366633][ C1] ? ip6_autoflowlabel+0x120/0x120
[ 266.366634][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 266.366636][ C1] ? mark_usage+0x61/0x170
[ 266.366637][ C1] ? __lock_acquire+0x518/0xc20
[ 266.366639][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 266.366641][ C1] ? inet6_csk_xmit+0xfe/0x5f0
[ 266.366643][ C1] ? rcu_is_watching+0x16/0xd0
[ 266.366644][ C1] ? lock_acquire+0x13c/0x160
[ 266.366646][ C1] inet6_csk_xmit+0x2f6/0x5f0
[ 266.366649][ C1] __tcp_transmit_skb+0x1b6e/0x3c10
[ 266.366652][ C1] ? __tcp_select_window+0xf20/0xf20
[ 266.366653][ C1] ? find_held_lock+0x2b/0x80
[ 266.366654][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 266.366656][ C1] ? rcu_is_watching+0x16/0xd0
[ 266.366657][ C1] ? tcp_mtu_probe+0x19/0x1b60
[ 266.366660][ C1] tcp_write_xmit+0xff9/0x3710
[ 266.366663][ C1] ? __alloc_skb+0x3f0/0x5f0
[ 266.366666][ C1] ? tcp_retrans_try_collapse+0xee0/0xee0
[ 266.366667][ C1] ? tcp_set_state+0x101/0x580
[ 266.366671][ C1] __tcp_push_pending_frames+0x8f/0x3b0
[ 266.366673][ C1] __tcp_close+0x84e/0xe70
[ 266.366675][ C1] tcp_close+0x23/0xb0
[ 266.366677][ C1] inet_release+0x10a/0x240
[ 266.366679][ C1] ? fcntl_setlk+0xc80/0xc80
[ 266.366682][ C1] __sock_release+0xb8/0x280
[ 266.366685][ C1] sock_close+0x18/0x20
[ 266.366687][ C1] __fput+0x363/0xac0
[ 266.366690][ C1] fput_close_sync+0xde/0x1b0
[ 266.366691][ C1] ? alloc_file_clone+0xe0/0xe0
[ 266.366693][ C1] ? do_raw_spin_unlock+0x59/0x250
[ 266.366695][ C1] __x64_sys_close+0x8b/0xf0
[ 266.366697][ C1] do_syscall_64+0xff/0x530
[ 266.366700][ C1] ? irq_exit_rcu+0x1a/0x30
[ 266.366701][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 266.366704][ C1] RIP: 0033:0x7f5aff5fc312
[ 266.366707][ C1] Code: 08 0f 85 71 41 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 bf 01 00
[ 266.366709][ C1] RSP: 002b:00007ffe76820bb8 EFLAGS: 00000246 ORIG_RAX: 0000000000000003
[ 266.366712][ C1] RAX: ffffffffffffffda RBX: 000000000000004a RCX: 00007f5aff5fc312
[ 266.366714][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000000000b
[ 266.366715][ C1] RBP: 00007ffe76820be0 R08: 0000000000000000 R09: 0000000000000000
[ 266.366715][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 000000002ecc4210
[ 266.366716][ C1] R13: 0000000000000200 R14: 000000002ecc4210 R15: ffffffff00000000
[ 266.366719][ C1]
[ 266.366720][ C1]
[ 266.388127][ C1] The buggy address belongs to the object at ff1100000d293098
[ 266.388127][ C1] which belongs to the cache tw_sock_TCPv6 of size 296
[ 266.388696][ C1] The buggy address is located 112 bytes inside of
[ 266.388696][ C1] allocated 296-byte region [ff1100000d293098, ff1100000d2931c0)
[ 266.389194][ C1]
[ 266.389285][ C1] The buggy address belongs to the physical page:
[ 266.389544][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000d292d48 pfn:0xd292
[ 266.389934][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 266.390247][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 266.390470][ C1] page_type: f5(slab)
[ 266.390662][ C1] raw: 0080000000000240 ff11000005cc3b40 ff11000005ccce48 ff11000005ccce48
[ 266.390966][ C1] raw: ff1100000d292d48 0000000000130008 00000000f5000000 0000000000000000
[ 266.391332][ C1] head: 0080000000000240 ff11000005cc3b40 ff11000005ccce48 ff11000005ccce48
[ 266.391686][ C1] head: ff1100000d292d48 0000000000130008 00000000f5000000 0000000000000000
[ 266.392031][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 266.392377][ C1] head: ff1100000d293f40 0000000000000000 00000000ffffffff 0000000000000000
[ 266.392725][ C1] page dumped because: kasan: bad access detected
[ 266.392926][ C1]
[ 266.393064][ C1] Memory state around the buggy address:
[ 266.393220][ C1] ff1100000d293000: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 266.393520][ C1] ff1100000d293080: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 266.393807][ C1] >ff1100000d293100: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 266.394040][ C1] ^
[ 266.394217][ C1] ff1100000d293180: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 266.394509][ C1] ff1100000d293200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 266.394741][ C1] ==================================================================
[ 266.395040][ C1] Disabling lock debugging due to kernel taint