[ 747.313144][ C0] ================================================================== [ 747.313477][ C0] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe2c/0x2450 [ 747.313746][ C0] Read of size 8 at addr ff11000013b6d950 by task bench-lookups_i/9693 [ 747.314038][ C0] [ 747.314144][ C0] CPU: 0 UID: 0 PID: 9693 Comm: bench-lookups_i Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 747.314148][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 747.314150][ C0] Call Trace: [ 747.314152][ C0] [ 747.314154][ C0] dump_stack_lvl+0x6f/0xa0 [ 747.314160][ C0] print_address_description.constprop.0+0x56/0x2d0 [ 747.314165][ C0] print_report+0xfc/0x1fa [ 747.314167][ C0] ? __virt_addr_valid+0x102/0x440 [ 747.314171][ C0] ? __virt_addr_valid+0x1da/0x440 [ 747.314174][ C0] kasan_report+0x108/0x130 [ 747.314178][ C0] ? tcp_v6_send_response+0xe2c/0x2450 [ 747.314181][ C0] ? tcp_v6_send_response+0xe2c/0x2450 [ 747.314183][ C0] kasan_check_range+0x130/0x200 [ 747.314186][ C0] tcp_v6_send_response+0xe2c/0x2450 [ 747.314190][ C0] ? tcp_v6_send_synack+0xe10/0xe10 [ 747.314191][ C0] ? __lock_acquire+0x518/0xc20 [ 747.314196][ C0] ? __lock_release.isra.0+0x69/0x1a0 [ 747.314198][ C0] ? rcu_is_watching+0x16/0xd0 [ 747.314202][ C0] tcp_v6_timewait_ack+0x35b/0x7f0 [ 747.314205][ C0] ? tcp_v6_reqsk_send_ack+0xe00/0xe00 [ 747.314207][ C0] ? __local_bh_enable_ip+0xaa/0x150 [ 747.314210][ C0] ? tcp_ecn_openreq_child+0x14c0/0x14c0 [ 747.314214][ C0] ? ip6_pol_route+0x2e7/0xaa0 [ 747.314217][ C0] ? __asan_memcpy+0x3c/0x60 [ 747.314220][ C0] tcp_v6_rcv+0x217b/0x2dc0 [ 747.314223][ C0] ? tcp_v6_syn_recv_sock+0x1be0/0x1be0 [ 747.314225][ C0] ? ipv6_raw_deliver+0x35f/0x930 [ 747.314227][ C0] ? ipv6_raw_deliver+0x369/0x930 [ 747.314229][ C0] ? ret_from_fork_asm+0x11/0x20 [ 747.314232][ C0] ip6_protocol_deliver_rcu+0x15c/0x1480 [ 747.314237][ C0] ip6_input_finish+0x196/0x590 [ 747.314239][ C0] ip6_input+0x130/0x570 [ 747.314242][ C0] ? ip6_input_finish+0x590/0x590 [ 747.314244][ C0] ? ip6_rcv_core+0xe22/0x1be0 [ 747.314247][ C0] ipv6_rcv+0x3c1/0x5a0 [ 747.314249][ C0] ? ip6_rcv_core+0x1be0/0x1be0 [ 747.314251][ C0] ? rcu_is_watching+0x16/0xd0 [ 747.314253][ C0] ? __update_load_avg_cfs_rq+0x36c/0x10c0 [ 747.314256][ C0] ? mark_usage+0x61/0x170 [ 747.314258][ C0] ? __lock_acquire+0x518/0xc20 [ 747.314260][ C0] ? trace_raw_output_rcu_invoke_kfree_bulk_callback+0x57/0x130 [ 747.314263][ C0] ? process_backlog+0x3f1/0x14c0 [ 747.314267][ C0] __netif_receive_skb_one_core+0xfc/0x180 [ 747.314269][ C0] ? lock_acquire.part.0+0xd4/0x280 [ 747.314271][ C0] ? process_backlog+0x3f1/0x14c0 [ 747.314273][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 747.314276][ C0] ? rcu_is_watching+0x16/0xd0 [ 747.314279][ C0] process_backlog+0x431/0x14c0 [ 747.314282][ C0] __napi_poll+0xa7/0x3b0 [ 747.314285][ C0] net_rx_action+0x513/0xf50 [ 747.314287][ C0] ? __lock_acquire+0x518/0xc20 [ 747.314289][ C0] ? __napi_poll+0x3b0/0x3b0 [ 747.314293][ C0] ? ktime_get_update_offsets_now+0x2a8/0x490 [ 747.314297][ C0] ? mark_held_locks+0x40/0x70 [ 747.314299][ C0] handle_softirqs+0x1d3/0x900 [ 747.314302][ C0] ? _local_bh_enable+0xc0/0xc0 [ 747.314303][ C0] ? do_raw_spin_unlock+0x59/0x250 [ 747.314306][ C0] ? rcu_is_watching+0x16/0xd0 [ 747.314308][ C0] ? __dev_queue_xmit+0x964/0x1b80 [ 747.314310][ C0] do_softirq+0xac/0xe0 [ 747.314312][ C0] [ 747.314313][ C0] [ 747.314314][ C0] __local_bh_enable_ip+0x118/0x150 [ 747.314316][ C0] __dev_queue_xmit+0x979/0x1b80 [ 747.314320][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 747.314322][ C0] ? lock_acquire.part.0+0xd4/0x280 [ 747.314323][ C0] ? find_held_lock+0x2b/0x80 [ 747.314326][ C0] ? __lock_release.isra.0+0x69/0x1a0 [ 747.314327][ C0] ? rcu_is_watching+0x16/0xd0 [ 747.314329][ C0] ? mark_held_locks+0x40/0x70 [ 747.314331][ C0] ? __asan_memcpy+0x3c/0x60 [ 747.314333][ C0] ? neigh_hh_output+0x152/0x4c0 [ 747.314336][ C0] ip6_finish_output2+0x96f/0x12a0 [ 747.314338][ C0] ? ip6_dst_lookup+0x80/0x80 [ 747.314340][ C0] ? find_held_lock+0x2b/0x80 [ 747.314342][ C0] ? __lock_release.isra.0+0x69/0x1a0 [ 747.314344][ C0] ? ip6_mtu+0x15d/0x310 [ 747.314347][ C0] ip6_finish_output+0x646/0xda0 [ 747.314349][ C0] ip6_output+0x23f/0x7f0 [ 747.314351][ C0] ? ip6_finish_output+0xda0/0xda0 [ 747.314353][ C0] ? lock_acquire.part.0+0xd4/0x280 [ 747.314355][ C0] ? find_held_lock+0x2b/0x80 [ 747.314356][ C0] ? __lock_release.isra.0+0x69/0x1a0 [ 747.314359][ C0] ip6_xmit+0xc44/0x1ec0 [ 747.314361][ C0] ? mark_usage+0x61/0x170 [ 747.314363][ C0] ? __lock_acquire+0x518/0xc20 [ 747.314366][ C0] ? ip6_autoflowlabel+0x120/0x120 [ 747.314368][ C0] ? __lock_release.isra.0+0x69/0x1a0 [ 747.314370][ C0] ? mark_usage+0x61/0x170 [ 747.314371][ C0] ? __lock_acquire+0x518/0xc20 [ 747.314374][ C0] ? lock_acquire.part.0+0xd4/0x280 [ 747.314376][ C0] ? inet6_csk_xmit+0xfe/0x5f0 [ 747.314378][ C0] ? rcu_is_watching+0x16/0xd0 [ 747.314380][ C0] ? lock_acquire+0x13c/0x160 [ 747.314383][ C0] inet6_csk_xmit+0x2f6/0x5f0 [ 747.314385][ C0] __tcp_transmit_skb+0x1b6e/0x3c10 [ 747.314389][ C0] ? __tcp_select_window+0xf20/0xf20 [ 747.314391][ C0] ? find_held_lock+0x2b/0x80 [ 747.314392][ C0] ? __lock_release.isra.0+0x69/0x1a0 [ 747.314394][ C0] ? rcu_is_watching+0x16/0xd0 [ 747.314396][ C0] ? tcp_mtu_probe+0x19/0x1b60 [ 747.314399][ C0] tcp_write_xmit+0xff9/0x3710 [ 747.314402][ C0] ? __alloc_skb+0x3f0/0x5f0 [ 747.314406][ C0] ? tcp_retrans_try_collapse+0xee0/0xee0 [ 747.314408][ C0] ? tcp_set_state+0x101/0x580 [ 747.314412][ C0] __tcp_push_pending_frames+0x8f/0x3b0 [ 747.314414][ C0] __tcp_close+0x84e/0xe70 [ 747.314417][ C0] tcp_close+0x23/0xb0 [ 747.314419][ C0] inet_release+0x10a/0x240 [ 747.314421][ C0] ? fcntl_setlk+0xc80/0xc80 [ 747.314425][ C0] __sock_release+0xb8/0x280 [ 747.314428][ C0] sock_close+0x18/0x20 [ 747.314430][ C0] __fput+0x363/0xac0 [ 747.314433][ C0] fput_close_sync+0xde/0x1b0 [ 747.314435][ C0] ? alloc_file_clone+0xe0/0xe0 [ 747.314437][ C0] ? do_raw_spin_unlock+0x59/0x250 [ 747.314439][ C0] __x64_sys_close+0x8b/0xf0 [ 747.314442][ C0] do_syscall_64+0xff/0x530 [ 747.314445][ C0] ? exc_page_fault+0xee/0x100 [ 747.314447][ C0] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 747.314450][ C0] RIP: 0033:0x7f3c5d647312 [ 747.314453][ C0] Code: 08 0f 85 71 41 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 bf 01 00 [ 747.314455][ C0] RSP: 002b:00007ffc7831e758 EFLAGS: 00000246 ORIG_RAX: 0000000000000003 [ 747.314465][ C0] RAX: ffffffffffffffda RBX: 0000000000000058 RCX: 00007f3c5d647312 [ 747.314467][ C0] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000000000b [ 747.314468][ C0] RBP: 00007ffc7831e780 R08: 0000000000000000 R09: 0000000000000000 [ 747.314469][ C0] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000027cf2210 [ 747.314470][ C0] R13: 0000000000000200 R14: 0000000027cf2210 R15: ffffffff00000000 [ 747.314473][ C0] [ 747.314474][ C0] [ 747.338208][ C0] The buggy address belongs to the object at ff11000013b6d8e0 [ 747.338208][ C0] which belongs to the cache tw_sock_TCPv6 of size 296 [ 747.338737][ C0] The buggy address is located 112 bytes inside of [ 747.338737][ C0] allocated 296-byte region [ff11000013b6d8e0, ff11000013b6da08) [ 747.339322][ C0] [ 747.339409][ C0] The buggy address belongs to the physical page: [ 747.339686][ C0] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000013b6d590 pfn:0x13b6c [ 747.340106][ C0] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 747.340367][ C0] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 747.340654][ C0] page_type: f5(slab) [ 747.340791][ C0] raw: 0080000000000240 ff11000005ac7b40 ffd40000004e4510 ff11000005dfee48 [ 747.341169][ C0] raw: ff11000013b6d590 000000000013000d 00000000f5000000 0000000000000000 [ 747.341545][ C0] head: 0080000000000240 ff11000005ac7b40 ffd40000004e4510 ff11000005dfee48 [ 747.341925][ C0] head: ff11000013b6d590 000000000013000d 00000000f5000000 0000000000000000 [ 747.342301][ C0] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 747.342676][ C0] head: ff11000013b6d340 0000000000000000 00000000ffffffff 0000000000000000 [ 747.343046][ C0] page dumped because: kasan: bad access detected [ 747.343262][ C0] [ 747.343350][ C0] Memory state around the buggy address: [ 747.343583][ C0] ff11000013b6d800: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 747.343897][ C0] ff11000013b6d880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 747.344152][ C0] >ff11000013b6d900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 747.344469][ C0] ^ [ 747.344744][ C0] ff11000013b6d980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 747.345059][ C0] ff11000013b6da00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 747.345311][ C0] ================================================================== [ 747.345630][ C0] Disabling lock debugging due to kernel taint