[ 9.572907][ C1] ================================================================== [ 9.573203][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe2c/0x2450 [ 9.573444][ C1] Read of size 8 at addr ff1100000d868570 by task rst_ipv6/169 [ 9.573673][ C1] [ 9.573753][ C1] CPU: 1 UID: 0 PID: 169 Comm: rst_ipv6 Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 9.573756][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 9.573758][ C1] Call Trace: [ 9.573760][ C1] [ 9.573761][ C1] dump_stack_lvl+0x6f/0xa0 [ 9.573767][ C1] print_address_description.constprop.0+0x56/0x2d0 [ 9.573772][ C1] print_report+0xfc/0x1fa [ 9.573773][ C1] ? __virt_addr_valid+0x102/0x440 [ 9.573777][ C1] ? __virt_addr_valid+0x1da/0x440 [ 9.573779][ C1] kasan_report+0x108/0x130 [ 9.573783][ C1] ? tcp_v6_send_response+0xe2c/0x2450 [ 9.573784][ C1] ? tcp_v6_send_response+0xe2c/0x2450 [ 9.573787][ C1] kasan_check_range+0x130/0x200 [ 9.573789][ C1] tcp_v6_send_response+0xe2c/0x2450 [ 9.573792][ C1] ? tcp_v6_send_synack+0xe10/0xe10 [ 9.573793][ C1] ? lock_acquire.part.0+0x36/0x280 [ 9.573796][ C1] ? mark_usage+0x61/0x170 [ 9.573798][ C1] ? tcp_ao_established_key+0x1a5/0x260 [ 9.573801][ C1] ? tcp_ao_prepare_reset+0x213/0xe00 [ 9.573804][ C1] tcp_v6_send_reset+0x633/0x1330 [ 9.573806][ C1] ? trace_fib6_table_lookup+0xd1/0x1c0 [ 9.573809][ C1] ? tcp_v6_timewait_ack+0x7f0/0x7f0 [ 9.573810][ C1] ? reacquire_held_locks+0x1d0/0x240 [ 9.573812][ C1] ? __local_bh_enable_ip+0xaa/0x150 [ 9.573816][ C1] ? __asan_memcpy+0x3c/0x60 [ 9.573818][ C1] tcp_v6_rcv+0x2249/0x2dc0 [ 9.573821][ C1] ? tcp_v6_syn_recv_sock+0x1be0/0x1be0 [ 9.573822][ C1] ? ipv6_raw_deliver+0x35f/0x930 [ 9.573825][ C1] ? ipv6_raw_deliver+0x369/0x930 [ 9.573827][ C1] ? __lock_acquire+0x518/0xc20 [ 9.573829][ C1] ip6_protocol_deliver_rcu+0x15c/0x1480 [ 9.573833][ C1] ip6_input_finish+0x196/0x590 [ 9.573835][ C1] ip6_input+0x130/0x570 [ 9.573837][ C1] ? ip6_input_finish+0x590/0x590 [ 9.573839][ C1] ? ip6_rcv_core+0xe22/0x1be0 [ 9.573841][ C1] ipv6_rcv+0x3c1/0x5a0 [ 9.573843][ C1] ? ip6_rcv_core+0x1be0/0x1be0 [ 9.573845][ C1] ? rcu_lockdep_current_cpu_online+0x3f/0x1b0 [ 9.573849][ C1] ? mark_usage+0x61/0x170 [ 9.573850][ C1] ? __lock_acquire+0x518/0xc20 [ 9.573852][ C1] ? trace_raw_output_rcu_invoke_kfree_bulk_callback+0x57/0x130 [ 9.573854][ C1] ? process_backlog+0x3f1/0x14c0 [ 9.573858][ C1] __netif_receive_skb_one_core+0xfc/0x180 [ 9.573860][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 9.573861][ C1] ? process_backlog+0x3f1/0x14c0 [ 9.573863][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 9.573865][ C1] ? rcu_is_watching+0x16/0xd0 [ 9.573868][ C1] process_backlog+0x431/0x14c0 [ 9.573870][ C1] __napi_poll+0xa7/0x3b0 [ 9.573873][ C1] net_rx_action+0x513/0xf50 [ 9.573875][ C1] ? __napi_poll+0x3b0/0x3b0 [ 9.573877][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 9.573880][ C1] ? clockevents_program_event+0x307/0x7e0 [ 9.573883][ C1] ? rcu_is_watching+0x16/0xd0 [ 9.573885][ C1] ? rcu_is_watching+0x16/0xd0 [ 9.573886][ C1] ? mark_held_locks+0x40/0x70 [ 9.573888][ C1] handle_softirqs+0x1d3/0x900 [ 9.573890][ C1] ? _local_bh_enable+0xc0/0xc0 [ 9.573892][ C1] ? _local_bh_enable+0xc0/0xc0 [ 9.573893][ C1] ? __dev_queue_xmit+0x964/0x1b80 [ 9.573896][ C1] do_softirq+0xac/0xe0 [ 9.573897][ C1] [ 9.573898][ C1] [ 9.573898][ C1] __local_bh_enable_ip+0x118/0x150 [ 9.573900][ C1] __dev_queue_xmit+0x979/0x1b80 [ 9.573902][ C1] ? rcu_read_lock_any_held+0x3c/0x90 [ 9.573904][ C1] ? validate_chain+0x38b/0xc20 [ 9.573906][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 9.573908][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 9.573909][ C1] ? find_held_lock+0x2b/0x80 [ 9.573911][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 9.573913][ C1] ? rcu_is_watching+0x16/0xd0 [ 9.573914][ C1] ? mark_held_locks+0x40/0x70 [ 9.573916][ C1] ? __asan_memcpy+0x3c/0x60 [ 9.573917][ C1] ? neigh_hh_output+0x152/0x4c0 [ 9.573920][ C1] ip6_finish_output2+0x96f/0x12a0 [ 9.573922][ C1] ? ip6_dst_lookup+0x80/0x80 [ 9.573924][ C1] ? find_held_lock+0x2b/0x80 [ 9.573925][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 9.573927][ C1] ? ip6_mtu+0x15d/0x310 [ 9.573929][ C1] ip6_finish_output+0x646/0xda0 [ 9.573931][ C1] ip6_output+0x23f/0x7f0 [ 9.573933][ C1] ? ip6_finish_output+0xda0/0xda0 [ 9.573935][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 9.573936][ C1] ? find_held_lock+0x2b/0x80 [ 9.573938][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 9.573940][ C1] ip6_xmit+0xc44/0x1ec0 [ 9.573942][ C1] ? mark_usage+0x61/0x170 [ 9.573943][ C1] ? __lock_acquire+0x518/0xc20 [ 9.573946][ C1] ? ip6_autoflowlabel+0x120/0x120 [ 9.573947][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 9.573949][ C1] ? mark_usage+0x61/0x170 [ 9.573950][ C1] ? __lock_acquire+0x518/0xc20 [ 9.573952][ C1] ? lock_acquire.part.0+0xd4/0x280 [ 9.573954][ C1] ? inet6_csk_xmit+0xfe/0x5f0 [ 9.573956][ C1] ? rcu_is_watching+0x16/0xd0 [ 9.573958][ C1] ? lock_acquire+0x13c/0x160 [ 9.573960][ C1] inet6_csk_xmit+0x2f6/0x5f0 [ 9.573962][ C1] __tcp_transmit_skb+0x1b6e/0x3c10 [ 9.573966][ C1] ? __tcp_select_window+0xf20/0xf20 [ 9.573967][ C1] ? find_held_lock+0x2b/0x80 [ 9.573969][ C1] ? __lock_release.isra.0+0x69/0x1a0 [ 9.573970][ C1] ? rcu_is_watching+0x16/0xd0 [ 9.573972][ C1] ? tcp_mtu_probe+0x19/0x1b60 [ 9.573974][ C1] tcp_write_xmit+0xff9/0x3710 [ 9.573977][ C1] ? __asan_memset+0x27/0x50 [ 9.573978][ C1] ? __alloc_skb+0x3f0/0x5f0 [ 9.573981][ C1] ? tcp_retrans_try_collapse+0xee0/0xee0 [ 9.573983][ C1] ? skb_do_copy_data_nocache+0x133/0x260 [ 9.573985][ C1] ? trace_tcp_sendmsg_locked+0x1f0/0x1f0 [ 9.573987][ C1] __tcp_push_pending_frames+0x8f/0x3b0 [ 9.573989][ C1] tcp_sendmsg_locked+0xda0/0x3de0 [ 9.573993][ C1] ? tcp_sendmsg_fastopen+0x630/0x630 [ 9.573995][ C1] ? do_raw_spin_lock+0x131/0x280 [ 9.573997][ C1] ? find_held_lock+0x2b/0x80 [ 9.573998][ C1] ? mark_held_locks+0x40/0x70 [ 9.574000][ C1] tcp_sendmsg+0x2f/0x50 [ 9.574002][ C1] __sys_sendto+0x2aa/0x400 [ 9.574005][ C1] ? __ia32_sys_getpeername+0xd0/0xd0 [ 9.574009][ C1] ? __sys_getsockopt+0x12a/0x180 [ 9.574011][ C1] ? fput+0x1f/0xa0 [ 9.574013][ C1] ? fput+0x4c/0xa0 [ 9.574014][ C1] ? __sys_setsockopt+0x116/0x150 [ 9.574016][ C1] __x64_sys_sendto+0xe4/0x1f0 [ 9.574018][ C1] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 9.574021][ C1] ? lockdep_hardirqs_on+0x91/0x130 [ 9.574023][ C1] ? do_syscall_64+0xa6/0x530 [ 9.574025][ C1] do_syscall_64+0xff/0x530 [ 9.574027][ C1] ? exc_page_fault+0xee/0x100 [ 9.574028][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 9.574031][ C1] RIP: 0033:0x7f16c5f54312 [ 9.574034][ C1] Code: 08 0f 85 71 41 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 bf 01 00 [ 9.574035][ C1] RSP: 002b:00007f16c56d13c8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c [ 9.574039][ C1] RAX: ffffffffffffffda RBX: 000000000000000b RCX: 00007f16c5f54312 [ 9.574041][ C1] RDX: 0000000000000064 RSI: 00007f16c56d1440 RDI: 000000000000000b [ 9.574041][ C1] RBP: 00007f16c56d13f0 R08: 0000000000000000 R09: 0000000000000000 [ 9.574042][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000064 [ 9.574043][ C1] R13: 0000000000000000 R14: 0000000000000064 R15: 0000000000000002 [ 9.574045][ C1] [ 9.574046][ C1] [ 9.596728][ C1] The buggy address belongs to the object at ff1100000d868500 [ 9.596728][ C1] which belongs to the cache tw_sock_TCPv6 of size 296 [ 9.597187][ C1] The buggy address is located 112 bytes inside of [ 9.597187][ C1] allocated 296-byte region [ff1100000d868500, ff1100000d868628) [ 9.597650][ C1] [ 9.597780][ C1] The buggy address belongs to the physical page: [ 9.597970][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000d8681b0 pfn:0xd868 [ 9.598333][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 9.598622][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 9.598872][ C1] page_type: f5(slab) [ 9.598991][ C1] raw: 0080000000000240 ff11000005cdbb40 ff11000005ce4e48 ff11000005ce4e48 [ 9.599318][ C1] raw: ff1100000d8681b0 0000000000130001 00000000f5000000 0000000000000000 [ 9.599649][ C1] head: 0080000000000240 ff11000005cdbb40 ff11000005ce4e48 ff11000005ce4e48 [ 9.599974][ C1] head: ff1100000d8681b0 0000000000130001 00000000f5000000 0000000000000000 [ 9.600251][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 9.600578][ C1] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 9.600903][ C1] page dumped because: kasan: bad access detected [ 9.601144][ C1] [ 9.601220][ C1] Memory state around the buggy address: [ 9.601423][ C1] ff1100000d868400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 9.601648][ C1] ff1100000d868480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 9.601921][ C1] >ff1100000d868500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 9.602192][ C1] ^ [ 9.602463][ C1] ff1100000d868580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 9.602684][ C1] ff1100000d868600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 9.602956][ C1] ================================================================== [ 9.603235][ C1] Disabling lock debugging due to kernel taint