[ 30.980191][ C1] ==================================================================
[ 30.980497][ C1] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0xe2c/0x2450
[ 30.980737][ C1] Read of size 8 at addr ff1100000fd3c570 by task rst_ipv6/319
[ 30.980963][ C1]
[ 30.981048][ C1] CPU: 1 UID: 0 PID: 319 Comm: rst_ipv6 Not tainted 7.2.0-virtme #1 PREEMPT(full)
[ 30.981051][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 30.981053][ C1] Call Trace:
[ 30.981054][ C1]
[ 30.981056][ C1] dump_stack_lvl+0x6f/0xa0
[ 30.981061][ C1] print_address_description.constprop.0+0x56/0x2d0
[ 30.981065][ C1] print_report+0xfc/0x1fa
[ 30.981067][ C1] ? __virt_addr_valid+0x102/0x440
[ 30.981071][ C1] ? __virt_addr_valid+0x1da/0x440
[ 30.981073][ C1] kasan_report+0x108/0x130
[ 30.981077][ C1] ? tcp_v6_send_response+0xe2c/0x2450
[ 30.981078][ C1] ? tcp_v6_send_response+0xe2c/0x2450
[ 30.981081][ C1] kasan_check_range+0x130/0x200
[ 30.981083][ C1] tcp_v6_send_response+0xe2c/0x2450
[ 30.981086][ C1] ? tcp_v6_send_synack+0xe10/0xe10
[ 30.981087][ C1] ? mark_usage+0x61/0x170
[ 30.981091][ C1] ? tcp_ao_established_key+0x1a5/0x260
[ 30.981094][ C1] ? tcp_ao_prepare_reset+0x213/0xe00
[ 30.981096][ C1] tcp_v6_send_reset+0x633/0x1330
[ 30.981099][ C1] ? trace_fib6_table_lookup+0xd1/0x1c0
[ 30.981101][ C1] ? tcp_v6_timewait_ack+0x7f0/0x7f0
[ 30.981103][ C1] ? reacquire_held_locks+0x1d0/0x240
[ 30.981105][ C1] ? __local_bh_enable_ip+0xaa/0x150
[ 30.981108][ C1] ? __asan_memcpy+0x3c/0x60
[ 30.981110][ C1] tcp_v6_rcv+0x2249/0x2dc0
[ 30.981113][ C1] ? tcp_v6_syn_recv_sock+0x1be0/0x1be0
[ 30.981115][ C1] ? ipv6_raw_deliver+0x35f/0x930
[ 30.981118][ C1] ? ipv6_raw_deliver+0x369/0x930
[ 30.981120][ C1] ? update_cfs_rq_load_avg+0x4b/0x660
[ 30.981123][ C1] ip6_protocol_deliver_rcu+0x15c/0x1480
[ 30.981127][ C1] ip6_input_finish+0x196/0x590
[ 30.981129][ C1] ip6_input+0x130/0x570
[ 30.981131][ C1] ? ip6_input_finish+0x590/0x590
[ 30.981133][ C1] ? ip6_rcv_core+0xe22/0x1be0
[ 30.981135][ C1] ipv6_rcv+0x3c1/0x5a0
[ 30.981137][ C1] ? ip6_rcv_core+0x1be0/0x1be0
[ 30.981139][ C1] ? mark_usage+0x61/0x170
[ 30.981141][ C1] ? __lock_acquire+0x518/0xc20
[ 30.981143][ C1] ? process_backlog+0x3f1/0x14c0
[ 30.981146][ C1] __netif_receive_skb_one_core+0xfc/0x180
[ 30.981149][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 30.981150][ C1] ? process_backlog+0x3f1/0x14c0
[ 30.981152][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 30.981154][ C1] ? rcu_is_watching+0x16/0xd0
[ 30.981158][ C1] process_backlog+0x431/0x14c0
[ 30.981161][ C1] __napi_poll+0xa7/0x3b0
[ 30.981163][ C1] net_rx_action+0x513/0xf50
[ 30.981166][ C1] ? __napi_poll+0x3b0/0x3b0
[ 30.981168][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 30.981171][ C1] ? clockevents_program_event+0x307/0x7e0
[ 30.981174][ C1] ? mark_held_locks+0x40/0x70
[ 30.981175][ C1] ? rcu_is_watching+0x16/0xd0
[ 30.981177][ C1] ? mark_held_locks+0x40/0x70
[ 30.981179][ C1] handle_softirqs+0x1d3/0x900
[ 30.981181][ C1] ? _local_bh_enable+0xc0/0xc0
[ 30.981182][ C1] ? _local_bh_enable+0xc0/0xc0
[ 30.981184][ C1] ? __dev_queue_xmit+0x964/0x1b80
[ 30.981186][ C1] do_softirq+0xac/0xe0
[ 30.981187][ C1]
[ 30.981188][ C1]
[ 30.981189][ C1] __local_bh_enable_ip+0x118/0x150
[ 30.981191][ C1] __dev_queue_xmit+0x979/0x1b80
[ 30.981193][ C1] ? rcu_read_lock_any_held+0x3c/0x90
[ 30.981194][ C1] ? validate_chain+0x38b/0xc20
[ 30.981197][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 30.981199][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 30.981200][ C1] ? find_held_lock+0x2b/0x80
[ 30.981202][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 30.981203][ C1] ? rcu_is_watching+0x16/0xd0
[ 30.981205][ C1] ? mark_held_locks+0x40/0x70
[ 30.981206][ C1] ? __asan_memcpy+0x3c/0x60
[ 30.981208][ C1] ? neigh_hh_output+0x152/0x4c0
[ 30.981210][ C1] ip6_finish_output2+0x96f/0x12a0
[ 30.981213][ C1] ? ip6_dst_lookup+0x80/0x80
[ 30.981214][ C1] ? find_held_lock+0x2b/0x80
[ 30.981216][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 30.981218][ C1] ? ip6_mtu+0x15d/0x310
[ 30.981220][ C1] ip6_finish_output+0x646/0xda0
[ 30.981222][ C1] ip6_output+0x23f/0x7f0
[ 30.981224][ C1] ? ip6_finish_output+0xda0/0xda0
[ 30.981226][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 30.981227][ C1] ? find_held_lock+0x2b/0x80
[ 30.981229][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 30.981231][ C1] ip6_xmit+0xc44/0x1ec0
[ 30.981232][ C1] ? mark_usage+0x61/0x170
[ 30.981234][ C1] ? __lock_acquire+0x518/0xc20
[ 30.981236][ C1] ? ip6_autoflowlabel+0x120/0x120
[ 30.981238][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 30.981239][ C1] ? mark_usage+0x61/0x170
[ 30.981241][ C1] ? __lock_acquire+0x518/0xc20
[ 30.981243][ C1] ? lock_acquire.part.0+0xd4/0x280
[ 30.981244][ C1] ? inet6_csk_xmit+0xfe/0x5f0
[ 30.981246][ C1] ? rcu_is_watching+0x16/0xd0
[ 30.981248][ C1] ? lock_acquire+0x13c/0x160
[ 30.981250][ C1] inet6_csk_xmit+0x2f6/0x5f0
[ 30.981252][ C1] __tcp_transmit_skb+0x1b6e/0x3c10
[ 30.981257][ C1] ? __tcp_select_window+0xf20/0xf20
[ 30.981258][ C1] ? find_held_lock+0x2b/0x80
[ 30.981260][ C1] ? __lock_release.isra.0+0x69/0x1a0
[ 30.981261][ C1] ? rcu_is_watching+0x16/0xd0
[ 30.981262][ C1] ? tcp_mtu_probe+0x19/0x1b60
[ 30.981265][ C1] tcp_write_xmit+0xff9/0x3710
[ 30.981268][ C1] ? __asan_memset+0x27/0x50
[ 30.981269][ C1] ? __alloc_skb+0x3f0/0x5f0
[ 30.981272][ C1] ? tcp_retrans_try_collapse+0xee0/0xee0
[ 30.981274][ C1] ? skb_do_copy_data_nocache+0x133/0x260
[ 30.981276][ C1] ? trace_tcp_sendmsg_locked+0x1f0/0x1f0
[ 30.981278][ C1] __tcp_push_pending_frames+0x8f/0x3b0
[ 30.981280][ C1] tcp_sendmsg_locked+0xda0/0x3de0
[ 30.981284][ C1] ? tcp_sendmsg_fastopen+0x630/0x630
[ 30.981286][ C1] ? do_raw_spin_lock+0x131/0x280
[ 30.981287][ C1] ? find_held_lock+0x2b/0x80
[ 30.981289][ C1] ? mark_held_locks+0x40/0x70
[ 30.981291][ C1] tcp_sendmsg+0x2f/0x50
[ 30.981293][ C1] __sys_sendto+0x2aa/0x400
[ 30.981296][ C1] ? __ia32_sys_getpeername+0xd0/0xd0
[ 30.981300][ C1] ? __sys_getsockopt+0x12a/0x180
[ 30.981302][ C1] ? fput+0x1f/0xa0
[ 30.981304][ C1] ? fput+0x4c/0xa0
[ 30.981305][ C1] ? __sys_setsockopt+0x116/0x150
[ 30.981307][ C1] __x64_sys_sendto+0xe4/0x1f0
[ 30.981309][ C1] ? trace_irq_enable.constprop.0+0x9b/0x160
[ 30.981312][ C1] ? lockdep_hardirqs_on+0x91/0x130
[ 30.981314][ C1] ? do_syscall_64+0xa6/0x530
[ 30.981316][ C1] do_syscall_64+0xff/0x530
[ 30.981318][ C1] ? exc_page_fault+0xee/0x100
[ 30.981320][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 30.981322][ C1] RIP: 0033:0x7f12da982312
[ 30.981325][ C1] Code: 08 0f 85 71 41 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 bf 01 00
[ 30.981327][ C1] RSP: 002b:00007f12da0ff3c8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
[ 30.981331][ C1] RAX: ffffffffffffffda RBX: 0000000000000009 RCX: 00007f12da982312
[ 30.981332][ C1] RDX: 0000000000000064 RSI: 00007f12da0ff440 RDI: 0000000000000009
[ 30.981333][ C1] RBP: 00007f12da0ff3f0 R08: 0000000000000000 R09: 0000000000000000
[ 30.981334][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000064
[ 30.981335][ C1] R13: 0000000000000000 R14: 0000000000000064 R15: 0000000000000002
[ 30.981337][ C1]
[ 30.981338][ C1]
[ 31.003135][ C1] The buggy address belongs to the object at ff1100000fd3c500
[ 31.003135][ C1] which belongs to the cache tw_sock_TCPv6 of size 296
[ 31.003593][ C1] The buggy address is located 112 bytes inside of
[ 31.003593][ C1] allocated 296-byte region [ff1100000fd3c500, ff1100000fd3c628)
[ 31.004109][ C1]
[ 31.004187][ C1] The buggy address belongs to the physical page:
[ 31.004373][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000fd3c1b0 pfn:0xfd3c
[ 31.004739][ C1] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 31.005025][ C1] flags: 0x80000000000240(workingset|head|node=0|zone=1)
[ 31.005275][ C1] page_type: f5(slab)
[ 31.005394][ C1] raw: 0080000000000240 ff11000005b01b40 ff11000005bb8e48 ff11000005bb8e48
[ 31.005730][ C1] raw: ff1100000fd3c1b0 0000000000130001 00000000f5000000 0000000000000000
[ 31.006054][ C1] head: 0080000000000240 ff11000005b01b40 ff11000005bb8e48 ff11000005bb8e48
[ 31.006383][ C1] head: ff1100000fd3c1b0 0000000000130001 00000000f5000000 0000000000000000
[ 31.006715][ C1] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff
[ 31.007039][ C1] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
[ 31.007308][ C1] page dumped because: kasan: bad access detected
[ 31.007552][ C1]
[ 31.007628][ C1] Memory state around the buggy address:
[ 31.007833][ C1] ff1100000fd3c400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 31.008109][ C1] ff1100000fd3c480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 31.008328][ C1] >ff1100000fd3c500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 31.008602][ C1] ^
[ 31.008880][ C1] ff1100000fd3c580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 31.009153][ C1] ff1100000fd3c600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 31.009374][ C1] ==================================================================
[ 31.009658][ C1] Disabling lock debugging due to kernel taint