[ 202.996308][ T2937] ================================================================== [ 202.996574][ T2937] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0x1241/0x2000 [ 202.996776][ T2937] Read of size 8 at addr ff1100000fcd0570 by task packetdrill/2937 [ 202.996977][ T2937] [ 202.997045][ T2937] CPU: 3 UID: 0 PID: 2937 Comm: packetdrill Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 202.997048][ T2937] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 202.997050][ T2937] Call Trace: [ 202.997051][ T2937] [ 202.997052][ T2937] dump_stack_lvl+0x6f/0xa0 [ 202.997058][ T2937] print_address_description.constprop.0+0x56/0x2d0 [ 202.997062][ T2937] print_report+0xfc/0x1fa [ 202.997064][ T2937] ? __virt_addr_valid+0x102/0x440 [ 202.997067][ T2937] ? __virt_addr_valid+0x1da/0x440 [ 202.997069][ T2937] kasan_report+0x108/0x130 [ 202.997071][ T2937] ? tcp_v6_send_response+0x1241/0x2000 [ 202.997073][ T2937] ? tcp_v6_send_response+0x1241/0x2000 [ 202.997076][ T2937] kasan_check_range+0x130/0x200 [ 202.997078][ T2937] tcp_v6_send_response+0x1241/0x2000 [ 202.997079][ T2937] ? __mod_timer+0x91/0xc60 [ 202.997083][ T2937] ? __xfrm_policy_check2.constprop.0+0x720/0x720 [ 202.997085][ T2937] ? __lock_acquire+0x518/0xc20 [ 202.997089][ T2937] ? __lock_release.isra.0+0x69/0x1a0 [ 202.997090][ T2937] ? rcu_is_watching+0x16/0xd0 [ 202.997093][ T2937] tcp_v6_rcv+0x220e/0x2e70 [ 202.997097][ T2937] ? tcp_v6_syn_recv_sock+0x1b00/0x1b00 [ 202.997099][ T2937] ? mark_usage+0x61/0x170 [ 202.997102][ T2937] ip6_protocol_deliver_rcu+0x15a/0x1290 [ 202.997106][ T2937] ? rcu_is_watching+0x16/0xd0 [ 202.997108][ T2937] ip6_input+0x223/0x5f0 [ 202.997110][ T2937] __netif_receive_skb_one_core+0xfc/0x180 [ 202.997113][ T2937] ? lock_acquire.part.0+0xd4/0x280 [ 202.997115][ T2937] ? netif_receive_skb_internal+0x81/0x330 [ 202.997117][ T2937] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 202.997119][ T2937] ? rcu_is_watching+0x16/0xd0 [ 202.997120][ T2937] ? ktime_get_with_offset+0x1ef/0x3a0 [ 202.997123][ T2937] netif_receive_skb_internal+0xb0/0x330 [ 202.997125][ T2937] ? __netif_receive_skb+0x150/0x150 [ 202.997127][ T2937] ? __might_fault+0x97/0x140 [ 202.997130][ T2937] ? _copy_from_iter+0x3c6/0x1810 [ 202.997135][ T2937] netif_receive_skb+0x56/0x340 [ 202.997137][ T2937] ? __local_bh_disable_ip+0x80/0x100 [ 202.997140][ T2937] tun_rx_batched.isra.0+0x3d5/0x790 [ 202.997143][ T2937] ? mark_usage+0x61/0x170 [ 202.997144][ T2937] ? __lock_acquire+0x518/0xc20 [ 202.997146][ T2937] ? tun_setup+0x2d0/0x2d0 [ 202.997149][ T2937] ? rcu_is_watching+0x16/0xd0 [ 202.997150][ T2937] ? lock_acquire+0x13c/0x160 [ 202.997152][ T2937] tun_get_user+0x1687/0x2620 [ 202.997155][ T2937] ? do_syscall_64+0xff/0x530 [ 202.997158][ T2937] ? entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 202.997160][ T2937] ? tun_build_skb+0x14f0/0x14f0 [ 202.997162][ T2937] ? mark_usage+0x61/0x170 [ 202.997163][ T2937] ? ref_tracker_free+0x501/0x870 [ 202.997166][ T2937] ? ref_tracker_dir_print+0x100/0x100 [ 202.997169][ T2937] ? find_held_lock+0x2b/0x80 [ 202.997171][ T2937] ? __lock_release.isra.0+0x69/0x1a0 [ 202.997173][ T2937] ? tun_get+0x106/0x240 [ 202.997175][ T2937] tun_chr_write_iter+0xb5/0x1a0 [ 202.997177][ T2937] do_iter_readv_writev+0x485/0xb70 [ 202.997179][ T2937] ? kasan_quarantine_put+0x13e/0x2b0 [ 202.997180][ T2937] ? fsnotify+0x3610/0x3610 [ 202.997183][ T2937] ? ref_tracker_free+0x501/0x870 [ 202.997185][ T2937] ? new_sync_write+0x760/0x760 [ 202.997188][ T2937] ? import_iovec+0x4e/0xa0 [ 202.997190][ T2937] vfs_writev+0x2a4/0xd80 [ 202.997191][ T2937] ? tun_get+0x106/0x240 [ 202.997193][ T2937] ? vfs_iocb_iter_write+0x940/0x940 [ 202.997194][ T2937] ? tun_recvmsg+0x290/0x290 [ 202.997196][ T2937] ? __lock_acquire+0x518/0xc20 [ 202.997198][ T2937] ? new_sync_read+0x192/0x750 [ 202.997200][ T2937] ? lock_acquire.part.0+0xd4/0x280 [ 202.997202][ T2937] ? find_held_lock+0x2b/0x80 [ 202.997204][ T2937] ? __fget_files+0x1e3/0x460 [ 202.997207][ T2937] ? do_writev+0x12f/0x320 [ 202.997209][ T2937] do_writev+0x12f/0x320 [ 202.997210][ T2937] ? vfs_writev+0xd80/0xd80 [ 202.997211][ T2937] ? fput+0x1f/0xa0 [ 202.997213][ T2937] ? rcu_is_watching+0x16/0xd0 [ 202.997215][ T2937] do_syscall_64+0xff/0x530 [ 202.997217][ T2937] ? irq_exit_rcu+0x1a/0x30 [ 202.997219][ T2937] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 202.997220][ T2937] RIP: 0033:0x4c42a2 [ 202.997223][ T2937] Code: 08 0f 85 31 ea ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 48 89 e5 [ 202.997225][ T2937] RSP: 002b:00007ffe5fd659c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000014 [ 202.997230][ T2937] RAX: ffffffffffffffda RBX: 0000000000000010 RCX: 00000000004c42a2 [ 202.997231][ T2937] RDX: 0000000000000002 RSI: 00007ffe5fd65a50 RDI: 0000000000000005 [ 202.997232][ T2937] RBP: 00007ffe5fd659f0 R08: 0000000000000000 R09: 0000000000000000 [ 202.997233][ T2937] R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffe5fd66028 [ 202.997234][ T2937] R13: 00007ffe5fd660b0 R14: 0000000000000002 R15: 0000000000543540 [ 202.997236][ T2937] [ 202.997237][ T2937] [ 203.008960][ T2937] The buggy address belongs to the object at ff1100000fcd04e8 [ 203.008960][ T2937] which belongs to the cache tw_sock_TCPv6 of size 288 [ 203.009309][ T2937] The buggy address is located 136 bytes inside of [ 203.009309][ T2937] allocated 288-byte region [ff1100000fcd04e8, ff1100000fcd0608) [ 203.009659][ T2937] [ 203.009726][ T2937] The buggy address belongs to the physical page: [ 203.009895][ T2937] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff1100000fcd01a8 pfn:0xfcd0 [ 203.010160][ T2937] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 203.010361][ T2937] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 203.010531][ T2937] page_type: f5(slab) [ 203.010634][ T2937] raw: 0080000000000240 ff11000005b479c0 ff11000005b54d08 ff11000005b54d08 [ 203.010880][ T2937] raw: ff1100000fcd01a8 0000000000130001 00000000f5000000 0000000000000000 [ 203.011111][ T2937] head: 0080000000000240 ff11000005b479c0 ff11000005b54d08 ff11000005b54d08 [ 203.011349][ T2937] head: ff1100000fcd01a8 0000000000130001 00000000f5000000 0000000000000000 [ 203.011582][ T2937] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 203.011867][ T2937] head: ff11000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 203.012144][ T2937] page dumped because: kasan: bad access detected [ 203.012308][ T2937] [ 203.012374][ T2937] Memory state around the buggy address: [ 203.012543][ T2937] ff1100000fcd0400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 203.012776][ T2937] ff1100000fcd0480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 203.012972][ T2937] >ff1100000fcd0500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 203.013200][ T2937] ^ [ 203.013429][ T2937] ff1100000fcd0580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 203.013661][ T2937] ff1100000fcd0600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 203.013851][ T2937] ================================================================== [ 203.014085][ T2937] Disabling lock debugging due to kernel taint