[ 1455.263644][T19412] ================================================================== [ 1455.263900][T19412] BUG: KASAN: slab-out-of-bounds in tcp_v6_send_response+0x1241/0x2000 [ 1455.264105][T19412] Read of size 8 at addr ff11000009764a50 by task packetdrill/19412 [ 1455.264296][T19412] [ 1455.264364][T19412] CPU: 2 UID: 0 PID: 19412 Comm: packetdrill Not tainted 7.2.0-virtme #1 PREEMPT(full) [ 1455.264367][T19412] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 1455.264369][T19412] Call Trace: [ 1455.264371][T19412] [ 1455.264372][T19412] dump_stack_lvl+0x6f/0xa0 [ 1455.264377][T19412] print_address_description.constprop.0+0x56/0x2d0 [ 1455.264381][T19412] print_report+0xfc/0x1fa [ 1455.264383][T19412] ? __virt_addr_valid+0x102/0x440 [ 1455.264385][T19412] ? __virt_addr_valid+0x1da/0x440 [ 1455.264387][T19412] kasan_report+0x108/0x130 [ 1455.264390][T19412] ? tcp_v6_send_response+0x1241/0x2000 [ 1455.264392][T19412] ? tcp_v6_send_response+0x1241/0x2000 [ 1455.264394][T19412] kasan_check_range+0x130/0x200 [ 1455.264396][T19412] tcp_v6_send_response+0x1241/0x2000 [ 1455.264397][T19412] ? __mod_timer+0x91/0xc60 [ 1455.264401][T19412] ? __xfrm_policy_check2.constprop.0+0x720/0x720 [ 1455.264403][T19412] ? __lock_acquire+0x518/0xc20 [ 1455.264407][T19412] ? __lock_release.isra.0+0x69/0x1a0 [ 1455.264408][T19412] ? rcu_is_watching+0x16/0xd0 [ 1455.264412][T19412] tcp_v6_rcv+0x220e/0x2e70 [ 1455.264415][T19412] ? tcp_v6_syn_recv_sock+0x1b00/0x1b00 [ 1455.264417][T19412] ? mark_usage+0x61/0x170 [ 1455.264420][T19412] ip6_protocol_deliver_rcu+0x15a/0x1290 [ 1455.264424][T19412] ? rcu_is_watching+0x16/0xd0 [ 1455.264426][T19412] ip6_input+0x223/0x5f0 [ 1455.264427][T19412] __netif_receive_skb_one_core+0xfc/0x180 [ 1455.264431][T19412] ? lock_acquire.part.0+0xd4/0x280 [ 1455.264433][T19412] ? netif_receive_skb_internal+0x81/0x330 [ 1455.264435][T19412] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 1455.264437][T19412] ? rcu_is_watching+0x16/0xd0 [ 1455.264438][T19412] ? ktime_get_with_offset+0x1ef/0x3a0 [ 1455.264441][T19412] netif_receive_skb_internal+0xb0/0x330 [ 1455.264443][T19412] ? __netif_receive_skb+0x150/0x150 [ 1455.264444][T19412] ? __might_fault+0x97/0x140 [ 1455.264448][T19412] ? _copy_from_iter+0x3c6/0x1810 [ 1455.264452][T19412] netif_receive_skb+0x56/0x340 [ 1455.264454][T19412] ? __local_bh_disable_ip+0x80/0x100 [ 1455.264456][T19412] tun_rx_batched.isra.0+0x3d5/0x790 [ 1455.264459][T19412] ? mark_usage+0x61/0x170 [ 1455.264461][T19412] ? __lock_acquire+0x518/0xc20 [ 1455.264463][T19412] ? tun_setup+0x2d0/0x2d0 [ 1455.264465][T19412] ? rcu_is_watching+0x16/0xd0 [ 1455.264466][T19412] ? lock_acquire+0x13c/0x160 [ 1455.264468][T19412] tun_get_user+0x1687/0x2620 [ 1455.264471][T19412] ? do_syscall_64+0xff/0x530 [ 1455.264474][T19412] ? entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 1455.264476][T19412] ? tun_build_skb+0x14f0/0x14f0 [ 1455.264478][T19412] ? mark_usage+0x61/0x170 [ 1455.264480][T19412] ? ref_tracker_free+0x501/0x870 [ 1455.264482][T19412] ? ref_tracker_dir_print+0x100/0x100 [ 1455.264485][T19412] ? find_held_lock+0x2b/0x80 [ 1455.264487][T19412] ? __lock_release.isra.0+0x69/0x1a0 [ 1455.264489][T19412] ? tun_get+0x106/0x240 [ 1455.264491][T19412] tun_chr_write_iter+0xb5/0x1a0 [ 1455.264493][T19412] do_iter_readv_writev+0x485/0xb70 [ 1455.264495][T19412] ? kasan_quarantine_put+0x13e/0x2b0 [ 1455.264496][T19412] ? fsnotify+0x3610/0x3610 [ 1455.264499][T19412] ? ref_tracker_free+0x501/0x870 [ 1455.264501][T19412] ? new_sync_write+0x760/0x760 [ 1455.264504][T19412] ? import_iovec+0x4e/0xa0 [ 1455.264506][T19412] vfs_writev+0x2a4/0xd80 [ 1455.264507][T19412] ? tun_get+0x106/0x240 [ 1455.264509][T19412] ? vfs_iocb_iter_write+0x940/0x940 [ 1455.264510][T19412] ? tun_recvmsg+0x290/0x290 [ 1455.264512][T19412] ? __lock_acquire+0x518/0xc20 [ 1455.264513][T19412] ? new_sync_read+0x192/0x750 [ 1455.264516][T19412] ? lock_acquire.part.0+0xd4/0x280 [ 1455.264517][T19412] ? find_held_lock+0x2b/0x80 [ 1455.264520][T19412] ? __fget_files+0x1e3/0x460 [ 1455.264523][T19412] ? do_writev+0x12f/0x320 [ 1455.264524][T19412] do_writev+0x12f/0x320 [ 1455.264526][T19412] ? vfs_writev+0xd80/0xd80 [ 1455.264527][T19412] ? fput+0x1f/0xa0 [ 1455.264529][T19412] ? rcu_is_watching+0x16/0xd0 [ 1455.264531][T19412] do_syscall_64+0xff/0x530 [ 1455.264532][T19412] ? irq_exit_rcu+0x1a/0x30 [ 1455.264534][T19412] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 1455.264536][T19412] RIP: 0033:0x4c42a2 [ 1455.264538][T19412] Code: 08 0f 85 31 ea ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 55 48 89 e5 [ 1455.264540][T19412] RSP: 002b:00007fff00dfba38 EFLAGS: 00000246 ORIG_RAX: 0000000000000014 [ 1455.264544][T19412] RAX: ffffffffffffffda RBX: 0000000000000010 RCX: 00000000004c42a2 [ 1455.264545][T19412] RDX: 0000000000000002 RSI: 00007fff00dfbac0 RDI: 0000000000000005 [ 1455.264546][T19412] RBP: 00007fff00dfba60 R08: 0000000000000000 R09: 0000000000000000 [ 1455.264547][T19412] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fff00dfc098 [ 1455.264548][T19412] R13: 00007fff00dfc120 R14: 0000000000000002 R15: 0000000000543540 [ 1455.264551][T19412] [ 1455.264551][T19412] [ 1455.275989][T19412] The buggy address belongs to the object at ff110000097649c8 [ 1455.275989][T19412] which belongs to the cache tw_sock_TCPv6 of size 288 [ 1455.276333][T19412] The buggy address is located 136 bytes inside of [ 1455.276333][T19412] allocated 288-byte region [ff110000097649c8, ff11000009764ae8) [ 1455.276675][T19412] [ 1455.276740][T19412] The buggy address belongs to the physical page: [ 1455.276899][T19412] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000009764348 pfn:0x9764 [ 1455.277168][T19412] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 1455.277410][T19412] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 1455.277622][T19412] page_type: f5(slab) [ 1455.277722][T19412] raw: 0080000000000240 ff11000005daf9c0 ff11000005b64d08 ff11000005b64d08 [ 1455.277999][T19412] raw: ff11000009764348 0000000000130001 00000000f5000000 0000000000000000 [ 1455.278278][T19412] head: 0080000000000240 ff11000005daf9c0 ff11000005b64d08 ff11000005b64d08 [ 1455.278551][T19412] head: ff11000009764348 0000000000130001 00000000f5000000 0000000000000000 [ 1455.278782][T19412] head: 0080000000000001 ffffffffffffff81 00000000ffffffff 00000000ffffffff [ 1455.279054][T19412] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 1455.279328][T19412] page dumped because: kasan: bad access detected [ 1455.279530][T19412] [ 1455.279595][T19412] Memory state around the buggy address: [ 1455.279764][T19412] ff11000009764900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 1455.279952][T19412] ff11000009764980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 1455.280183][T19412] >ff11000009764a00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 1455.280412][T19412] ^ [ 1455.280567][T19412] ff11000009764a80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 1455.280791][T19412] ff11000009764b00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 1455.281016][T19412] ================================================================== [ 1455.281290][T19412] Disabling lock debugging due to kernel taint