Hay
Date
July 10, 2025, 11:10 p.m.

Environment
qemu-arm64

[   18.922951] ==================================================================
[   18.923027] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x578/0x5d0
[   18.923111] Read of size 1 at addr ffff8000800fe7f3 by task kunit_try_catch/269
[   18.923164] 
[   18.923204] CPU: 0 UID: 0 PID: 269 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc5 #1 PREEMPT 
[   18.923502] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.923550] Hardware name: linux,dummy-virt (DT)
[   18.923586] Call trace:
[   18.923613]  show_stack+0x20/0x38 (C)
[   18.923676]  dump_stack_lvl+0x8c/0xd0
[   18.923728]  print_report+0x310/0x608
[   18.923785]  kasan_report+0xdc/0x128
[   18.923833]  __asan_report_load1_noabort+0x20/0x30
[   18.923888]  vmalloc_oob+0x578/0x5d0
[   18.923933]  kunit_try_run_case+0x170/0x3f0
[   18.923985]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   18.924043]  kthread+0x328/0x630
[   18.924181]  ret_from_fork+0x10/0x20
[   18.924341] 
[   18.924458] The buggy address belongs to the virtual mapping at
[   18.924458]  [ffff8000800fe000, ffff800080100000) created by:
[   18.924458]  vmalloc_oob+0x98/0x5d0
[   18.924569] 
[   18.924595] The buggy address belongs to the physical page:
[   18.924631] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x106406
[   18.924804] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   18.924973] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   18.925099] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   18.925144] page dumped because: kasan: bad access detected
[   18.925179] 
[   18.925891] Memory state around the buggy address:
[   18.925937]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.925984]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.926030] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   18.926070]                                                              ^
[   18.926123]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   18.926170]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   18.926211] ==================================================================
[   18.926454] ==================================================================
[   18.926500] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x51c/0x5d0
[   18.926550] Read of size 1 at addr ffff8000800fe7f8 by task kunit_try_catch/269
[   18.926600] 
[   18.926634] CPU: 0 UID: 0 PID: 269 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc5 #1 PREEMPT 
[   18.926717] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.926744] Hardware name: linux,dummy-virt (DT)
[   18.926777] Call trace:
[   18.926800]  show_stack+0x20/0x38 (C)
[   18.926849]  dump_stack_lvl+0x8c/0xd0
[   18.926898]  print_report+0x310/0x608
[   18.926948]  kasan_report+0xdc/0x128
[   18.926996]  __asan_report_load1_noabort+0x20/0x30
[   18.927050]  vmalloc_oob+0x51c/0x5d0
[   18.927180]  kunit_try_run_case+0x170/0x3f0
[   18.927242]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   18.927298]  kthread+0x328/0x630
[   18.927343]  ret_from_fork+0x10/0x20
[   18.927392] 
[   18.927424] The buggy address belongs to the virtual mapping at
[   18.927424]  [ffff8000800fe000, ffff800080100000) created by:
[   18.927424]  vmalloc_oob+0x98/0x5d0
[   18.927769] 
[   18.927896] The buggy address belongs to the physical page:
[   18.928070] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x106406
[   18.928139] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   18.928203] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   18.928285] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   18.928374] page dumped because: kasan: bad access detected
[   18.928552] 
[   18.928595] Memory state around the buggy address:
[   18.928634]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.928784]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.928873] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   18.928986]                                                                 ^
[   18.929027]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   18.929071]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   18.929118] ==================================================================