Hay
Date
July 12, 2025, 11:09 a.m.

Environment
qemu-x86_64

[   12.970159] ==================================================================
[   12.970908] BUG: KFENCE: use-after-free write in memset_orig+0x72/0xb0
[   12.970908] 
[   12.971310] Use-after-free write at 0x(____ptrval____) (in kfence-#40):
[   12.971557]  memset_orig+0x72/0xb0
[   12.971880]  kmalloc_double_kzfree+0x19c/0x350
[   12.972051]  kunit_try_run_case+0x1a5/0x480
[   12.972259]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   12.972461]  kthread+0x337/0x6f0
[   12.972628]  ret_from_fork+0x116/0x1d0
[   12.973033]  ret_from_fork_asm+0x1a/0x30
[   12.973204] 
[   12.973299] kfence-#40: 0x(____ptrval____)-0x(____ptrval____), size=16, cache=kmalloc-16
[   12.973299] 
[   12.973670] allocated by task 210 on cpu 1 at 12.969119s (0.004549s ago):
[   12.974144]  kmalloc_double_kzfree+0xa9/0x350
[   12.974317]  kunit_try_run_case+0x1a5/0x480
[   12.974534]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   12.974855]  kthread+0x337/0x6f0
[   12.975029]  ret_from_fork+0x116/0x1d0
[   12.975204]  ret_from_fork_asm+0x1a/0x30
[   12.975344] 
[   12.975428] freed by task 210 on cpu 1 at 12.969196s (0.006230s ago):
[   12.975788]  kfree_sensitive+0x67/0x90
[   12.976082]  kmalloc_double_kzfree+0x12b/0x350
[   12.976237]  kunit_try_run_case+0x1a5/0x480
[   12.976460]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   12.976950]  kthread+0x337/0x6f0
[   12.977160]  ret_from_fork+0x116/0x1d0
[   12.977336]  ret_from_fork_asm+0x1a/0x30
[   12.977475] 
[   12.977571] CPU: 1 UID: 0 PID: 210 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc5 #1 PREEMPT(voluntary) 
[   12.978196] Tainted: [B]=BAD_PAGE, [N]=TEST
[   12.978406] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   12.978770] ==================================================================