Hay
Date
July 18, 2025, 11:11 p.m.

Environment
qemu-arm64

[   15.368423] ==================================================================
[   15.368803] BUG: KFENCE: use-after-free read in kmalloc_uaf_16+0x1fc/0x438
[   15.368803] 
[   15.369209] Use-after-free read at 0x00000000447f8fa9 (in kfence-#54):
[   15.369949]  kmalloc_uaf_16+0x1fc/0x438
[   15.369994]  kunit_try_run_case+0x170/0x3f0
[   15.370035]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   15.370078]  kthread+0x328/0x630
[   15.370122]  ret_from_fork+0x10/0x20
[   15.370164] 
[   15.370353] kfence-#54: 0x00000000447f8fa9-0x00000000dcaff8c4, size=16, cache=kmalloc-16
[   15.370353] 
[   15.370611] allocated by task 168 on cpu 1 at 15.366922s (0.003618s ago):
[   15.371065]  kmalloc_uaf_16+0x140/0x438
[   15.371135]  kunit_try_run_case+0x170/0x3f0
[   15.371184]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   15.371226]  kthread+0x328/0x630
[   15.371260]  ret_from_fork+0x10/0x20
[   15.371637] 
[   15.372405] freed by task 168 on cpu 1 at 15.366990s (0.004702s ago):
[   15.373405]  kmalloc_uaf_16+0x190/0x438
[   15.373471]  kunit_try_run_case+0x170/0x3f0
[   15.373529]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   15.373602]  kthread+0x328/0x630
[   15.373669]  ret_from_fork+0x10/0x20
[   15.374031] 
[   15.374205] CPU: 1 UID: 0 PID: 168 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc6 #1 PREEMPT 
[   15.374295] Tainted: [B]=BAD_PAGE, [N]=TEST
[   15.374322] Hardware name: linux,dummy-virt (DT)
[   15.374888] ==================================================================