Hay
Date
Nov. 20, 2024, 6:35 a.m.

Environment
qemu-arm64
qemu-x86_64

[   70.887181] ==================================================================
[   70.887852] BUG: KFENCE: use-after-free read in test_krealloc+0x51c/0x830
[   70.887852] 
[   70.888573] Use-after-free read at 0x000000003a070cce (in kfence-#246):
[   70.889367]  test_krealloc+0x51c/0x830
[   70.889913]  test_krealloc+0x458/0x830
[   70.890506]  kunit_try_run_case+0x14c/0x3d0
[   70.891140]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   70.891846]  kthread+0x24c/0x2d0
[   70.892320]  ret_from_fork+0x10/0x20
[   70.892910] 
[   70.893262] kfence-#246: 0x000000003a070cce-0x00000000a4a80f0a, size=32, cache=kmalloc-32
[   70.893262] 
[   70.894285] allocated by task 326 on cpu 0 at 70.886088s (0.008186s ago):
[   70.895034]  test_alloc+0x298/0x620
[   70.895566]  test_krealloc+0xc0/0x830
[   70.896038]  kunit_try_run_case+0x14c/0x3d0
[   70.896669]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   70.897389]  kthread+0x24c/0x2d0
[   70.897849]  ret_from_fork+0x10/0x20
[   70.898404] 
[   70.898772] freed by task 326 on cpu 0 at 70.886550s (0.012210s ago):
[   70.899587]  krealloc_noprof+0x148/0x360
[   70.900166]  test_krealloc+0x1dc/0x830
[   70.900698]  kunit_try_run_case+0x14c/0x3d0
[   70.901303]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   70.901971]  kthread+0x24c/0x2d0
[   70.902503]  ret_from_fork+0x10/0x20
[   70.903004] 
[   70.903359] CPU: 0 UID: 0 PID: 326 Comm: kunit_try_catch Tainted: G    B            N 6.12.0-next-20241120 #1
[   70.904317] Tainted: [B]=BAD_PAGE, [N]=TEST
[   70.904889] Hardware name: linux,dummy-virt (DT)
[   70.905345] ==================================================================

[   68.057606] ==================================================================
[   68.058274] BUG: KFENCE: use-after-free read in test_krealloc+0x6fd/0xbe0
[   68.058274] 
[   68.059055] Use-after-free read at 0x(____ptrval____) (in kfence-#172):
[   68.059448]  test_krealloc+0x6fd/0xbe0
[   68.059978]  kunit_try_run_case+0x1b3/0x490
[   68.060445]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   68.061067]  kthread+0x257/0x310
[   68.061335]  ret_from_fork+0x41/0x80
[   68.061612]  ret_from_fork_asm+0x1a/0x30
[   68.062294] 
[   68.062548] kfence-#172: 0x(____ptrval____)-0x(____ptrval____), size=32, cache=kmalloc-32
[   68.062548] 
[   68.063707] allocated by task 344 on cpu 1 at 68.056529s (0.007174s ago):
[   68.064279]  test_alloc+0x35f/0x10d0
[   68.064588]  test_krealloc+0xae/0xbe0
[   68.065184]  kunit_try_run_case+0x1b3/0x490
[   68.065817]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   68.066255]  kthread+0x257/0x310
[   68.066904]  ret_from_fork+0x41/0x80
[   68.067477]  ret_from_fork_asm+0x1a/0x30
[   68.067881] 
[   68.068235] freed by task 344 on cpu 1 at 68.056932s (0.011299s ago):
[   68.069044]  krealloc_noprof+0x108/0x340
[   68.069644]  test_krealloc+0x227/0xbe0
[   68.070205]  kunit_try_run_case+0x1b3/0x490
[   68.070789]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   68.071344]  kthread+0x257/0x310
[   68.071875]  ret_from_fork+0x41/0x80
[   68.072283]  ret_from_fork_asm+0x1a/0x30
[   68.072802] 
[   68.073086] CPU: 1 UID: 0 PID: 344 Comm: kunit_try_catch Tainted: G    B            N 6.12.0-next-20241120 #1
[   68.074193] Tainted: [B]=BAD_PAGE, [N]=TEST
[   68.074818] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   68.075551] ==================================================================