Hay
Date
May 13, 2025, 12:07 p.m.

Environment
qemu-arm64

[   22.172540] ==================================================================
[   22.172612] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x51c/0x5d0
[   22.172687] Read of size 1 at addr ffff8000800fe7f8 by task kunit_try_catch/269
[   22.173521] 
[   22.173842] CPU: 1 UID: 0 PID: 269 Comm: kunit_try_catch Tainted: G    B            N  6.15.0-rc6-next-20250513 #1 PREEMPT 
[   22.173991] Tainted: [B]=BAD_PAGE, [N]=TEST
[   22.174028] Hardware name: linux,dummy-virt (DT)
[   22.174073] Call trace:
[   22.174416]  show_stack+0x20/0x38 (C)
[   22.174870]  dump_stack_lvl+0x8c/0xd0
[   22.174960]  print_report+0x310/0x608
[   22.175131]  kasan_report+0xdc/0x128
[   22.175333]  __asan_report_load1_noabort+0x20/0x30
[   22.175899]  vmalloc_oob+0x51c/0x5d0
[   22.175984]  kunit_try_run_case+0x170/0x3f0
[   22.176230]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.176598]  kthread+0x328/0x630
[   22.176672]  ret_from_fork+0x10/0x20
[   22.177260] 
[   22.177469] The buggy address belongs to the virtual mapping at
[   22.177469]  [ffff8000800fe000, ffff800080100000) created by:
[   22.177469]  vmalloc_oob+0x98/0x5d0
[   22.177573] 
[   22.177604] The buggy address belongs to the physical page:
[   22.177644] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1059db
[   22.177900] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   22.178906] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   22.179644] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   22.179728] page dumped because: kasan: bad access detected
[   22.180187] 
[   22.180250] Memory state around the buggy address:
[   22.180303]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.180362]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.180861] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   22.181227]                                                                 ^
[   22.181295]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.181351]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.181644] ==================================================================
[   22.167308] ==================================================================
[   22.167481] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x578/0x5d0
[   22.167573] Read of size 1 at addr ffff8000800fe7f3 by task kunit_try_catch/269
[   22.167635] 
[   22.167684] CPU: 1 UID: 0 PID: 269 Comm: kunit_try_catch Tainted: G    B            N  6.15.0-rc6-next-20250513 #1 PREEMPT 
[   22.167803] Tainted: [B]=BAD_PAGE, [N]=TEST
[   22.167847] Hardware name: linux,dummy-virt (DT)
[   22.167889] Call trace:
[   22.167921]  show_stack+0x20/0x38 (C)
[   22.168001]  dump_stack_lvl+0x8c/0xd0
[   22.168060]  print_report+0x310/0x608
[   22.168116]  kasan_report+0xdc/0x128
[   22.168468]  __asan_report_load1_noabort+0x20/0x30
[   22.168596]  vmalloc_oob+0x578/0x5d0
[   22.168798]  kunit_try_run_case+0x170/0x3f0
[   22.169407]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.169727]  kthread+0x328/0x630
[   22.169836]  ret_from_fork+0x10/0x20
[   22.169908] 
[   22.169954] The buggy address belongs to the virtual mapping at
[   22.169954]  [ffff8000800fe000, ffff800080100000) created by:
[   22.169954]  vmalloc_oob+0x98/0x5d0
[   22.170068] 
[   22.170100] The buggy address belongs to the physical page:
[   22.170152] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1059db
[   22.170217] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   22.170302] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   22.170373] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   22.170461] page dumped because: kasan: bad access detected
[   22.170533] 
[   22.170559] Memory state around the buggy address:
[   22.170609]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.170848]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.170937] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   22.171212]                                                              ^
[   22.171423]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.171501]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.171549] ==================================================================