Date
May 15, 2025, 10:38 a.m.
Environment | |
---|---|
e850-96 |
[ 27.394420] ================================================================== [ 27.404090] BUG: KASAN: slab-out-of-bounds in kmalloc_oob_memset_2+0x150/0x2f8 [ 27.411292] Write of size 2 at addr ffff000801f1c277 by task kunit_try_catch/217 [ 27.418670] [ 27.420153] CPU: 7 UID: 0 PID: 217 Comm: kunit_try_catch Tainted: G B N 6.15.0-rc6-next-20250515 #1 PREEMPT [ 27.420207] Tainted: [B]=BAD_PAGE, [N]=TEST [ 27.420221] Hardware name: WinLink E850-96 board (DT) [ 27.420241] Call trace: [ 27.420255] show_stack+0x20/0x38 (C) [ 27.420290] dump_stack_lvl+0x8c/0xd0 [ 27.420321] print_report+0x118/0x608 [ 27.420356] kasan_report+0xdc/0x128 [ 27.420387] kasan_check_range+0x100/0x1a8 [ 27.420419] __asan_memset+0x34/0x78 [ 27.420450] kmalloc_oob_memset_2+0x150/0x2f8 [ 27.420480] kunit_try_run_case+0x170/0x3f0 [ 27.420510] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 27.420545] kthread+0x328/0x630 [ 27.420581] ret_from_fork+0x10/0x20 [ 27.420613] [ 27.487245] Allocated by task 217: [ 27.490633] kasan_save_stack+0x3c/0x68 [ 27.494449] kasan_save_track+0x20/0x40 [ 27.498268] kasan_save_alloc_info+0x40/0x58 [ 27.502521] __kasan_kmalloc+0xd4/0xd8 [ 27.506254] __kmalloc_cache_noprof+0x15c/0x3c0 [ 27.510768] kmalloc_oob_memset_2+0xb0/0x2f8 [ 27.515021] kunit_try_run_case+0x170/0x3f0 [ 27.519188] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 27.524657] kthread+0x328/0x630 [ 27.527868] ret_from_fork+0x10/0x20 [ 27.531427] [ 27.532905] The buggy address belongs to the object at ffff000801f1c200 [ 27.532905] which belongs to the cache kmalloc-128 of size 128 [ 27.545405] The buggy address is located 119 bytes inside of [ 27.545405] allocated 120-byte region [ffff000801f1c200, ffff000801f1c278) [ 27.557989] [ 27.559469] The buggy address belongs to the physical page: [ 27.565024] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x881f1c [ 27.573009] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 27.580648] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 27.587592] page_type: f5(slab) [ 27.590729] raw: 0bfffe0000000040 ffff000800002a00 dead000000000122 0000000000000000 [ 27.598447] raw: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000 [ 27.606173] head: 0bfffe0000000040 ffff000800002a00 dead000000000122 0000000000000000 [ 27.613985] head: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000 [ 27.621798] head: 0bfffe0000000001 fffffdffe007c701 00000000ffffffff 00000000ffffffff [ 27.629610] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002 [ 27.637417] page dumped because: kasan: bad access detected [ 27.642971] [ 27.644446] Memory state around the buggy address: [ 27.649229] ffff000801f1c100: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 27.656429] ffff000801f1c180: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 27.663636] >ffff000801f1c200: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fc [ 27.670835] ^ [ 27.677956] ffff000801f1c280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 27.685161] ffff000801f1c300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 27.692364] ==================================================================