Hay
Date
May 15, 2025, 10:38 a.m.

Environment
e850-96

[   20.432603] ==================================================================
[   20.442304] BUG: KASAN: slab-out-of-bounds in kmalloc_track_caller_oob_right+0x40c/0x488
[   20.450372] Write of size 1 at addr ffff000801eaa178 by task kunit_try_catch/187
[   20.457750] 
[   20.459236] CPU: 5 UID: 0 PID: 187 Comm: kunit_try_catch Tainted: G    B            N  6.15.0-rc6-next-20250515 #1 PREEMPT 
[   20.459292] Tainted: [B]=BAD_PAGE, [N]=TEST
[   20.459308] Hardware name: WinLink E850-96 board (DT)
[   20.459329] Call trace:
[   20.459343]  show_stack+0x20/0x38 (C)
[   20.459382]  dump_stack_lvl+0x8c/0xd0
[   20.459417]  print_report+0x118/0x608
[   20.459451]  kasan_report+0xdc/0x128
[   20.459481]  __asan_report_store1_noabort+0x20/0x30
[   20.459518]  kmalloc_track_caller_oob_right+0x40c/0x488
[   20.459551]  kunit_try_run_case+0x170/0x3f0
[   20.459583]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   20.459616]  kthread+0x328/0x630
[   20.459652]  ret_from_fork+0x10/0x20
[   20.459684] 
[   20.524415] Allocated by task 187:
[   20.527802]  kasan_save_stack+0x3c/0x68
[   20.531619]  kasan_save_track+0x20/0x40
[   20.535438]  kasan_save_alloc_info+0x40/0x58
[   20.539692]  __kasan_kmalloc+0xd4/0xd8
[   20.543425]  __kmalloc_node_track_caller_noprof+0x18c/0x4c0
[   20.548980]  kmalloc_track_caller_oob_right+0xa8/0x488
[   20.554101]  kunit_try_run_case+0x170/0x3f0
[   20.558268]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   20.563737]  kthread+0x328/0x630
[   20.566948]  ret_from_fork+0x10/0x20
[   20.570507] 
[   20.571985] The buggy address belongs to the object at ffff000801eaa100
[   20.571985]  which belongs to the cache kmalloc-128 of size 128
[   20.584487] The buggy address is located 0 bytes to the right of
[   20.584487]  allocated 120-byte region [ffff000801eaa100, ffff000801eaa178)
[   20.597416] 
[   20.598896] The buggy address belongs to the physical page:
[   20.604452] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x881eaa
[   20.612436] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   20.620075] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   20.627018] page_type: f5(slab)
[   20.630156] raw: 0bfffe0000000040 ffff000800002a00 dead000000000122 0000000000000000
[   20.637874] raw: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000
[   20.645601] head: 0bfffe0000000040 ffff000800002a00 dead000000000122 0000000000000000
[   20.653412] head: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000
[   20.661225] head: 0bfffe0000000001 fffffdffe007aa81 00000000ffffffff 00000000ffffffff
[   20.669037] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002
[   20.676843] page dumped because: kasan: bad access detected
[   20.682398] 
[   20.683873] Memory state around the buggy address:
[   20.688656]  ffff000801eaa000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   20.695856]  ffff000801eaa080: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   20.703061] >ffff000801eaa100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fc
[   20.710262]                                                                 ^
[   20.717384]  ffff000801eaa180: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   20.724590]  ffff000801eaa200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   20.731792] ==================================================================