Date
May 15, 2025, 10:38 a.m.
Environment | |
---|---|
e850-96 |
[ 24.210139] ================================================================== [ 24.219507] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x60c/0x678 [ 24.227054] Write of size 1 at addr ffff0008067a20eb by task kunit_try_catch/205 [ 24.234429] [ 24.235916] CPU: 7 UID: 0 PID: 205 Comm: kunit_try_catch Tainted: G B N 6.15.0-rc6-next-20250515 #1 PREEMPT [ 24.235972] Tainted: [B]=BAD_PAGE, [N]=TEST [ 24.235988] Hardware name: WinLink E850-96 board (DT) [ 24.236008] Call trace: [ 24.236020] show_stack+0x20/0x38 (C) [ 24.236057] dump_stack_lvl+0x8c/0xd0 [ 24.236088] print_report+0x118/0x608 [ 24.236119] kasan_report+0xdc/0x128 [ 24.236148] __asan_report_store1_noabort+0x20/0x30 [ 24.236185] krealloc_more_oob_helper+0x60c/0x678 [ 24.236215] krealloc_large_more_oob+0x20/0x38 [ 24.236243] kunit_try_run_case+0x170/0x3f0 [ 24.236278] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 24.236312] kthread+0x328/0x630 [ 24.236346] ret_from_fork+0x10/0x20 [ 24.236381] [ 24.305004] The buggy address belongs to the physical page: [ 24.310559] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8867a0 [ 24.318543] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 24.326184] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 24.333126] page_type: f8(unknown) [ 24.336524] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 24.344242] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 24.351968] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 24.359780] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 24.367593] head: 0bfffe0000000002 fffffdffe019e801 00000000ffffffff 00000000ffffffff [ 24.375405] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 24.383212] page dumped because: kasan: bad access detected [ 24.388767] [ 24.390241] Memory state around the buggy address: [ 24.395024] ffff0008067a1f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 24.402224] ffff0008067a2000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 24.409429] >ffff0008067a2080: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fe fe [ 24.416630] ^ [ 24.423231] ffff0008067a2100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 24.430436] ffff0008067a2180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 24.437638] ================================================================== [ 22.046304] ================================================================== [ 22.055385] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x60c/0x678 [ 22.062935] Write of size 1 at addr ffff0008034c88eb by task kunit_try_catch/201 [ 22.070313] [ 22.071799] CPU: 7 UID: 0 PID: 201 Comm: kunit_try_catch Tainted: G B N 6.15.0-rc6-next-20250515 #1 PREEMPT [ 22.071857] Tainted: [B]=BAD_PAGE, [N]=TEST [ 22.071874] Hardware name: WinLink E850-96 board (DT) [ 22.071896] Call trace: [ 22.071910] show_stack+0x20/0x38 (C) [ 22.071947] dump_stack_lvl+0x8c/0xd0 [ 22.071980] print_report+0x118/0x608 [ 22.072014] kasan_report+0xdc/0x128 [ 22.072045] __asan_report_store1_noabort+0x20/0x30 [ 22.072082] krealloc_more_oob_helper+0x60c/0x678 [ 22.072111] krealloc_more_oob+0x20/0x38 [ 22.072138] kunit_try_run_case+0x170/0x3f0 [ 22.072172] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 22.072208] kthread+0x328/0x630 [ 22.072242] ret_from_fork+0x10/0x20 [ 22.072276] [ 22.140362] Allocated by task 201: [ 22.143752] kasan_save_stack+0x3c/0x68 [ 22.147568] kasan_save_track+0x20/0x40 [ 22.151387] kasan_save_alloc_info+0x40/0x58 [ 22.155640] __kasan_krealloc+0x118/0x178 [ 22.159633] krealloc_noprof+0x128/0x360 [ 22.163539] krealloc_more_oob_helper+0x168/0x678 [ 22.168226] krealloc_more_oob+0x20/0x38 [ 22.172133] kunit_try_run_case+0x170/0x3f0 [ 22.176299] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 22.181768] kthread+0x328/0x630 [ 22.184981] ret_from_fork+0x10/0x20 [ 22.188539] [ 22.190017] The buggy address belongs to the object at ffff0008034c8800 [ 22.190017] which belongs to the cache kmalloc-256 of size 256 [ 22.202517] The buggy address is located 0 bytes to the right of [ 22.202517] allocated 235-byte region [ffff0008034c8800, ffff0008034c88eb) [ 22.215448] [ 22.216928] The buggy address belongs to the physical page: [ 22.222483] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8834c8 [ 22.230467] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 22.238106] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 22.245050] page_type: f5(slab) [ 22.248188] raw: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000 [ 22.255905] raw: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000 [ 22.263632] head: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000 [ 22.271443] head: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000 [ 22.279256] head: 0bfffe0000000002 fffffdffe00d3201 00000000ffffffff 00000000ffffffff [ 22.287068] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 22.294874] page dumped because: kasan: bad access detected [ 22.300429] [ 22.301905] Memory state around the buggy address: [ 22.306687] ffff0008034c8780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 22.313889] ffff0008034c8800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 22.321094] >ffff0008034c8880: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fc fc [ 22.328294] ^ [ 22.334894] ffff0008034c8900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 22.342099] ffff0008034c8980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 22.349302] ================================================================== [ 22.356624] ================================================================== [ 22.363713] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x5c0/0x678 [ 22.371262] Write of size 1 at addr ffff0008034c88f0 by task kunit_try_catch/201 [ 22.378640] [ 22.380125] CPU: 7 UID: 0 PID: 201 Comm: kunit_try_catch Tainted: G B N 6.15.0-rc6-next-20250515 #1 PREEMPT [ 22.380176] Tainted: [B]=BAD_PAGE, [N]=TEST [ 22.380192] Hardware name: WinLink E850-96 board (DT) [ 22.380209] Call trace: [ 22.380223] show_stack+0x20/0x38 (C) [ 22.380255] dump_stack_lvl+0x8c/0xd0 [ 22.380286] print_report+0x118/0x608 [ 22.380319] kasan_report+0xdc/0x128 [ 22.380347] __asan_report_store1_noabort+0x20/0x30 [ 22.380382] krealloc_more_oob_helper+0x5c0/0x678 [ 22.380411] krealloc_more_oob+0x20/0x38 [ 22.380440] kunit_try_run_case+0x170/0x3f0 [ 22.380470] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 22.380502] kthread+0x328/0x630 [ 22.380534] ret_from_fork+0x10/0x20 [ 22.380567] [ 22.448691] Allocated by task 201: [ 22.452077] kasan_save_stack+0x3c/0x68 [ 22.455896] kasan_save_track+0x20/0x40 [ 22.459717] kasan_save_alloc_info+0x40/0x58 [ 22.463968] __kasan_krealloc+0x118/0x178 [ 22.467961] krealloc_noprof+0x128/0x360 [ 22.471868] krealloc_more_oob_helper+0x168/0x678 [ 22.476555] krealloc_more_oob+0x20/0x38 [ 22.480461] kunit_try_run_case+0x170/0x3f0 [ 22.484628] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 22.490097] kthread+0x328/0x630 [ 22.493308] ret_from_fork+0x10/0x20 [ 22.496867] [ 22.498345] The buggy address belongs to the object at ffff0008034c8800 [ 22.498345] which belongs to the cache kmalloc-256 of size 256 [ 22.510845] The buggy address is located 5 bytes to the right of [ 22.510845] allocated 235-byte region [ffff0008034c8800, ffff0008034c88eb) [ 22.523777] [ 22.525252] The buggy address belongs to the physical page: [ 22.530812] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8834c8 [ 22.538794] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 22.546434] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 22.553377] page_type: f5(slab) [ 22.556513] raw: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000 [ 22.564234] raw: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000 [ 22.571960] head: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000 [ 22.579772] head: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000 [ 22.587585] head: 0bfffe0000000002 fffffdffe00d3201 00000000ffffffff 00000000ffffffff [ 22.595397] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 22.603202] page dumped because: kasan: bad access detected [ 22.608758] [ 22.610233] Memory state around the buggy address: [ 22.615013] ffff0008034c8780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 22.622218] ffff0008034c8800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 22.629421] >ffff0008034c8880: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fc fc [ 22.636622] ^ [ 22.643483] ffff0008034c8900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 22.650688] ffff0008034c8980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 22.657889] ================================================================== [ 24.444944] ================================================================== [ 24.452051] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x5c0/0x678 [ 24.459599] Write of size 1 at addr ffff0008067a20f0 by task kunit_try_catch/205 [ 24.466977] [ 24.468459] CPU: 7 UID: 0 PID: 205 Comm: kunit_try_catch Tainted: G B N 6.15.0-rc6-next-20250515 #1 PREEMPT [ 24.468508] Tainted: [B]=BAD_PAGE, [N]=TEST [ 24.468523] Hardware name: WinLink E850-96 board (DT) [ 24.468543] Call trace: [ 24.468554] show_stack+0x20/0x38 (C) [ 24.468584] dump_stack_lvl+0x8c/0xd0 [ 24.468614] print_report+0x118/0x608 [ 24.468644] kasan_report+0xdc/0x128 [ 24.468673] __asan_report_store1_noabort+0x20/0x30 [ 24.468708] krealloc_more_oob_helper+0x5c0/0x678 [ 24.468737] krealloc_large_more_oob+0x20/0x38 [ 24.468767] kunit_try_run_case+0x170/0x3f0 [ 24.468796] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 24.468828] kthread+0x328/0x630 [ 24.468862] ret_from_fork+0x10/0x20 [ 24.468892] [ 24.537549] The buggy address belongs to the physical page: [ 24.543107] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8867a0 [ 24.551090] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 24.558731] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 24.565673] page_type: f8(unknown) [ 24.569066] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 24.576790] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 24.584517] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 24.592328] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 24.600141] head: 0bfffe0000000002 fffffdffe019e801 00000000ffffffff 00000000ffffffff [ 24.607953] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 24.615760] page dumped because: kasan: bad access detected [ 24.621315] [ 24.622790] Memory state around the buggy address: [ 24.627568] ffff0008067a1f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 24.634773] ffff0008067a2000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 24.641978] >ffff0008067a2080: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fe fe [ 24.649179] ^ [ 24.656040] ffff0008067a2100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 24.663245] ffff0008067a2180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 24.670446] ==================================================================