Hay
Date
May 15, 2025, 10:38 a.m.

Environment
e850-96

[   24.210139] ==================================================================
[   24.219507] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x60c/0x678
[   24.227054] Write of size 1 at addr ffff0008067a20eb by task kunit_try_catch/205
[   24.234429] 
[   24.235916] CPU: 7 UID: 0 PID: 205 Comm: kunit_try_catch Tainted: G    B            N  6.15.0-rc6-next-20250515 #1 PREEMPT 
[   24.235972] Tainted: [B]=BAD_PAGE, [N]=TEST
[   24.235988] Hardware name: WinLink E850-96 board (DT)
[   24.236008] Call trace:
[   24.236020]  show_stack+0x20/0x38 (C)
[   24.236057]  dump_stack_lvl+0x8c/0xd0
[   24.236088]  print_report+0x118/0x608
[   24.236119]  kasan_report+0xdc/0x128
[   24.236148]  __asan_report_store1_noabort+0x20/0x30
[   24.236185]  krealloc_more_oob_helper+0x60c/0x678
[   24.236215]  krealloc_large_more_oob+0x20/0x38
[   24.236243]  kunit_try_run_case+0x170/0x3f0
[   24.236278]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   24.236312]  kthread+0x328/0x630
[   24.236346]  ret_from_fork+0x10/0x20
[   24.236381] 
[   24.305004] The buggy address belongs to the physical page:
[   24.310559] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8867a0
[   24.318543] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   24.326184] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   24.333126] page_type: f8(unknown)
[   24.336524] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   24.344242] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   24.351968] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   24.359780] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   24.367593] head: 0bfffe0000000002 fffffdffe019e801 00000000ffffffff 00000000ffffffff
[   24.375405] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   24.383212] page dumped because: kasan: bad access detected
[   24.388767] 
[   24.390241] Memory state around the buggy address:
[   24.395024]  ffff0008067a1f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   24.402224]  ffff0008067a2000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   24.409429] >ffff0008067a2080: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fe fe
[   24.416630]                                                           ^
[   24.423231]  ffff0008067a2100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   24.430436]  ffff0008067a2180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   24.437638] ==================================================================
[   22.046304] ==================================================================
[   22.055385] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x60c/0x678
[   22.062935] Write of size 1 at addr ffff0008034c88eb by task kunit_try_catch/201
[   22.070313] 
[   22.071799] CPU: 7 UID: 0 PID: 201 Comm: kunit_try_catch Tainted: G    B            N  6.15.0-rc6-next-20250515 #1 PREEMPT 
[   22.071857] Tainted: [B]=BAD_PAGE, [N]=TEST
[   22.071874] Hardware name: WinLink E850-96 board (DT)
[   22.071896] Call trace:
[   22.071910]  show_stack+0x20/0x38 (C)
[   22.071947]  dump_stack_lvl+0x8c/0xd0
[   22.071980]  print_report+0x118/0x608
[   22.072014]  kasan_report+0xdc/0x128
[   22.072045]  __asan_report_store1_noabort+0x20/0x30
[   22.072082]  krealloc_more_oob_helper+0x60c/0x678
[   22.072111]  krealloc_more_oob+0x20/0x38
[   22.072138]  kunit_try_run_case+0x170/0x3f0
[   22.072172]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.072208]  kthread+0x328/0x630
[   22.072242]  ret_from_fork+0x10/0x20
[   22.072276] 
[   22.140362] Allocated by task 201:
[   22.143752]  kasan_save_stack+0x3c/0x68
[   22.147568]  kasan_save_track+0x20/0x40
[   22.151387]  kasan_save_alloc_info+0x40/0x58
[   22.155640]  __kasan_krealloc+0x118/0x178
[   22.159633]  krealloc_noprof+0x128/0x360
[   22.163539]  krealloc_more_oob_helper+0x168/0x678
[   22.168226]  krealloc_more_oob+0x20/0x38
[   22.172133]  kunit_try_run_case+0x170/0x3f0
[   22.176299]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.181768]  kthread+0x328/0x630
[   22.184981]  ret_from_fork+0x10/0x20
[   22.188539] 
[   22.190017] The buggy address belongs to the object at ffff0008034c8800
[   22.190017]  which belongs to the cache kmalloc-256 of size 256
[   22.202517] The buggy address is located 0 bytes to the right of
[   22.202517]  allocated 235-byte region [ffff0008034c8800, ffff0008034c88eb)
[   22.215448] 
[   22.216928] The buggy address belongs to the physical page:
[   22.222483] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8834c8
[   22.230467] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   22.238106] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   22.245050] page_type: f5(slab)
[   22.248188] raw: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000
[   22.255905] raw: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000
[   22.263632] head: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000
[   22.271443] head: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000
[   22.279256] head: 0bfffe0000000002 fffffdffe00d3201 00000000ffffffff 00000000ffffffff
[   22.287068] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   22.294874] page dumped because: kasan: bad access detected
[   22.300429] 
[   22.301905] Memory state around the buggy address:
[   22.306687]  ffff0008034c8780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   22.313889]  ffff0008034c8800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.321094] >ffff0008034c8880: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fc fc
[   22.328294]                                                           ^
[   22.334894]  ffff0008034c8900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   22.342099]  ffff0008034c8980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   22.349302] ==================================================================
[   22.356624] ==================================================================
[   22.363713] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x5c0/0x678
[   22.371262] Write of size 1 at addr ffff0008034c88f0 by task kunit_try_catch/201
[   22.378640] 
[   22.380125] CPU: 7 UID: 0 PID: 201 Comm: kunit_try_catch Tainted: G    B            N  6.15.0-rc6-next-20250515 #1 PREEMPT 
[   22.380176] Tainted: [B]=BAD_PAGE, [N]=TEST
[   22.380192] Hardware name: WinLink E850-96 board (DT)
[   22.380209] Call trace:
[   22.380223]  show_stack+0x20/0x38 (C)
[   22.380255]  dump_stack_lvl+0x8c/0xd0
[   22.380286]  print_report+0x118/0x608
[   22.380319]  kasan_report+0xdc/0x128
[   22.380347]  __asan_report_store1_noabort+0x20/0x30
[   22.380382]  krealloc_more_oob_helper+0x5c0/0x678
[   22.380411]  krealloc_more_oob+0x20/0x38
[   22.380440]  kunit_try_run_case+0x170/0x3f0
[   22.380470]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.380502]  kthread+0x328/0x630
[   22.380534]  ret_from_fork+0x10/0x20
[   22.380567] 
[   22.448691] Allocated by task 201:
[   22.452077]  kasan_save_stack+0x3c/0x68
[   22.455896]  kasan_save_track+0x20/0x40
[   22.459717]  kasan_save_alloc_info+0x40/0x58
[   22.463968]  __kasan_krealloc+0x118/0x178
[   22.467961]  krealloc_noprof+0x128/0x360
[   22.471868]  krealloc_more_oob_helper+0x168/0x678
[   22.476555]  krealloc_more_oob+0x20/0x38
[   22.480461]  kunit_try_run_case+0x170/0x3f0
[   22.484628]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.490097]  kthread+0x328/0x630
[   22.493308]  ret_from_fork+0x10/0x20
[   22.496867] 
[   22.498345] The buggy address belongs to the object at ffff0008034c8800
[   22.498345]  which belongs to the cache kmalloc-256 of size 256
[   22.510845] The buggy address is located 5 bytes to the right of
[   22.510845]  allocated 235-byte region [ffff0008034c8800, ffff0008034c88eb)
[   22.523777] 
[   22.525252] The buggy address belongs to the physical page:
[   22.530812] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8834c8
[   22.538794] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   22.546434] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   22.553377] page_type: f5(slab)
[   22.556513] raw: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000
[   22.564234] raw: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000
[   22.571960] head: 0bfffe0000000040 ffff000800002b40 dead000000000122 0000000000000000
[   22.579772] head: 0000000000000000 0000000080200020 00000000f5000000 0000000000000000
[   22.587585] head: 0bfffe0000000002 fffffdffe00d3201 00000000ffffffff 00000000ffffffff
[   22.595397] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   22.603202] page dumped because: kasan: bad access detected
[   22.608758] 
[   22.610233] Memory state around the buggy address:
[   22.615013]  ffff0008034c8780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   22.622218]  ffff0008034c8800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.629421] >ffff0008034c8880: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fc fc
[   22.636622]                                                              ^
[   22.643483]  ffff0008034c8900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   22.650688]  ffff0008034c8980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   22.657889] ==================================================================
[   24.444944] ==================================================================
[   24.452051] BUG: KASAN: slab-out-of-bounds in krealloc_more_oob_helper+0x5c0/0x678
[   24.459599] Write of size 1 at addr ffff0008067a20f0 by task kunit_try_catch/205
[   24.466977] 
[   24.468459] CPU: 7 UID: 0 PID: 205 Comm: kunit_try_catch Tainted: G    B            N  6.15.0-rc6-next-20250515 #1 PREEMPT 
[   24.468508] Tainted: [B]=BAD_PAGE, [N]=TEST
[   24.468523] Hardware name: WinLink E850-96 board (DT)
[   24.468543] Call trace:
[   24.468554]  show_stack+0x20/0x38 (C)
[   24.468584]  dump_stack_lvl+0x8c/0xd0
[   24.468614]  print_report+0x118/0x608
[   24.468644]  kasan_report+0xdc/0x128
[   24.468673]  __asan_report_store1_noabort+0x20/0x30
[   24.468708]  krealloc_more_oob_helper+0x5c0/0x678
[   24.468737]  krealloc_large_more_oob+0x20/0x38
[   24.468767]  kunit_try_run_case+0x170/0x3f0
[   24.468796]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   24.468828]  kthread+0x328/0x630
[   24.468862]  ret_from_fork+0x10/0x20
[   24.468892] 
[   24.537549] The buggy address belongs to the physical page:
[   24.543107] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8867a0
[   24.551090] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   24.558731] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   24.565673] page_type: f8(unknown)
[   24.569066] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   24.576790] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   24.584517] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   24.592328] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   24.600141] head: 0bfffe0000000002 fffffdffe019e801 00000000ffffffff 00000000ffffffff
[   24.607953] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   24.615760] page dumped because: kasan: bad access detected
[   24.621315] 
[   24.622790] Memory state around the buggy address:
[   24.627568]  ffff0008067a1f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   24.634773]  ffff0008067a2000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   24.641978] >ffff0008067a2080: 00 00 00 00 00 00 00 00 00 00 00 00 00 03 fe fe
[   24.649179]                                                              ^
[   24.656040]  ffff0008067a2100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   24.663245]  ffff0008067a2180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   24.670446] ==================================================================