Hay
Date
June 17, 2025, 6:35 a.m.

Environment
qemu-arm64

[   19.995407] ==================================================================
[   19.995685] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x51c/0x5d0
[   19.995745] Read of size 1 at addr ffff8000800fe7f8 by task kunit_try_catch/278
[   19.995822] 
[   19.996177] CPU: 1 UID: 0 PID: 278 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc2-next-20250617 #1 PREEMPT 
[   19.996332] Tainted: [B]=BAD_PAGE, [N]=TEST
[   19.996376] Hardware name: linux,dummy-virt (DT)
[   19.996420] Call trace:
[   19.996447]  show_stack+0x20/0x38 (C)
[   19.996545]  dump_stack_lvl+0x8c/0xd0
[   19.996597]  print_report+0x310/0x608
[   19.996646]  kasan_report+0xdc/0x128
[   19.996695]  __asan_report_load1_noabort+0x20/0x30
[   19.996754]  vmalloc_oob+0x51c/0x5d0
[   19.996801]  kunit_try_run_case+0x170/0x3f0
[   19.996850]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   19.996903]  kthread+0x328/0x630
[   19.996966]  ret_from_fork+0x10/0x20
[   19.997015] 
[   19.997045] The buggy address belongs to the virtual mapping at
[   19.997045]  [ffff8000800fe000, ffff800080100000) created by:
[   19.997045]  vmalloc_oob+0x98/0x5d0
[   19.997120] 
[   19.997144] The buggy address belongs to the physical page:
[   19.997176] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x10522a
[   19.997230] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   19.997295] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   19.997348] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   19.997392] page dumped because: kasan: bad access detected
[   19.997435] 
[   19.997455] Memory state around the buggy address:
[   19.997489]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   19.997547]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   19.997599] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   19.997639]                                                                 ^
[   19.997692]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   19.997738]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   19.997780] ==================================================================
[   19.989101] ==================================================================
[   19.989222] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x578/0x5d0
[   19.989346] Read of size 1 at addr ffff8000800fe7f3 by task kunit_try_catch/278
[   19.989400] 
[   19.989724] CPU: 1 UID: 0 PID: 278 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc2-next-20250617 #1 PREEMPT 
[   19.989841] Tainted: [B]=BAD_PAGE, [N]=TEST
[   19.989870] Hardware name: linux,dummy-virt (DT)
[   19.989908] Call trace:
[   19.989944]  show_stack+0x20/0x38 (C)
[   19.990143]  dump_stack_lvl+0x8c/0xd0
[   19.990533]  print_report+0x310/0x608
[   19.990643]  kasan_report+0xdc/0x128
[   19.990854]  __asan_report_load1_noabort+0x20/0x30
[   19.991093]  vmalloc_oob+0x578/0x5d0
[   19.991174]  kunit_try_run_case+0x170/0x3f0
[   19.991486]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   19.991634]  kthread+0x328/0x630
[   19.991716]  ret_from_fork+0x10/0x20
[   19.992048] 
[   19.992115] The buggy address belongs to the virtual mapping at
[   19.992115]  [ffff8000800fe000, ffff800080100000) created by:
[   19.992115]  vmalloc_oob+0x98/0x5d0
[   19.992440] 
[   19.992476] The buggy address belongs to the physical page:
[   19.992647] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x10522a
[   19.992742] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   19.993122] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   19.993226] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   19.993312] page dumped because: kasan: bad access detected
[   19.993417] 
[   19.993469] Memory state around the buggy address:
[   19.993537]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   19.993716]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   19.993963] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   19.994084]                                                              ^
[   19.994151]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   19.994249]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   19.994362] ==================================================================