Date
June 19, 2025, 12:07 p.m.
Environment | |
---|---|
qemu-arm64 | |
qemu-x86_64 |
[ 29.735325] ================================================================== [ 29.735544] BUG: KASAN: slab-out-of-bounds in kmalloc_oob_left+0x2ec/0x320 [ 29.735692] Read of size 1 at addr fff00000c4726c5f by task kunit_try_catch/149 [ 29.735818] [ 29.735921] CPU: 1 UID: 0 PID: 149 Comm: kunit_try_catch Tainted: G B N 6.16.0-rc2-next-20250619 #1 PREEMPT [ 29.736141] Tainted: [B]=BAD_PAGE, [N]=TEST [ 29.736208] Hardware name: linux,dummy-virt (DT) [ 29.736284] Call trace: [ 29.736338] show_stack+0x20/0x38 (C) [ 29.736479] dump_stack_lvl+0x8c/0xd0 [ 29.736592] print_report+0x118/0x608 [ 29.736698] kasan_report+0xdc/0x128 [ 29.736829] __asan_report_load1_noabort+0x20/0x30 [ 29.736999] kmalloc_oob_left+0x2ec/0x320 [ 29.737191] kunit_try_run_case+0x170/0x3f0 [ 29.737371] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 29.737550] kthread+0x328/0x630 [ 29.737660] ret_from_fork+0x10/0x20 [ 29.737796] [ 29.737838] Allocated by task 21: [ 29.737937] kasan_save_stack+0x3c/0x68 [ 29.738077] kasan_save_track+0x20/0x40 [ 29.738167] kasan_save_alloc_info+0x40/0x58 [ 29.738284] __kasan_kmalloc+0xd4/0xd8 [ 29.738362] __kmalloc_cache_node_noprof+0x178/0x3d0 [ 29.738443] build_sched_domains+0x32c/0x3768 [ 29.738557] partition_sched_domains+0x79c/0x1098 [ 29.738649] rebuild_sched_domains_locked+0x494/0xde0 [ 29.738749] cpuset_handle_hotplug+0xab0/0x1480 [ 29.738824] cpuset_update_active_cpus+0x18/0x30 [ 29.738916] sched_cpu_activate+0x2d0/0x388 [ 29.739016] cpuhp_invoke_callback+0x5b8/0x1620 [ 29.739112] cpuhp_thread_fun+0x230/0x5d8 [ 29.739239] smpboot_thread_fn+0x2e8/0x760 [ 29.739377] kthread+0x328/0x630 [ 29.739485] ret_from_fork+0x10/0x20 [ 29.739605] [ 29.739720] Freed by task 21: [ 29.739843] kasan_save_stack+0x3c/0x68 [ 29.739989] kasan_save_track+0x20/0x40 [ 29.740080] kasan_save_free_info+0x4c/0x78 [ 29.740211] __kasan_slab_free+0x6c/0x98 [ 29.740337] kfree+0x214/0x3c8 [ 29.740452] build_sched_domains+0x1c64/0x3768 [ 29.740587] partition_sched_domains+0x79c/0x1098 [ 29.740723] rebuild_sched_domains_locked+0x494/0xde0 [ 29.740861] cpuset_handle_hotplug+0xab0/0x1480 [ 29.740958] cpuset_update_active_cpus+0x18/0x30 [ 29.741034] sched_cpu_activate+0x2d0/0x388 [ 29.741120] cpuhp_invoke_callback+0x5b8/0x1620 [ 29.741219] cpuhp_thread_fun+0x230/0x5d8 [ 29.741314] smpboot_thread_fn+0x2e8/0x760 [ 29.741447] kthread+0x328/0x630 [ 29.741532] ret_from_fork+0x10/0x20 [ 29.741653] [ 29.741723] The buggy address belongs to the object at fff00000c4726c40 [ 29.741723] which belongs to the cache kmalloc-16 of size 16 [ 29.741885] The buggy address is located 15 bytes to the right of [ 29.741885] allocated 16-byte region [fff00000c4726c40, fff00000c4726c50) [ 29.742056] [ 29.742113] The buggy address belongs to the physical page: [ 29.742198] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x104726 [ 29.742327] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff) [ 29.742509] page_type: f5(slab) [ 29.742638] raw: 0bfffe0000000000 fff00000c0001640 dead000000000100 dead000000000122 [ 29.742800] raw: 0000000000000000 0000000080800080 00000000f5000000 0000000000000000 [ 29.742916] page dumped because: kasan: bad access detected [ 29.743000] [ 29.743043] Memory state around the buggy address: [ 29.743126] fff00000c4726b00: fa fb fc fc fa fb fc fc fa fb fc fc fa fb fc fc [ 29.743250] fff00000c4726b80: 00 00 fc fc fa fb fc fc fa fb fc fc fa fb fc fc [ 29.743339] >fff00000c4726c00: fa fb fc fc fa fb fc fc fa fb fc fc 00 07 fc fc [ 29.743412] ^ [ 29.743511] fff00000c4726c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 29.743610] fff00000c4726d00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 29.743694] ==================================================================
[ 25.873812] ================================================================== [ 25.875527] BUG: KASAN: slab-out-of-bounds in kmalloc_oob_left+0x361/0x3c0 [ 25.876316] Read of size 1 at addr ffff8881022a25ff by task kunit_try_catch/167 [ 25.876791] [ 25.876952] CPU: 1 UID: 0 PID: 167 Comm: kunit_try_catch Tainted: G B N 6.16.0-rc2-next-20250619 #1 PREEMPT(voluntary) [ 25.877050] Tainted: [B]=BAD_PAGE, [N]=TEST [ 25.877072] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 25.877122] Call Trace: [ 25.877149] <TASK> [ 25.877183] dump_stack_lvl+0x73/0xb0 [ 25.877260] print_report+0xd1/0x650 [ 25.877301] ? __virt_addr_valid+0x1db/0x2d0 [ 25.877338] ? kmalloc_oob_left+0x361/0x3c0 [ 25.877372] ? kasan_complete_mode_report_info+0x64/0x200 [ 25.877411] ? kmalloc_oob_left+0x361/0x3c0 [ 25.877448] kasan_report+0x141/0x180 [ 25.877880] ? kmalloc_oob_left+0x361/0x3c0 [ 25.877999] __asan_report_load1_noabort+0x18/0x20 [ 25.878059] kmalloc_oob_left+0x361/0x3c0 [ 25.878120] ? __pfx_kmalloc_oob_left+0x10/0x10 [ 25.878173] ? __schedule+0x10cc/0x2b60 [ 25.878223] ? __pfx_read_tsc+0x10/0x10 [ 25.878270] ? ktime_get_ts64+0x86/0x230 [ 25.878422] kunit_try_run_case+0x1a5/0x480 [ 25.878526] ? __pfx_kunit_try_run_case+0x10/0x10 [ 25.878556] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 25.878583] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 25.878607] ? __kthread_parkme+0x82/0x180 [ 25.878631] ? preempt_count_sub+0x50/0x80 [ 25.878657] ? __pfx_kunit_try_run_case+0x10/0x10 [ 25.878681] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 25.878722] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 25.878747] kthread+0x337/0x6f0 [ 25.878769] ? trace_preempt_on+0x20/0xc0 [ 25.878794] ? __pfx_kthread+0x10/0x10 [ 25.878816] ? _raw_spin_unlock_irq+0x47/0x80 [ 25.878839] ? calculate_sigpending+0x7b/0xa0 [ 25.878864] ? __pfx_kthread+0x10/0x10 [ 25.878887] ret_from_fork+0x116/0x1d0 [ 25.878930] ? __pfx_kthread+0x10/0x10 [ 25.879229] ret_from_fork_asm+0x1a/0x30 [ 25.879266] </TASK> [ 25.879279] [ 25.893995] Allocated by task 21: [ 25.894317] kasan_save_stack+0x45/0x70 [ 25.894623] kasan_save_track+0x18/0x40 [ 25.894882] kasan_save_alloc_info+0x3b/0x50 [ 25.895085] __kasan_kmalloc+0xb7/0xc0 [ 25.896753] __kmalloc_cache_node_noprof+0x188/0x420 [ 25.897231] build_sched_domains+0x38c/0x5dd0 [ 25.897862] partition_sched_domains+0x471/0x9c0 [ 25.898484] rebuild_sched_domains_locked+0x97d/0xd50 [ 25.898728] cpuset_update_active_cpus+0x80f/0x1a90 [ 25.898948] sched_cpu_activate+0x2bf/0x330 [ 25.899875] cpuhp_invoke_callback+0x2a1/0xf00 [ 25.900521] cpuhp_thread_fun+0x2ce/0x5c0 [ 25.901160] smpboot_thread_fn+0x2bc/0x730 [ 25.901471] kthread+0x337/0x6f0 [ 25.901769] ret_from_fork+0x116/0x1d0 [ 25.902526] ret_from_fork_asm+0x1a/0x30 [ 25.902937] [ 25.903387] Freed by task 21: [ 25.903629] kasan_save_stack+0x45/0x70 [ 25.904497] kasan_save_track+0x18/0x40 [ 25.904810] kasan_save_free_info+0x3f/0x60 [ 25.905275] __kasan_slab_free+0x56/0x70 [ 25.905655] kfree+0x222/0x3f0 [ 25.905858] build_sched_domains+0x1fff/0x5dd0 [ 25.906488] partition_sched_domains+0x471/0x9c0 [ 25.907133] rebuild_sched_domains_locked+0x97d/0xd50 [ 25.907414] cpuset_update_active_cpus+0x80f/0x1a90 [ 25.907830] sched_cpu_activate+0x2bf/0x330 [ 25.908718] cpuhp_invoke_callback+0x2a1/0xf00 [ 25.909245] cpuhp_thread_fun+0x2ce/0x5c0 [ 25.909462] smpboot_thread_fn+0x2bc/0x730 [ 25.909840] kthread+0x337/0x6f0 [ 25.910363] ret_from_fork+0x116/0x1d0 [ 25.910695] ret_from_fork_asm+0x1a/0x30 [ 25.911346] [ 25.911559] The buggy address belongs to the object at ffff8881022a25e0 [ 25.911559] which belongs to the cache kmalloc-16 of size 16 [ 25.912295] The buggy address is located 15 bytes to the right of [ 25.912295] allocated 16-byte region [ffff8881022a25e0, ffff8881022a25f0) [ 25.913645] [ 25.913873] The buggy address belongs to the physical page: [ 25.914632] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1022a2 [ 25.915363] flags: 0x200000000000000(node=0|zone=2) [ 25.915785] page_type: f5(slab) [ 25.916422] raw: 0200000000000000 ffff888100041640 dead000000000100 dead000000000122 [ 25.916921] raw: 0000000000000000 0000000080800080 00000000f5000000 0000000000000000 [ 25.917241] page dumped because: kasan: bad access detected [ 25.917633] [ 25.917752] Memory state around the buggy address: [ 25.918091] ffff8881022a2480: fa fb fc fc 00 06 fc fc 00 06 fc fc 00 06 fc fc [ 25.919166] ffff8881022a2500: fa fb fc fc fa fb fc fc 00 00 fc fc fa fb fc fc [ 25.919747] >ffff8881022a2580: fa fb fc fc fa fb fc fc fa fb fc fc fa fb fc fc [ 25.920832] ^ [ 25.921541] ffff8881022a2600: 00 07 fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 25.921959] ffff8881022a2680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 25.922660] ==================================================================