Hay
Date
June 20, 2025, 12:38 p.m.

Environment
qemu-arm64

[   36.247320] ==================================================================
[   36.247556] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x578/0x5d0
[   36.247728] Read of size 1 at addr ffff8000800fe7f3 by task kunit_try_catch/280
[   36.248096] 
[   36.248335] CPU: 0 UID: 0 PID: 280 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc2-next-20250620 #1 PREEMPT 
[   36.248617] Tainted: [B]=BAD_PAGE, [N]=TEST
[   36.248686] Hardware name: linux,dummy-virt (DT)
[   36.248770] Call trace:
[   36.249022]  show_stack+0x20/0x38 (C)
[   36.249166]  dump_stack_lvl+0x8c/0xd0
[   36.249275]  print_report+0x310/0x608
[   36.249461]  kasan_report+0xdc/0x128
[   36.249596]  __asan_report_load1_noabort+0x20/0x30
[   36.249831]  vmalloc_oob+0x578/0x5d0
[   36.250025]  kunit_try_run_case+0x170/0x3f0
[   36.250152]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   36.250280]  kthread+0x328/0x630
[   36.250697]  ret_from_fork+0x10/0x20
[   36.250853] 
[   36.251031] The buggy address belongs to the virtual mapping at
[   36.251031]  [ffff8000800fe000, ffff800080100000) created by:
[   36.251031]  vmalloc_oob+0x98/0x5d0
[   36.251278] 
[   36.251367] The buggy address belongs to the physical page:
[   36.251514] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x105ab5
[   36.251673] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   36.251849] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   36.251988] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   36.252108] page dumped because: kasan: bad access detected
[   36.252206] 
[   36.252280] Memory state around the buggy address:
[   36.252364]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   36.252469]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   36.252876] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   36.253003]                                                              ^
[   36.253231]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   36.253383]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   36.253513] ==================================================================
[   36.255605] ==================================================================
[   36.256028] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x51c/0x5d0
[   36.256240] Read of size 1 at addr ffff8000800fe7f8 by task kunit_try_catch/280
[   36.256358] 
[   36.256690] CPU: 0 UID: 0 PID: 280 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc2-next-20250620 #1 PREEMPT 
[   36.256988] Tainted: [B]=BAD_PAGE, [N]=TEST
[   36.257061] Hardware name: linux,dummy-virt (DT)
[   36.257160] Call trace:
[   36.257259]  show_stack+0x20/0x38 (C)
[   36.257381]  dump_stack_lvl+0x8c/0xd0
[   36.257510]  print_report+0x310/0x608
[   36.257622]  kasan_report+0xdc/0x128
[   36.257716]  __asan_report_load1_noabort+0x20/0x30
[   36.258136]  vmalloc_oob+0x51c/0x5d0
[   36.258312]  kunit_try_run_case+0x170/0x3f0
[   36.258536]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   36.258686]  kthread+0x328/0x630
[   36.258806]  ret_from_fork+0x10/0x20
[   36.258934] 
[   36.259093] The buggy address belongs to the virtual mapping at
[   36.259093]  [ffff8000800fe000, ffff800080100000) created by:
[   36.259093]  vmalloc_oob+0x98/0x5d0
[   36.259529] 
[   36.259595] The buggy address belongs to the physical page:
[   36.259713] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x105ab5
[   36.259937] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   36.260161] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   36.260287] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   36.260385] page dumped because: kasan: bad access detected
[   36.260471] 
[   36.260789] Memory state around the buggy address:
[   36.260928]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   36.261069]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   36.261231] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   36.261380]                                                                 ^
[   36.261534]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   36.261675]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   36.261776] ==================================================================