Hay
Date
June 20, 2025, 12:38 p.m.

Environment
qemu-x86_64

[   25.998576] ==================================================================
[   25.999480] BUG: KFENCE: use-after-free write in memset_orig+0x72/0xb0
[   25.999480] 
[   26.000127] Use-after-free write at 0x(____ptrval____) (in kfence-#68):
[   26.000616]  memset_orig+0x72/0xb0
[   26.000961]  kmalloc_double_kzfree+0x19c/0x350
[   26.001304]  kunit_try_run_case+0x1a5/0x480
[   26.001597]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   26.001972]  kthread+0x337/0x6f0
[   26.002214]  ret_from_fork+0x116/0x1d0
[   26.002574]  ret_from_fork_asm+0x1a/0x30
[   26.002813] 
[   26.002927] kfence-#68: 0x(____ptrval____)-0x(____ptrval____), size=16, cache=kmalloc-16
[   26.002927] 
[   26.003576] allocated by task 221 on cpu 0 at 25.997099s (0.006471s ago):
[   26.003958]  kmalloc_double_kzfree+0xa9/0x350
[   26.004352]  kunit_try_run_case+0x1a5/0x480
[   26.004670]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   26.004887]  kthread+0x337/0x6f0
[   26.005047]  ret_from_fork+0x116/0x1d0
[   26.005431]  ret_from_fork_asm+0x1a/0x30
[   26.005789] 
[   26.005949] freed by task 221 on cpu 0 at 25.997213s (0.008731s ago):
[   26.006407]  kfree_sensitive+0x67/0x90
[   26.006724]  kmalloc_double_kzfree+0x12b/0x350
[   26.007092]  kunit_try_run_case+0x1a5/0x480
[   26.007423]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   26.007806]  kthread+0x337/0x6f0
[   26.008019]  ret_from_fork+0x116/0x1d0
[   26.008200]  ret_from_fork_asm+0x1a/0x30
[   26.008387] 
[   26.008618] CPU: 0 UID: 0 PID: 221 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc2-next-20250620 #1 PREEMPT(voluntary) 
[   26.009580] Tainted: [B]=BAD_PAGE, [N]=TEST
[   26.009914] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   26.010413] ==================================================================