Hay
Date
June 2, 2025, 2:10 p.m.

Environment
qemu-x86_64

[   12.424349] ==================================================================
[   12.425093] BUG: KFENCE: use-after-free write in memset_orig+0x72/0xb0
[   12.425093] 
[   12.425640] Use-after-free write at 0x(____ptrval____) (in kfence-#45):
[   12.426294]  memset_orig+0x72/0xb0
[   12.426587]  kmalloc_double_kzfree+0x19d/0x360
[   12.426903]  kunit_try_run_case+0x1a6/0x480
[   12.427392]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   12.427639]  kthread+0x257/0x310
[   12.428006]  ret_from_fork+0x41/0x80
[   12.428672]  ret_from_fork_asm+0x1a/0x30
[   12.429050] 
[   12.429591] kfence-#45: 0x(____ptrval____)-0x(____ptrval____), size=16, cache=kmalloc-16
[   12.429591] 
[   12.430542] allocated by task 197 on cpu 1 at 12.422899s (0.007436s ago):
[   12.431415]  kmalloc_double_kzfree+0xaa/0x360
[   12.431653]  kunit_try_run_case+0x1a6/0x480
[   12.431821]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   12.432533]  kthread+0x257/0x310
[   12.432818]  ret_from_fork+0x41/0x80
[   12.432980]  ret_from_fork_asm+0x1a/0x30
[   12.433370] 
[   12.433696] freed by task 197 on cpu 1 at 12.422979s (0.010575s ago):
[   12.434195]  kfree_sensitive+0x67/0x90
[   12.434499]  kmalloc_double_kzfree+0x12c/0x360
[   12.434982]  kunit_try_run_case+0x1a6/0x480
[   12.435499]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   12.435901]  kthread+0x257/0x310
[   12.436465]  ret_from_fork+0x41/0x80
[   12.436829]  ret_from_fork_asm+0x1a/0x30
[   12.437219] 
[   12.437531] CPU: 1 UID: 0 PID: 197 Comm: kunit_try_catch Tainted: G    B            N 6.12.32-rc1 #1
[   12.438215] Tainted: [B]=BAD_PAGE, [N]=TEST
[   12.438376] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   12.439745] ==================================================================