Hay
Date
June 7, 2025, 10:40 a.m.

Environment
qemu-arm64
qemu-x86_64

[   61.127112] ==================================================================
[   61.127785] BUG: KFENCE: use-after-free read in test_krealloc+0x51c/0x830
[   61.127785] 
[   61.128464] Use-after-free read at 0x0000000073356e49 (in kfence-#186):
[   61.129375]  test_krealloc+0x51c/0x830
[   61.130534]  kunit_try_run_case+0x170/0x3f0
[   61.132223]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   61.133247]  kthread+0x318/0x620
[   61.133803]  ret_from_fork+0x10/0x20
[   61.134367] 
[   61.134711] kfence-#186: 0x0000000073356e49-0x00000000b10284cc, size=32, cache=kmalloc-32
[   61.134711] 
[   61.135680] allocated by task 326 on cpu 0 at 61.124411s (0.011257s ago):
[   61.136463]  test_alloc+0x29c/0x628
[   61.136968]  test_krealloc+0xc0/0x830
[   61.137519]  kunit_try_run_case+0x170/0x3f0
[   61.138110]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   61.138741]  kthread+0x318/0x620
[   61.139303]  ret_from_fork+0x10/0x20
[   61.139806] 
[   61.140151] freed by task 326 on cpu 0 at 61.124937s (0.015202s ago):
[   61.140838]  krealloc_noprof+0x148/0x360
[   61.141435]  test_krealloc+0x1dc/0x830
[   61.142037]  kunit_try_run_case+0x170/0x3f0
[   61.142597]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   61.143376]  kthread+0x318/0x620
[   61.143878]  ret_from_fork+0x10/0x20
[   61.144423] 
[   61.144768] CPU: 0 UID: 0 PID: 326 Comm: kunit_try_catch Tainted: G    B            N 6.14.11-rc1 #1
[   61.145734] Tainted: [B]=BAD_PAGE, [N]=TEST
[   61.146314] Hardware name: linux,dummy-virt (DT)
[   61.146845] ==================================================================

[   55.764161] ==================================================================
[   55.764553] BUG: KFENCE: use-after-free read in test_krealloc+0x6fd/0xbe0
[   55.764553] 
[   55.764953] Use-after-free read at 0x(____ptrval____) (in kfence-#161):
[   55.765632]  test_krealloc+0x6fd/0xbe0
[   55.765921]  kunit_try_run_case+0x1a6/0x480
[   55.766405]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   55.767079]  kthread+0x324/0x6e0
[   55.767502]  ret_from_fork+0x41/0x80
[   55.768008]  ret_from_fork_asm+0x1a/0x30
[   55.768496] 
[   55.768747] kfence-#161: 0x(____ptrval____)-0x(____ptrval____), size=32, cache=kmalloc-32
[   55.768747] 
[   55.769591] allocated by task 345 on cpu 0 at 55.763110s (0.006475s ago):
[   55.770323]  test_alloc+0x365/0x10f0
[   55.770574]  test_krealloc+0xae/0xbe0
[   55.770960]  kunit_try_run_case+0x1a6/0x480
[   55.771279]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   55.771692]  kthread+0x324/0x6e0
[   55.772065]  ret_from_fork+0x41/0x80
[   55.772455]  ret_from_fork_asm+0x1a/0x30
[   55.772720] 
[   55.772956] freed by task 345 on cpu 0 at 55.763644s (0.009306s ago):
[   55.773572]  krealloc_noprof+0x108/0x340
[   55.773995]  test_krealloc+0x227/0xbe0
[   55.774355]  kunit_try_run_case+0x1a6/0x480
[   55.774775]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   55.775348]  kthread+0x324/0x6e0
[   55.775747]  ret_from_fork+0x41/0x80
[   55.776012]  ret_from_fork_asm+0x1a/0x30
[   55.776284] 
[   55.776471] CPU: 0 UID: 0 PID: 345 Comm: kunit_try_catch Tainted: G    B            N 6.14.11-rc1 #1
[   55.777024] Tainted: [B]=BAD_PAGE, [N]=TEST
[   55.777408] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   55.777917] ==================================================================