Hay
Date
June 17, 2025, 3:40 p.m.

Environment
qemu-arm64
qemu-x86_64

[   21.487259] ==================================================================
[   21.487402] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xb9c/0xc50
[   21.487544] Write of size 1 at addr fff00000c78920d0 by task kunit_try_catch/164
[   21.487655] 
[   21.487766] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT 
[   21.487971] Tainted: [B]=BAD_PAGE, [N]=TEST
[   21.488035] Hardware name: linux,dummy-virt (DT)
[   21.488116] Call trace:
[   21.488175]  show_stack+0x20/0x38 (C)
[   21.488292]  dump_stack_lvl+0x8c/0xd0
[   21.488404]  print_report+0x118/0x608
[   21.488511]  kasan_report+0xdc/0x128
[   21.488614]  __asan_report_store1_noabort+0x20/0x30
[   21.489451]  krealloc_less_oob_helper+0xb9c/0xc50
[   21.489697]  krealloc_large_less_oob+0x20/0x38
[   21.490024]  kunit_try_run_case+0x170/0x3f0
[   21.490212]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   21.490557]  kthread+0x328/0x630
[   21.490691]  ret_from_fork+0x10/0x20
[   21.490856] 
[   21.490903] The buggy address belongs to the physical page:
[   21.491052] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890
[   21.491234] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   21.491582] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   21.491828] page_type: f8(unknown)
[   21.491968] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.492152] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.492688] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.493166] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.493392] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff
[   21.493602] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   21.493819] page dumped because: kasan: bad access detected
[   21.493906] 
[   21.494123] Memory state around the buggy address:
[   21.494209]  fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.494313]  fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.494408] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   21.494494]                                                  ^
[   21.494710]  fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.494921]  fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.495084] ==================================================================
[   21.465691] ==================================================================
[   21.466470] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xa48/0xc50
[   21.466655] Write of size 1 at addr fff00000c78920c9 by task kunit_try_catch/164
[   21.466774] 
[   21.466870] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT 
[   21.467076] Tainted: [B]=BAD_PAGE, [N]=TEST
[   21.467152] Hardware name: linux,dummy-virt (DT)
[   21.467264] Call trace:
[   21.467318]  show_stack+0x20/0x38 (C)
[   21.467439]  dump_stack_lvl+0x8c/0xd0
[   21.467552]  print_report+0x118/0x608
[   21.467657]  kasan_report+0xdc/0x128
[   21.467775]  __asan_report_store1_noabort+0x20/0x30
[   21.467910]  krealloc_less_oob_helper+0xa48/0xc50
[   21.468080]  krealloc_large_less_oob+0x20/0x38
[   21.468259]  kunit_try_run_case+0x170/0x3f0
[   21.468398]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   21.469105]  kthread+0x328/0x630
[   21.469286]  ret_from_fork+0x10/0x20
[   21.469427] 
[   21.469492] The buggy address belongs to the physical page:
[   21.469590] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890
[   21.469799] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   21.469913] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   21.470071] page_type: f8(unknown)
[   21.470789] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.470914] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.471032] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.471157] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.471280] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff
[   21.473315] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   21.473952] page dumped because: kasan: bad access detected
[   21.474047] 
[   21.474091] Memory state around the buggy address:
[   21.474172]  fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.474833]  fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.475398] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   21.477156]                                               ^
[   21.478003]  fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.478453]  fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.478537] ==================================================================
[   21.500321] ==================================================================
[   21.500458] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xa80/0xc50
[   21.500599] Write of size 1 at addr fff00000c78920da by task kunit_try_catch/164
[   21.500723] 
[   21.501498] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT 
[   21.501791] Tainted: [B]=BAD_PAGE, [N]=TEST
[   21.501846] Hardware name: linux,dummy-virt (DT)
[   21.502162] Call trace:
[   21.502242]  show_stack+0x20/0x38 (C)
[   21.502540]  dump_stack_lvl+0x8c/0xd0
[   21.502803]  print_report+0x118/0x608
[   21.503064]  kasan_report+0xdc/0x128
[   21.503305]  __asan_report_store1_noabort+0x20/0x30
[   21.503447]  krealloc_less_oob_helper+0xa80/0xc50
[   21.503832]  krealloc_large_less_oob+0x20/0x38
[   21.504338]  kunit_try_run_case+0x170/0x3f0
[   21.504615]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   21.504847]  kthread+0x328/0x630
[   21.504952]  ret_from_fork+0x10/0x20
[   21.505441] 
[   21.505509] The buggy address belongs to the physical page:
[   21.505700] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890
[   21.505987] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   21.506389] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   21.506557] page_type: f8(unknown)
[   21.506675] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.506795] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.507070] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.507320] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.507618] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff
[   21.508132] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   21.508244] page dumped because: kasan: bad access detected
[   21.508433] 
[   21.508486] Memory state around the buggy address:
[   21.508876]  fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.508987]  fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.509203] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   21.509400]                                                     ^
[   21.509605]  fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.509972]  fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.510087] ==================================================================
[   21.511744] ==================================================================
[   21.511862] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xae4/0xc50
[   21.511993] Write of size 1 at addr fff00000c78920ea by task kunit_try_catch/164
[   21.512122] 
[   21.512213] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT 
[   21.512412] Tainted: [B]=BAD_PAGE, [N]=TEST
[   21.512475] Hardware name: linux,dummy-virt (DT)
[   21.512553] Call trace:
[   21.512608]  show_stack+0x20/0x38 (C)
[   21.512723]  dump_stack_lvl+0x8c/0xd0
[   21.514530]  print_report+0x118/0x608
[   21.514760]  kasan_report+0xdc/0x128
[   21.515526]  __asan_report_store1_noabort+0x20/0x30
[   21.515672]  krealloc_less_oob_helper+0xae4/0xc50
[   21.515914]  krealloc_large_less_oob+0x20/0x38
[   21.516055]  kunit_try_run_case+0x170/0x3f0
[   21.516639]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   21.516903]  kthread+0x328/0x630
[   21.517129]  ret_from_fork+0x10/0x20
[   21.517350] 
[   21.517427] The buggy address belongs to the physical page:
[   21.517608] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890
[   21.517987] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   21.518102] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   21.518220] page_type: f8(unknown)
[   21.518402] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.518656] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.518888] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.519349] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.519644] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff
[   21.519893] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   21.520218] page dumped because: kasan: bad access detected
[   21.520390] 
[   21.520454] Memory state around the buggy address:
[   21.520634]  fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.520746]  fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.521079] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   21.521304]                                                           ^
[   21.521507]  fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.521778]  fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.521915] ==================================================================
[   21.523828] ==================================================================
[   21.523955] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xa58/0xc50
[   21.524078] Write of size 1 at addr fff00000c78920eb by task kunit_try_catch/164
[   21.524219] 
[   21.524338] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT 
[   21.524566] Tainted: [B]=BAD_PAGE, [N]=TEST
[   21.524633] Hardware name: linux,dummy-virt (DT)
[   21.524706] Call trace:
[   21.524772]  show_stack+0x20/0x38 (C)
[   21.524897]  dump_stack_lvl+0x8c/0xd0
[   21.525011]  print_report+0x118/0x608
[   21.525121]  kasan_report+0xdc/0x128
[   21.525228]  __asan_report_store1_noabort+0x20/0x30
[   21.525369]  krealloc_less_oob_helper+0xa58/0xc50
[   21.525497]  krealloc_large_less_oob+0x20/0x38
[   21.526184]  kunit_try_run_case+0x170/0x3f0
[   21.526370]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   21.526508]  kthread+0x328/0x630
[   21.526624]  ret_from_fork+0x10/0x20
[   21.526767] 
[   21.526819] The buggy address belongs to the physical page:
[   21.526956] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890
[   21.527070] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   21.527173] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff)
[   21.527392] page_type: f8(unknown)
[   21.527484] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.527848] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.527983] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000
[   21.528114] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   21.528239] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff
[   21.528356] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   21.528460] page dumped because: kasan: bad access detected
[   21.528537] 
[   21.528580] Memory state around the buggy address:
[   21.528665]  fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.528785]  fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   21.528893] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   21.528991]                                                           ^
[   21.529091]  fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.529203]  fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   21.529297] ==================================================================

[   18.858148] ==================================================================
[   18.859453] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe90/0x11d0
[   18.860361] Write of size 1 at addr ffff8881029f60ea by task kunit_try_catch/182
[   18.861682] 
[   18.861878] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.861967] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.862009] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.862061] Call Trace:
[   18.862233]  <TASK>
[   18.862301]  dump_stack_lvl+0x73/0xb0
[   18.862360]  print_report+0xd1/0x650
[   18.862399]  ? __virt_addr_valid+0x1db/0x2d0
[   18.862431]  ? krealloc_less_oob_helper+0xe90/0x11d0
[   18.862462]  ? kasan_addr_to_slab+0x11/0xa0
[   18.862495]  ? krealloc_less_oob_helper+0xe90/0x11d0
[   18.862525]  kasan_report+0x141/0x180
[   18.862559]  ? krealloc_less_oob_helper+0xe90/0x11d0
[   18.862598]  __asan_report_store1_noabort+0x1b/0x30
[   18.862630]  krealloc_less_oob_helper+0xe90/0x11d0
[   18.862663]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.862694]  ? finish_task_switch.isra.0+0x153/0x700
[   18.862727]  ? __switch_to+0x5d9/0xf60
[   18.862756]  ? dequeue_task_fair+0x166/0x4e0
[   18.862792]  ? __schedule+0x10cc/0x2b60
[   18.862826]  ? __pfx_read_tsc+0x10/0x10
[   18.862862]  krealloc_large_less_oob+0x1c/0x30
[   18.862891]  kunit_try_run_case+0x1a5/0x480
[   18.862928]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.863157]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.863212]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.863251]  ? __kthread_parkme+0x82/0x180
[   18.863303]  ? preempt_count_sub+0x50/0x80
[   18.863350]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.863387]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.863422]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.863457]  kthread+0x337/0x6f0
[   18.863482]  ? trace_preempt_on+0x20/0xc0
[   18.863519]  ? __pfx_kthread+0x10/0x10
[   18.863546]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.863578]  ? calculate_sigpending+0x7b/0xa0
[   18.863610]  ? __pfx_kthread+0x10/0x10
[   18.863636]  ret_from_fork+0x41/0x80
[   18.863668]  ? __pfx_kthread+0x10/0x10
[   18.863694]  ret_from_fork_asm+0x1a/0x30
[   18.863739]  </TASK>
[   18.863755] 
[   18.887305] The buggy address belongs to the physical page:
[   18.887864] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4
[   18.889475] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.890363] flags: 0x200000000000040(head|node=0|zone=2)
[   18.891050] page_type: f8(unknown)
[   18.891559] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.892523] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.893076] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.894607] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.895531] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff
[   18.896393] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   18.897126] page dumped because: kasan: bad access detected
[   18.897609] 
[   18.897826] Memory state around the buggy address:
[   18.898515]  ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.898833]  ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.899434] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   18.899696]                                                           ^
[   18.899936]  ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.901706]  ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.902281] ==================================================================
[   18.387819] ==================================================================
[   18.388652] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe23/0x11d0
[   18.389854] Write of size 1 at addr ffff888100aab4d0 by task kunit_try_catch/178
[   18.390487] 
[   18.390765] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.390868] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.390888] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.390917] Call Trace:
[   18.390935]  <TASK>
[   18.390958]  dump_stack_lvl+0x73/0xb0
[   18.391090]  print_report+0xd1/0x650
[   18.391188]  ? __virt_addr_valid+0x1db/0x2d0
[   18.391261]  ? krealloc_less_oob_helper+0xe23/0x11d0
[   18.391347]  ? kasan_complete_mode_report_info+0x2a/0x200
[   18.391420]  ? krealloc_less_oob_helper+0xe23/0x11d0
[   18.391487]  kasan_report+0x141/0x180
[   18.391552]  ? krealloc_less_oob_helper+0xe23/0x11d0
[   18.391631]  __asan_report_store1_noabort+0x1b/0x30
[   18.391702]  krealloc_less_oob_helper+0xe23/0x11d0
[   18.391777]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.391904]  ? finish_task_switch.isra.0+0x153/0x700
[   18.392089]  ? __switch_to+0x5d9/0xf60
[   18.392126]  ? dequeue_task_fair+0x166/0x4e0
[   18.392162]  ? __schedule+0x10cc/0x2b60
[   18.392196]  ? __pfx_read_tsc+0x10/0x10
[   18.392231]  krealloc_less_oob+0x1c/0x30
[   18.392258]  kunit_try_run_case+0x1a5/0x480
[   18.392319]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.392355]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.392391]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.392426]  ? __kthread_parkme+0x82/0x180
[   18.392458]  ? preempt_count_sub+0x50/0x80
[   18.392492]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.392526]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.392559]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.392592]  kthread+0x337/0x6f0
[   18.392615]  ? trace_preempt_on+0x20/0xc0
[   18.392648]  ? __pfx_kthread+0x10/0x10
[   18.392672]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.392702]  ? calculate_sigpending+0x7b/0xa0
[   18.392733]  ? __pfx_kthread+0x10/0x10
[   18.392758]  ret_from_fork+0x41/0x80
[   18.392789]  ? __pfx_kthread+0x10/0x10
[   18.392814]  ret_from_fork_asm+0x1a/0x30
[   18.392856]  </TASK>
[   18.392871] 
[   18.413861] Allocated by task 178:
[   18.414387]  kasan_save_stack+0x45/0x70
[   18.415812]  kasan_save_track+0x18/0x40
[   18.416314]  kasan_save_alloc_info+0x3b/0x50
[   18.416696]  __kasan_krealloc+0x190/0x1f0
[   18.417029]  krealloc_noprof+0xf3/0x340
[   18.417947]  krealloc_less_oob_helper+0x1aa/0x11d0
[   18.418872]  krealloc_less_oob+0x1c/0x30
[   18.419903]  kunit_try_run_case+0x1a5/0x480
[   18.420627]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.421089]  kthread+0x337/0x6f0
[   18.421860]  ret_from_fork+0x41/0x80
[   18.422636]  ret_from_fork_asm+0x1a/0x30
[   18.423346] 
[   18.423909] The buggy address belongs to the object at ffff888100aab400
[   18.423909]  which belongs to the cache kmalloc-256 of size 256
[   18.425156] The buggy address is located 7 bytes to the right of
[   18.425156]  allocated 201-byte region [ffff888100aab400, ffff888100aab4c9)
[   18.426119] 
[   18.426677] The buggy address belongs to the physical page:
[   18.427952] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa
[   18.428841] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.429601] flags: 0x200000000000040(head|node=0|zone=2)
[   18.430360] page_type: f5(slab)
[   18.431035] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.432121] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.432689] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.433988] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.434801] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff
[   18.436197] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002
[   18.436732] page dumped because: kasan: bad access detected
[   18.437489] 
[   18.437885] Memory state around the buggy address:
[   18.438630]  ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.439215]  ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.440445] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc
[   18.441184]                                                  ^
[   18.441731]  ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.442672]  ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.443906] ==================================================================
[   18.330771] ==================================================================
[   18.331433] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd70/0x11d0
[   18.331721] Write of size 1 at addr ffff888100aab4c9 by task kunit_try_catch/178
[   18.331979] 
[   18.332165] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.332282] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.332341] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.332393] Call Trace:
[   18.332429]  <TASK>
[   18.332480]  dump_stack_lvl+0x73/0xb0
[   18.332567]  print_report+0xd1/0x650
[   18.332645]  ? __virt_addr_valid+0x1db/0x2d0
[   18.332722]  ? krealloc_less_oob_helper+0xd70/0x11d0
[   18.332793]  ? kasan_complete_mode_report_info+0x2a/0x200
[   18.333721]  ? krealloc_less_oob_helper+0xd70/0x11d0
[   18.333801]  kasan_report+0x141/0x180
[   18.333875]  ? krealloc_less_oob_helper+0xd70/0x11d0
[   18.334143]  __asan_report_store1_noabort+0x1b/0x30
[   18.334221]  krealloc_less_oob_helper+0xd70/0x11d0
[   18.334262]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.334321]  ? finish_task_switch.isra.0+0x153/0x700
[   18.334364]  ? __switch_to+0x5d9/0xf60
[   18.334395]  ? dequeue_task_fair+0x166/0x4e0
[   18.334429]  ? __schedule+0x10cc/0x2b60
[   18.334462]  ? __pfx_read_tsc+0x10/0x10
[   18.334497]  krealloc_less_oob+0x1c/0x30
[   18.334524]  kunit_try_run_case+0x1a5/0x480
[   18.334561]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.334593]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.334628]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.334661]  ? __kthread_parkme+0x82/0x180
[   18.334692]  ? preempt_count_sub+0x50/0x80
[   18.334725]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.334759]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.334791]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.334823]  kthread+0x337/0x6f0
[   18.334847]  ? trace_preempt_on+0x20/0xc0
[   18.334882]  ? __pfx_kthread+0x10/0x10
[   18.334906]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.334936]  ? calculate_sigpending+0x7b/0xa0
[   18.335065]  ? __pfx_kthread+0x10/0x10
[   18.335122]  ret_from_fork+0x41/0x80
[   18.335163]  ? __pfx_kthread+0x10/0x10
[   18.335192]  ret_from_fork_asm+0x1a/0x30
[   18.335239]  </TASK>
[   18.335255] 
[   18.356112] Allocated by task 178:
[   18.356586]  kasan_save_stack+0x45/0x70
[   18.357001]  kasan_save_track+0x18/0x40
[   18.357573]  kasan_save_alloc_info+0x3b/0x50
[   18.357900]  __kasan_krealloc+0x190/0x1f0
[   18.358375]  krealloc_noprof+0xf3/0x340
[   18.359018]  krealloc_less_oob_helper+0x1aa/0x11d0
[   18.359980]  krealloc_less_oob+0x1c/0x30
[   18.360680]  kunit_try_run_case+0x1a5/0x480
[   18.361116]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.361646]  kthread+0x337/0x6f0
[   18.362023]  ret_from_fork+0x41/0x80
[   18.363663]  ret_from_fork_asm+0x1a/0x30
[   18.364657] 
[   18.365241] The buggy address belongs to the object at ffff888100aab400
[   18.365241]  which belongs to the cache kmalloc-256 of size 256
[   18.366637] The buggy address is located 0 bytes to the right of
[   18.366637]  allocated 201-byte region [ffff888100aab400, ffff888100aab4c9)
[   18.368118] 
[   18.368349] The buggy address belongs to the physical page:
[   18.368866] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa
[   18.370012] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.370677] flags: 0x200000000000040(head|node=0|zone=2)
[   18.371444] page_type: f5(slab)
[   18.371658] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.371927] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.373646] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.374583] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.375595] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff
[   18.376401] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002
[   18.377766] page dumped because: kasan: bad access detected
[   18.377995] 
[   18.378357] Memory state around the buggy address:
[   18.379621]  ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.380897]  ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.382152] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc
[   18.382684]                                               ^
[   18.383802]  ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.384854]  ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.385551] ==================================================================
[   18.712628] ==================================================================
[   18.714389] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd70/0x11d0
[   18.715431] Write of size 1 at addr ffff8881029f60c9 by task kunit_try_catch/182
[   18.715981] 
[   18.717031] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.717487] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.717515] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.717550] Call Trace:
[   18.717573]  <TASK>
[   18.717599]  dump_stack_lvl+0x73/0xb0
[   18.717644]  print_report+0xd1/0x650
[   18.717681]  ? __virt_addr_valid+0x1db/0x2d0
[   18.717716]  ? krealloc_less_oob_helper+0xd70/0x11d0
[   18.717747]  ? kasan_addr_to_slab+0x11/0xa0
[   18.717778]  ? krealloc_less_oob_helper+0xd70/0x11d0
[   18.717809]  kasan_report+0x141/0x180
[   18.717844]  ? krealloc_less_oob_helper+0xd70/0x11d0
[   18.717880]  __asan_report_store1_noabort+0x1b/0x30
[   18.717911]  krealloc_less_oob_helper+0xd70/0x11d0
[   18.717946]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.718439]  ? finish_task_switch.isra.0+0x153/0x700
[   18.718486]  ? __switch_to+0x5d9/0xf60
[   18.718519]  ? dequeue_task_fair+0x166/0x4e0
[   18.718556]  ? __schedule+0x10cc/0x2b60
[   18.718592]  ? __pfx_read_tsc+0x10/0x10
[   18.718629]  krealloc_large_less_oob+0x1c/0x30
[   18.718658]  kunit_try_run_case+0x1a5/0x480
[   18.718698]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.718733]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.718770]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.718805]  ? __kthread_parkme+0x82/0x180
[   18.718838]  ? preempt_count_sub+0x50/0x80
[   18.718873]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.718908]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.718942]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.719048]  kthread+0x337/0x6f0
[   18.719111]  ? trace_preempt_on+0x20/0xc0
[   18.719152]  ? __pfx_kthread+0x10/0x10
[   18.719178]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.719210]  ? calculate_sigpending+0x7b/0xa0
[   18.719241]  ? __pfx_kthread+0x10/0x10
[   18.719266]  ret_from_fork+0x41/0x80
[   18.719323]  ? __pfx_kthread+0x10/0x10
[   18.719352]  ret_from_fork_asm+0x1a/0x30
[   18.719398]  </TASK>
[   18.719414] 
[   18.741751] The buggy address belongs to the physical page:
[   18.742801] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4
[   18.743738] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.744666] flags: 0x200000000000040(head|node=0|zone=2)
[   18.745145] page_type: f8(unknown)
[   18.745721] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.746328] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.746922] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.747723] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.749549] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff
[   18.750447] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   18.751508] page dumped because: kasan: bad access detected
[   18.752266] 
[   18.752457] Memory state around the buggy address:
[   18.753812]  ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.754823]  ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.755411] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   18.756532]                                               ^
[   18.757313]  ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.758029]  ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.759831] ==================================================================
[   18.762032] ==================================================================
[   18.762610] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe23/0x11d0
[   18.763526] Write of size 1 at addr ffff8881029f60d0 by task kunit_try_catch/182
[   18.764742] 
[   18.765037] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.765172] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.765499] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.765540] Call Trace:
[   18.765561]  <TASK>
[   18.765585]  dump_stack_lvl+0x73/0xb0
[   18.765627]  print_report+0xd1/0x650
[   18.765664]  ? __virt_addr_valid+0x1db/0x2d0
[   18.765696]  ? krealloc_less_oob_helper+0xe23/0x11d0
[   18.765725]  ? kasan_addr_to_slab+0x11/0xa0
[   18.765757]  ? krealloc_less_oob_helper+0xe23/0x11d0
[   18.765787]  kasan_report+0x141/0x180
[   18.765821]  ? krealloc_less_oob_helper+0xe23/0x11d0
[   18.765857]  __asan_report_store1_noabort+0x1b/0x30
[   18.765888]  krealloc_less_oob_helper+0xe23/0x11d0
[   18.765922]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.765963]  ? finish_task_switch.isra.0+0x153/0x700
[   18.766104]  ? __switch_to+0x5d9/0xf60
[   18.766139]  ? dequeue_task_fair+0x166/0x4e0
[   18.766178]  ? __schedule+0x10cc/0x2b60
[   18.766214]  ? __pfx_read_tsc+0x10/0x10
[   18.766251]  krealloc_large_less_oob+0x1c/0x30
[   18.766280]  kunit_try_run_case+0x1a5/0x480
[   18.766343]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.766380]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.766416]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.766452]  ? __kthread_parkme+0x82/0x180
[   18.766485]  ? preempt_count_sub+0x50/0x80
[   18.766521]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.766557]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.766590]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.766626]  kthread+0x337/0x6f0
[   18.766652]  ? trace_preempt_on+0x20/0xc0
[   18.766688]  ? __pfx_kthread+0x10/0x10
[   18.766715]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.766748]  ? calculate_sigpending+0x7b/0xa0
[   18.766781]  ? __pfx_kthread+0x10/0x10
[   18.766806]  ret_from_fork+0x41/0x80
[   18.766838]  ? __pfx_kthread+0x10/0x10
[   18.766864]  ret_from_fork_asm+0x1a/0x30
[   18.766908]  </TASK>
[   18.766923] 
[   18.787364] The buggy address belongs to the physical page:
[   18.787742] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4
[   18.788185] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.792063] flags: 0x200000000000040(head|node=0|zone=2)
[   18.793930] page_type: f8(unknown)
[   18.794986] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.795540] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.795981] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.796463] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.796857] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff
[   18.797242] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   18.798817] page dumped because: kasan: bad access detected
[   18.799279] 
[   18.799504] Memory state around the buggy address:
[   18.799975]  ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.800953]  ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.801413] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   18.803752]                                                  ^
[   18.805133]  ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.805938]  ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.806843] ==================================================================
[   18.446262] ==================================================================
[   18.446859] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xec6/0x11d0
[   18.447905] Write of size 1 at addr ffff888100aab4da by task kunit_try_catch/178
[   18.448636] 
[   18.448866] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.448991] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.449047] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.449104] Call Trace:
[   18.449141]  <TASK>
[   18.449186]  dump_stack_lvl+0x73/0xb0
[   18.449265]  print_report+0xd1/0x650
[   18.449362]  ? __virt_addr_valid+0x1db/0x2d0
[   18.449440]  ? krealloc_less_oob_helper+0xec6/0x11d0
[   18.449509]  ? kasan_complete_mode_report_info+0x2a/0x200
[   18.449584]  ? krealloc_less_oob_helper+0xec6/0x11d0
[   18.449658]  kasan_report+0x141/0x180
[   18.449739]  ? krealloc_less_oob_helper+0xec6/0x11d0
[   18.449824]  __asan_report_store1_noabort+0x1b/0x30
[   18.449894]  krealloc_less_oob_helper+0xec6/0x11d0
[   18.449967]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.450035]  ? finish_task_switch.isra.0+0x153/0x700
[   18.450106]  ? __switch_to+0x5d9/0xf60
[   18.450165]  ? dequeue_task_fair+0x166/0x4e0
[   18.450241]  ? __schedule+0x10cc/0x2b60
[   18.450403]  ? __pfx_read_tsc+0x10/0x10
[   18.450461]  krealloc_less_oob+0x1c/0x30
[   18.450492]  kunit_try_run_case+0x1a5/0x480
[   18.450533]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.450568]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.450607]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.450643]  ? __kthread_parkme+0x82/0x180
[   18.450677]  ? preempt_count_sub+0x50/0x80
[   18.450713]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.450748]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.450785]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.450822]  kthread+0x337/0x6f0
[   18.450847]  ? trace_preempt_on+0x20/0xc0
[   18.450885]  ? __pfx_kthread+0x10/0x10
[   18.450911]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.450944]  ? calculate_sigpending+0x7b/0xa0
[   18.450977]  ? __pfx_kthread+0x10/0x10
[   18.451004]  ret_from_fork+0x41/0x80
[   18.451046]  ? __pfx_kthread+0x10/0x10
[   18.451076]  ret_from_fork_asm+0x1a/0x30
[   18.451120]  </TASK>
[   18.451136] 
[   18.474849] Allocated by task 178:
[   18.476112]  kasan_save_stack+0x45/0x70
[   18.476471]  kasan_save_track+0x18/0x40
[   18.476860]  kasan_save_alloc_info+0x3b/0x50
[   18.477657]  __kasan_krealloc+0x190/0x1f0
[   18.478042]  krealloc_noprof+0xf3/0x340
[   18.479060]  krealloc_less_oob_helper+0x1aa/0x11d0
[   18.479614]  krealloc_less_oob+0x1c/0x30
[   18.479948]  kunit_try_run_case+0x1a5/0x480
[   18.480630]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.481033]  kthread+0x337/0x6f0
[   18.481427]  ret_from_fork+0x41/0x80
[   18.481762]  ret_from_fork_asm+0x1a/0x30
[   18.482392] 
[   18.482724] The buggy address belongs to the object at ffff888100aab400
[   18.482724]  which belongs to the cache kmalloc-256 of size 256
[   18.485024] The buggy address is located 17 bytes to the right of
[   18.485024]  allocated 201-byte region [ffff888100aab400, ffff888100aab4c9)
[   18.486775] 
[   18.486962] The buggy address belongs to the physical page:
[   18.487943] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa
[   18.488683] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.489318] flags: 0x200000000000040(head|node=0|zone=2)
[   18.489802] page_type: f5(slab)
[   18.490594] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.491964] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.492850] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.493817] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.494945] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff
[   18.495753] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002
[   18.496988] page dumped because: kasan: bad access detected
[   18.497842] 
[   18.498211] Memory state around the buggy address:
[   18.498899]  ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.500170]  ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.501231] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc
[   18.501718]                                                     ^
[   18.502502]  ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.503643]  ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.504203] ==================================================================
[   18.807903] ==================================================================
[   18.808828] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xec6/0x11d0
[   18.810839] Write of size 1 at addr ffff8881029f60da by task kunit_try_catch/182
[   18.812631] 
[   18.813082] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.813213] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.813252] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.813326] Call Trace:
[   18.813370]  <TASK>
[   18.813398]  dump_stack_lvl+0x73/0xb0
[   18.813483]  print_report+0xd1/0x650
[   18.813524]  ? __virt_addr_valid+0x1db/0x2d0
[   18.813558]  ? krealloc_less_oob_helper+0xec6/0x11d0
[   18.813589]  ? kasan_addr_to_slab+0x11/0xa0
[   18.813623]  ? krealloc_less_oob_helper+0xec6/0x11d0
[   18.813654]  kasan_report+0x141/0x180
[   18.813690]  ? krealloc_less_oob_helper+0xec6/0x11d0
[   18.813728]  __asan_report_store1_noabort+0x1b/0x30
[   18.813760]  krealloc_less_oob_helper+0xec6/0x11d0
[   18.813793]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.813824]  ? finish_task_switch.isra.0+0x153/0x700
[   18.813860]  ? __switch_to+0x5d9/0xf60
[   18.813891]  ? dequeue_task_fair+0x166/0x4e0
[   18.813925]  ? __schedule+0x10cc/0x2b60
[   18.814225]  ? __pfx_read_tsc+0x10/0x10
[   18.814279]  krealloc_large_less_oob+0x1c/0x30
[   18.814341]  kunit_try_run_case+0x1a5/0x480
[   18.814383]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.814417]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.814453]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.814488]  ? __kthread_parkme+0x82/0x180
[   18.814520]  ? preempt_count_sub+0x50/0x80
[   18.814556]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.814591]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.814624]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.814658]  kthread+0x337/0x6f0
[   18.814684]  ? trace_preempt_on+0x20/0xc0
[   18.814721]  ? __pfx_kthread+0x10/0x10
[   18.814748]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.814780]  ? calculate_sigpending+0x7b/0xa0
[   18.814813]  ? __pfx_kthread+0x10/0x10
[   18.814840]  ret_from_fork+0x41/0x80
[   18.814872]  ? __pfx_kthread+0x10/0x10
[   18.814898]  ret_from_fork_asm+0x1a/0x30
[   18.814944]  </TASK>
[   18.814977] 
[   18.839384] The buggy address belongs to the physical page:
[   18.840588] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4
[   18.841962] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.842597] flags: 0x200000000000040(head|node=0|zone=2)
[   18.843040] page_type: f8(unknown)
[   18.843517] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.844959] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.845652] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.845917] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.847739] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff
[   18.848838] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   18.849655] page dumped because: kasan: bad access detected
[   18.850070] 
[   18.850317] Memory state around the buggy address:
[   18.850763]  ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.852098]  ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.852866] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   18.854107]                                                     ^
[   18.854755]  ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.855716]  ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.856627] ==================================================================
[   18.566602] ==================================================================
[   18.567257] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd47/0x11d0
[   18.568429] Write of size 1 at addr ffff888100aab4eb by task kunit_try_catch/178
[   18.569077] 
[   18.569371] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.569506] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.569568] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.569600] Call Trace:
[   18.569630]  <TASK>
[   18.569678]  dump_stack_lvl+0x73/0xb0
[   18.569733]  print_report+0xd1/0x650
[   18.569771]  ? __virt_addr_valid+0x1db/0x2d0
[   18.569804]  ? krealloc_less_oob_helper+0xd47/0x11d0
[   18.569833]  ? kasan_complete_mode_report_info+0x2a/0x200
[   18.569867]  ? krealloc_less_oob_helper+0xd47/0x11d0
[   18.569898]  kasan_report+0x141/0x180
[   18.569931]  ? krealloc_less_oob_helper+0xd47/0x11d0
[   18.569968]  __asan_report_store1_noabort+0x1b/0x30
[   18.569999]  krealloc_less_oob_helper+0xd47/0x11d0
[   18.570040]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.570096]  ? finish_task_switch.isra.0+0x153/0x700
[   18.570135]  ? __switch_to+0x5d9/0xf60
[   18.570166]  ? dequeue_task_fair+0x166/0x4e0
[   18.570201]  ? __schedule+0x10cc/0x2b60
[   18.570237]  ? __pfx_read_tsc+0x10/0x10
[   18.570274]  krealloc_less_oob+0x1c/0x30
[   18.570345]  kunit_try_run_case+0x1a5/0x480
[   18.570427]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.570495]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.570566]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.570635]  ? __kthread_parkme+0x82/0x180
[   18.570706]  ? preempt_count_sub+0x50/0x80
[   18.570782]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.570857]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.570934]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.571010]  kthread+0x337/0x6f0
[   18.571055]  ? trace_preempt_on+0x20/0xc0
[   18.571112]  ? __pfx_kthread+0x10/0x10
[   18.571141]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.571175]  ? calculate_sigpending+0x7b/0xa0
[   18.571209]  ? __pfx_kthread+0x10/0x10
[   18.571237]  ret_from_fork+0x41/0x80
[   18.571270]  ? __pfx_kthread+0x10/0x10
[   18.571323]  ret_from_fork_asm+0x1a/0x30
[   18.571370]  </TASK>
[   18.571386] 
[   18.591399] Allocated by task 178:
[   18.591787]  kasan_save_stack+0x45/0x70
[   18.592188]  kasan_save_track+0x18/0x40
[   18.592624]  kasan_save_alloc_info+0x3b/0x50
[   18.593077]  __kasan_krealloc+0x190/0x1f0
[   18.593708]  krealloc_noprof+0xf3/0x340
[   18.594039]  krealloc_less_oob_helper+0x1aa/0x11d0
[   18.594453]  krealloc_less_oob+0x1c/0x30
[   18.594774]  kunit_try_run_case+0x1a5/0x480
[   18.595429]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.595811]  kthread+0x337/0x6f0
[   18.596748]  ret_from_fork+0x41/0x80
[   18.597172]  ret_from_fork_asm+0x1a/0x30
[   18.598031] 
[   18.598281] The buggy address belongs to the object at ffff888100aab400
[   18.598281]  which belongs to the cache kmalloc-256 of size 256
[   18.599204] The buggy address is located 34 bytes to the right of
[   18.599204]  allocated 201-byte region [ffff888100aab400, ffff888100aab4c9)
[   18.600141] 
[   18.600464] The buggy address belongs to the physical page:
[   18.601542] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa
[   18.602505] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.602962] flags: 0x200000000000040(head|node=0|zone=2)
[   18.603412] page_type: f5(slab)
[   18.603767] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.604485] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.605790] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.606550] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.607496] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff
[   18.608363] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002
[   18.608903] page dumped because: kasan: bad access detected
[   18.609461] 
[   18.609646] Memory state around the buggy address:
[   18.610084]  ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.610689]  ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.611468] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc
[   18.612110]                                                           ^
[   18.612545]  ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.613230]  ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.613955] ==================================================================
[   18.505792] ==================================================================
[   18.506502] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe90/0x11d0
[   18.507653] Write of size 1 at addr ffff888100aab4ea by task kunit_try_catch/178
[   18.509443] 
[   18.509642] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.509769] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.509806] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.509863] Call Trace:
[   18.509917]  <TASK>
[   18.509989]  dump_stack_lvl+0x73/0xb0
[   18.510079]  print_report+0xd1/0x650
[   18.510156]  ? __virt_addr_valid+0x1db/0x2d0
[   18.510228]  ? krealloc_less_oob_helper+0xe90/0x11d0
[   18.510339]  ? kasan_complete_mode_report_info+0x2a/0x200
[   18.510435]  ? krealloc_less_oob_helper+0xe90/0x11d0
[   18.510506]  kasan_report+0x141/0x180
[   18.510541]  ? krealloc_less_oob_helper+0xe90/0x11d0
[   18.510578]  __asan_report_store1_noabort+0x1b/0x30
[   18.510612]  krealloc_less_oob_helper+0xe90/0x11d0
[   18.510644]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.510673]  ? finish_task_switch.isra.0+0x153/0x700
[   18.510708]  ? __switch_to+0x5d9/0xf60
[   18.510736]  ? dequeue_task_fair+0x166/0x4e0
[   18.510770]  ? __schedule+0x10cc/0x2b60
[   18.510804]  ? __pfx_read_tsc+0x10/0x10
[   18.510841]  krealloc_less_oob+0x1c/0x30
[   18.510867]  kunit_try_run_case+0x1a5/0x480
[   18.510905]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.510936]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.511035]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.511113]  ? __kthread_parkme+0x82/0x180
[   18.511150]  ? preempt_count_sub+0x50/0x80
[   18.511185]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.511221]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.511256]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.511314]  kthread+0x337/0x6f0
[   18.511343]  ? trace_preempt_on+0x20/0xc0
[   18.511380]  ? __pfx_kthread+0x10/0x10
[   18.511405]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.511435]  ? calculate_sigpending+0x7b/0xa0
[   18.511466]  ? __pfx_kthread+0x10/0x10
[   18.511490]  ret_from_fork+0x41/0x80
[   18.511521]  ? __pfx_kthread+0x10/0x10
[   18.511546]  ret_from_fork_asm+0x1a/0x30
[   18.511589]  </TASK>
[   18.511604] 
[   18.534967] Allocated by task 178:
[   18.536210]  kasan_save_stack+0x45/0x70
[   18.537676]  kasan_save_track+0x18/0x40
[   18.538457]  kasan_save_alloc_info+0x3b/0x50
[   18.539282]  __kasan_krealloc+0x190/0x1f0
[   18.540184]  krealloc_noprof+0xf3/0x340
[   18.540631]  krealloc_less_oob_helper+0x1aa/0x11d0
[   18.541370]  krealloc_less_oob+0x1c/0x30
[   18.541774]  kunit_try_run_case+0x1a5/0x480
[   18.542565]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.543007]  kthread+0x337/0x6f0
[   18.543557]  ret_from_fork+0x41/0x80
[   18.543968]  ret_from_fork_asm+0x1a/0x30
[   18.544643] 
[   18.544866] The buggy address belongs to the object at ffff888100aab400
[   18.544866]  which belongs to the cache kmalloc-256 of size 256
[   18.545840] The buggy address is located 33 bytes to the right of
[   18.545840]  allocated 201-byte region [ffff888100aab400, ffff888100aab4c9)
[   18.547073] 
[   18.547420] The buggy address belongs to the physical page:
[   18.547837] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa
[   18.549594] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.550498] flags: 0x200000000000040(head|node=0|zone=2)
[   18.550949] page_type: f5(slab)
[   18.551702] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.552798] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.553853] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000
[   18.554437] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000
[   18.554987] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff
[   18.556526] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002
[   18.557713] page dumped because: kasan: bad access detected
[   18.558401] 
[   18.558632] Memory state around the buggy address:
[   18.559275]  ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.560432]  ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.560983] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc
[   18.561506]                                                           ^
[   18.562054]  ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.562865]  ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   18.563581] ==================================================================
[   18.903171] ==================================================================
[   18.904787] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd47/0x11d0
[   18.905666] Write of size 1 at addr ffff8881029f60eb by task kunit_try_catch/182
[   18.906716] 
[   18.906929] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G    B            N  6.15.3-rc1 #1 PREEMPT(voluntary) 
[   18.907048] Tainted: [B]=BAD_PAGE, [N]=TEST
[   18.907086] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   18.907142] Call Trace:
[   18.907542]  <TASK>
[   18.907575]  dump_stack_lvl+0x73/0xb0
[   18.907619]  print_report+0xd1/0x650
[   18.907656]  ? __virt_addr_valid+0x1db/0x2d0
[   18.907689]  ? krealloc_less_oob_helper+0xd47/0x11d0
[   18.907718]  ? kasan_addr_to_slab+0x11/0xa0
[   18.907749]  ? krealloc_less_oob_helper+0xd47/0x11d0
[   18.907781]  kasan_report+0x141/0x180
[   18.907815]  ? krealloc_less_oob_helper+0xd47/0x11d0
[   18.907852]  __asan_report_store1_noabort+0x1b/0x30
[   18.907893]  krealloc_less_oob_helper+0xd47/0x11d0
[   18.907927]  ? __pfx_krealloc_less_oob_helper+0x10/0x10
[   18.907970]  ? finish_task_switch.isra.0+0x153/0x700
[   18.908430]  ? __switch_to+0x5d9/0xf60
[   18.908464]  ? dequeue_task_fair+0x166/0x4e0
[   18.908502]  ? __schedule+0x10cc/0x2b60
[   18.908536]  ? __pfx_read_tsc+0x10/0x10
[   18.908572]  krealloc_large_less_oob+0x1c/0x30
[   18.908602]  kunit_try_run_case+0x1a5/0x480
[   18.908640]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.908674]  ? _raw_spin_lock_irqsave+0xa1/0x100
[   18.908709]  ? _raw_spin_unlock_irqrestore+0x5f/0x90
[   18.908745]  ? __kthread_parkme+0x82/0x180
[   18.908777]  ? preempt_count_sub+0x50/0x80
[   18.908814]  ? __pfx_kunit_try_run_case+0x10/0x10
[   18.908849]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   18.908884]  ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10
[   18.908918]  kthread+0x337/0x6f0
[   18.908944]  ? trace_preempt_on+0x20/0xc0
[   18.909020]  ? __pfx_kthread+0x10/0x10
[   18.909090]  ? _raw_spin_unlock_irq+0x47/0x80
[   18.909140]  ? calculate_sigpending+0x7b/0xa0
[   18.909175]  ? __pfx_kthread+0x10/0x10
[   18.909201]  ret_from_fork+0x41/0x80
[   18.909234]  ? __pfx_kthread+0x10/0x10
[   18.909261]  ret_from_fork_asm+0x1a/0x30
[   18.909328]  </TASK>
[   18.909346] 
[   18.932319] The buggy address belongs to the physical page:
[   18.932796] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4
[   18.934438] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   18.935310] flags: 0x200000000000040(head|node=0|zone=2)
[   18.935827] page_type: f8(unknown)
[   18.936214] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.936806] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.937933] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000
[   18.938888] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000
[   18.940335] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff
[   18.941409] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004
[   18.942235] page dumped because: kasan: bad access detected
[   18.942678] 
[   18.942901] Memory state around the buggy address:
[   18.943795]  ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.945141]  ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   18.945640] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe
[   18.946439]                                                           ^
[   18.947267]  ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.947955]  ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe
[   18.948673] ==================================================================