Date
June 17, 2025, 3:40 p.m.
Environment | |
---|---|
qemu-arm64 | |
qemu-x86_64 |
[ 21.487259] ================================================================== [ 21.487402] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xb9c/0xc50 [ 21.487544] Write of size 1 at addr fff00000c78920d0 by task kunit_try_catch/164 [ 21.487655] [ 21.487766] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT [ 21.487971] Tainted: [B]=BAD_PAGE, [N]=TEST [ 21.488035] Hardware name: linux,dummy-virt (DT) [ 21.488116] Call trace: [ 21.488175] show_stack+0x20/0x38 (C) [ 21.488292] dump_stack_lvl+0x8c/0xd0 [ 21.488404] print_report+0x118/0x608 [ 21.488511] kasan_report+0xdc/0x128 [ 21.488614] __asan_report_store1_noabort+0x20/0x30 [ 21.489451] krealloc_less_oob_helper+0xb9c/0xc50 [ 21.489697] krealloc_large_less_oob+0x20/0x38 [ 21.490024] kunit_try_run_case+0x170/0x3f0 [ 21.490212] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 21.490557] kthread+0x328/0x630 [ 21.490691] ret_from_fork+0x10/0x20 [ 21.490856] [ 21.490903] The buggy address belongs to the physical page: [ 21.491052] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890 [ 21.491234] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 21.491582] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 21.491828] page_type: f8(unknown) [ 21.491968] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.492152] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.492688] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.493166] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.493392] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff [ 21.493602] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 21.493819] page dumped because: kasan: bad access detected [ 21.493906] [ 21.494123] Memory state around the buggy address: [ 21.494209] fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.494313] fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.494408] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 21.494494] ^ [ 21.494710] fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.494921] fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.495084] ================================================================== [ 21.465691] ================================================================== [ 21.466470] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xa48/0xc50 [ 21.466655] Write of size 1 at addr fff00000c78920c9 by task kunit_try_catch/164 [ 21.466774] [ 21.466870] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT [ 21.467076] Tainted: [B]=BAD_PAGE, [N]=TEST [ 21.467152] Hardware name: linux,dummy-virt (DT) [ 21.467264] Call trace: [ 21.467318] show_stack+0x20/0x38 (C) [ 21.467439] dump_stack_lvl+0x8c/0xd0 [ 21.467552] print_report+0x118/0x608 [ 21.467657] kasan_report+0xdc/0x128 [ 21.467775] __asan_report_store1_noabort+0x20/0x30 [ 21.467910] krealloc_less_oob_helper+0xa48/0xc50 [ 21.468080] krealloc_large_less_oob+0x20/0x38 [ 21.468259] kunit_try_run_case+0x170/0x3f0 [ 21.468398] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 21.469105] kthread+0x328/0x630 [ 21.469286] ret_from_fork+0x10/0x20 [ 21.469427] [ 21.469492] The buggy address belongs to the physical page: [ 21.469590] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890 [ 21.469799] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 21.469913] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 21.470071] page_type: f8(unknown) [ 21.470789] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.470914] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.471032] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.471157] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.471280] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff [ 21.473315] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 21.473952] page dumped because: kasan: bad access detected [ 21.474047] [ 21.474091] Memory state around the buggy address: [ 21.474172] fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.474833] fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.475398] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 21.477156] ^ [ 21.478003] fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.478453] fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.478537] ================================================================== [ 21.500321] ================================================================== [ 21.500458] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xa80/0xc50 [ 21.500599] Write of size 1 at addr fff00000c78920da by task kunit_try_catch/164 [ 21.500723] [ 21.501498] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT [ 21.501791] Tainted: [B]=BAD_PAGE, [N]=TEST [ 21.501846] Hardware name: linux,dummy-virt (DT) [ 21.502162] Call trace: [ 21.502242] show_stack+0x20/0x38 (C) [ 21.502540] dump_stack_lvl+0x8c/0xd0 [ 21.502803] print_report+0x118/0x608 [ 21.503064] kasan_report+0xdc/0x128 [ 21.503305] __asan_report_store1_noabort+0x20/0x30 [ 21.503447] krealloc_less_oob_helper+0xa80/0xc50 [ 21.503832] krealloc_large_less_oob+0x20/0x38 [ 21.504338] kunit_try_run_case+0x170/0x3f0 [ 21.504615] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 21.504847] kthread+0x328/0x630 [ 21.504952] ret_from_fork+0x10/0x20 [ 21.505441] [ 21.505509] The buggy address belongs to the physical page: [ 21.505700] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890 [ 21.505987] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 21.506389] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 21.506557] page_type: f8(unknown) [ 21.506675] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.506795] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.507070] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.507320] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.507618] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff [ 21.508132] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 21.508244] page dumped because: kasan: bad access detected [ 21.508433] [ 21.508486] Memory state around the buggy address: [ 21.508876] fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.508987] fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.509203] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 21.509400] ^ [ 21.509605] fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.509972] fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.510087] ================================================================== [ 21.511744] ================================================================== [ 21.511862] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xae4/0xc50 [ 21.511993] Write of size 1 at addr fff00000c78920ea by task kunit_try_catch/164 [ 21.512122] [ 21.512213] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT [ 21.512412] Tainted: [B]=BAD_PAGE, [N]=TEST [ 21.512475] Hardware name: linux,dummy-virt (DT) [ 21.512553] Call trace: [ 21.512608] show_stack+0x20/0x38 (C) [ 21.512723] dump_stack_lvl+0x8c/0xd0 [ 21.514530] print_report+0x118/0x608 [ 21.514760] kasan_report+0xdc/0x128 [ 21.515526] __asan_report_store1_noabort+0x20/0x30 [ 21.515672] krealloc_less_oob_helper+0xae4/0xc50 [ 21.515914] krealloc_large_less_oob+0x20/0x38 [ 21.516055] kunit_try_run_case+0x170/0x3f0 [ 21.516639] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 21.516903] kthread+0x328/0x630 [ 21.517129] ret_from_fork+0x10/0x20 [ 21.517350] [ 21.517427] The buggy address belongs to the physical page: [ 21.517608] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890 [ 21.517987] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 21.518102] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 21.518220] page_type: f8(unknown) [ 21.518402] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.518656] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.518888] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.519349] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.519644] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff [ 21.519893] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 21.520218] page dumped because: kasan: bad access detected [ 21.520390] [ 21.520454] Memory state around the buggy address: [ 21.520634] fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.520746] fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.521079] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 21.521304] ^ [ 21.521507] fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.521778] fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.521915] ================================================================== [ 21.523828] ================================================================== [ 21.523955] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xa58/0xc50 [ 21.524078] Write of size 1 at addr fff00000c78920eb by task kunit_try_catch/164 [ 21.524219] [ 21.524338] CPU: 0 UID: 0 PID: 164 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT [ 21.524566] Tainted: [B]=BAD_PAGE, [N]=TEST [ 21.524633] Hardware name: linux,dummy-virt (DT) [ 21.524706] Call trace: [ 21.524772] show_stack+0x20/0x38 (C) [ 21.524897] dump_stack_lvl+0x8c/0xd0 [ 21.525011] print_report+0x118/0x608 [ 21.525121] kasan_report+0xdc/0x128 [ 21.525228] __asan_report_store1_noabort+0x20/0x30 [ 21.525369] krealloc_less_oob_helper+0xa58/0xc50 [ 21.525497] krealloc_large_less_oob+0x20/0x38 [ 21.526184] kunit_try_run_case+0x170/0x3f0 [ 21.526370] kunit_generic_run_threadfn_adapter+0x88/0x100 [ 21.526508] kthread+0x328/0x630 [ 21.526624] ret_from_fork+0x10/0x20 [ 21.526767] [ 21.526819] The buggy address belongs to the physical page: [ 21.526956] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x107890 [ 21.527070] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 21.527173] flags: 0xbfffe0000000040(head|node=0|zone=2|lastcpupid=0x1ffff) [ 21.527392] page_type: f8(unknown) [ 21.527484] raw: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.527848] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.527983] head: 0bfffe0000000040 0000000000000000 dead000000000122 0000000000000000 [ 21.528114] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 21.528239] head: 0bfffe0000000002 ffffc1ffc31e2401 00000000ffffffff 00000000ffffffff [ 21.528356] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 21.528460] page dumped because: kasan: bad access detected [ 21.528537] [ 21.528580] Memory state around the buggy address: [ 21.528665] fff00000c7891f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.528785] fff00000c7892000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 21.528893] >fff00000c7892080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 21.528991] ^ [ 21.529091] fff00000c7892100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.529203] fff00000c7892180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 21.529297] ==================================================================
[ 18.858148] ================================================================== [ 18.859453] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe90/0x11d0 [ 18.860361] Write of size 1 at addr ffff8881029f60ea by task kunit_try_catch/182 [ 18.861682] [ 18.861878] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.861967] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.862009] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.862061] Call Trace: [ 18.862233] <TASK> [ 18.862301] dump_stack_lvl+0x73/0xb0 [ 18.862360] print_report+0xd1/0x650 [ 18.862399] ? __virt_addr_valid+0x1db/0x2d0 [ 18.862431] ? krealloc_less_oob_helper+0xe90/0x11d0 [ 18.862462] ? kasan_addr_to_slab+0x11/0xa0 [ 18.862495] ? krealloc_less_oob_helper+0xe90/0x11d0 [ 18.862525] kasan_report+0x141/0x180 [ 18.862559] ? krealloc_less_oob_helper+0xe90/0x11d0 [ 18.862598] __asan_report_store1_noabort+0x1b/0x30 [ 18.862630] krealloc_less_oob_helper+0xe90/0x11d0 [ 18.862663] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.862694] ? finish_task_switch.isra.0+0x153/0x700 [ 18.862727] ? __switch_to+0x5d9/0xf60 [ 18.862756] ? dequeue_task_fair+0x166/0x4e0 [ 18.862792] ? __schedule+0x10cc/0x2b60 [ 18.862826] ? __pfx_read_tsc+0x10/0x10 [ 18.862862] krealloc_large_less_oob+0x1c/0x30 [ 18.862891] kunit_try_run_case+0x1a5/0x480 [ 18.862928] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.863157] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.863212] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.863251] ? __kthread_parkme+0x82/0x180 [ 18.863303] ? preempt_count_sub+0x50/0x80 [ 18.863350] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.863387] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.863422] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.863457] kthread+0x337/0x6f0 [ 18.863482] ? trace_preempt_on+0x20/0xc0 [ 18.863519] ? __pfx_kthread+0x10/0x10 [ 18.863546] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.863578] ? calculate_sigpending+0x7b/0xa0 [ 18.863610] ? __pfx_kthread+0x10/0x10 [ 18.863636] ret_from_fork+0x41/0x80 [ 18.863668] ? __pfx_kthread+0x10/0x10 [ 18.863694] ret_from_fork_asm+0x1a/0x30 [ 18.863739] </TASK> [ 18.863755] [ 18.887305] The buggy address belongs to the physical page: [ 18.887864] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4 [ 18.889475] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.890363] flags: 0x200000000000040(head|node=0|zone=2) [ 18.891050] page_type: f8(unknown) [ 18.891559] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.892523] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.893076] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.894607] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.895531] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff [ 18.896393] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 18.897126] page dumped because: kasan: bad access detected [ 18.897609] [ 18.897826] Memory state around the buggy address: [ 18.898515] ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.898833] ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.899434] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 18.899696] ^ [ 18.899936] ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.901706] ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.902281] ================================================================== [ 18.387819] ================================================================== [ 18.388652] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe23/0x11d0 [ 18.389854] Write of size 1 at addr ffff888100aab4d0 by task kunit_try_catch/178 [ 18.390487] [ 18.390765] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.390868] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.390888] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.390917] Call Trace: [ 18.390935] <TASK> [ 18.390958] dump_stack_lvl+0x73/0xb0 [ 18.391090] print_report+0xd1/0x650 [ 18.391188] ? __virt_addr_valid+0x1db/0x2d0 [ 18.391261] ? krealloc_less_oob_helper+0xe23/0x11d0 [ 18.391347] ? kasan_complete_mode_report_info+0x2a/0x200 [ 18.391420] ? krealloc_less_oob_helper+0xe23/0x11d0 [ 18.391487] kasan_report+0x141/0x180 [ 18.391552] ? krealloc_less_oob_helper+0xe23/0x11d0 [ 18.391631] __asan_report_store1_noabort+0x1b/0x30 [ 18.391702] krealloc_less_oob_helper+0xe23/0x11d0 [ 18.391777] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.391904] ? finish_task_switch.isra.0+0x153/0x700 [ 18.392089] ? __switch_to+0x5d9/0xf60 [ 18.392126] ? dequeue_task_fair+0x166/0x4e0 [ 18.392162] ? __schedule+0x10cc/0x2b60 [ 18.392196] ? __pfx_read_tsc+0x10/0x10 [ 18.392231] krealloc_less_oob+0x1c/0x30 [ 18.392258] kunit_try_run_case+0x1a5/0x480 [ 18.392319] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.392355] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.392391] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.392426] ? __kthread_parkme+0x82/0x180 [ 18.392458] ? preempt_count_sub+0x50/0x80 [ 18.392492] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.392526] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.392559] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.392592] kthread+0x337/0x6f0 [ 18.392615] ? trace_preempt_on+0x20/0xc0 [ 18.392648] ? __pfx_kthread+0x10/0x10 [ 18.392672] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.392702] ? calculate_sigpending+0x7b/0xa0 [ 18.392733] ? __pfx_kthread+0x10/0x10 [ 18.392758] ret_from_fork+0x41/0x80 [ 18.392789] ? __pfx_kthread+0x10/0x10 [ 18.392814] ret_from_fork_asm+0x1a/0x30 [ 18.392856] </TASK> [ 18.392871] [ 18.413861] Allocated by task 178: [ 18.414387] kasan_save_stack+0x45/0x70 [ 18.415812] kasan_save_track+0x18/0x40 [ 18.416314] kasan_save_alloc_info+0x3b/0x50 [ 18.416696] __kasan_krealloc+0x190/0x1f0 [ 18.417029] krealloc_noprof+0xf3/0x340 [ 18.417947] krealloc_less_oob_helper+0x1aa/0x11d0 [ 18.418872] krealloc_less_oob+0x1c/0x30 [ 18.419903] kunit_try_run_case+0x1a5/0x480 [ 18.420627] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.421089] kthread+0x337/0x6f0 [ 18.421860] ret_from_fork+0x41/0x80 [ 18.422636] ret_from_fork_asm+0x1a/0x30 [ 18.423346] [ 18.423909] The buggy address belongs to the object at ffff888100aab400 [ 18.423909] which belongs to the cache kmalloc-256 of size 256 [ 18.425156] The buggy address is located 7 bytes to the right of [ 18.425156] allocated 201-byte region [ffff888100aab400, ffff888100aab4c9) [ 18.426119] [ 18.426677] The buggy address belongs to the physical page: [ 18.427952] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa [ 18.428841] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.429601] flags: 0x200000000000040(head|node=0|zone=2) [ 18.430360] page_type: f5(slab) [ 18.431035] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.432121] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.432689] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.433988] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.434801] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff [ 18.436197] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002 [ 18.436732] page dumped because: kasan: bad access detected [ 18.437489] [ 18.437885] Memory state around the buggy address: [ 18.438630] ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.439215] ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.440445] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc [ 18.441184] ^ [ 18.441731] ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.442672] ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.443906] ================================================================== [ 18.330771] ================================================================== [ 18.331433] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd70/0x11d0 [ 18.331721] Write of size 1 at addr ffff888100aab4c9 by task kunit_try_catch/178 [ 18.331979] [ 18.332165] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.332282] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.332341] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.332393] Call Trace: [ 18.332429] <TASK> [ 18.332480] dump_stack_lvl+0x73/0xb0 [ 18.332567] print_report+0xd1/0x650 [ 18.332645] ? __virt_addr_valid+0x1db/0x2d0 [ 18.332722] ? krealloc_less_oob_helper+0xd70/0x11d0 [ 18.332793] ? kasan_complete_mode_report_info+0x2a/0x200 [ 18.333721] ? krealloc_less_oob_helper+0xd70/0x11d0 [ 18.333801] kasan_report+0x141/0x180 [ 18.333875] ? krealloc_less_oob_helper+0xd70/0x11d0 [ 18.334143] __asan_report_store1_noabort+0x1b/0x30 [ 18.334221] krealloc_less_oob_helper+0xd70/0x11d0 [ 18.334262] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.334321] ? finish_task_switch.isra.0+0x153/0x700 [ 18.334364] ? __switch_to+0x5d9/0xf60 [ 18.334395] ? dequeue_task_fair+0x166/0x4e0 [ 18.334429] ? __schedule+0x10cc/0x2b60 [ 18.334462] ? __pfx_read_tsc+0x10/0x10 [ 18.334497] krealloc_less_oob+0x1c/0x30 [ 18.334524] kunit_try_run_case+0x1a5/0x480 [ 18.334561] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.334593] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.334628] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.334661] ? __kthread_parkme+0x82/0x180 [ 18.334692] ? preempt_count_sub+0x50/0x80 [ 18.334725] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.334759] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.334791] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.334823] kthread+0x337/0x6f0 [ 18.334847] ? trace_preempt_on+0x20/0xc0 [ 18.334882] ? __pfx_kthread+0x10/0x10 [ 18.334906] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.334936] ? calculate_sigpending+0x7b/0xa0 [ 18.335065] ? __pfx_kthread+0x10/0x10 [ 18.335122] ret_from_fork+0x41/0x80 [ 18.335163] ? __pfx_kthread+0x10/0x10 [ 18.335192] ret_from_fork_asm+0x1a/0x30 [ 18.335239] </TASK> [ 18.335255] [ 18.356112] Allocated by task 178: [ 18.356586] kasan_save_stack+0x45/0x70 [ 18.357001] kasan_save_track+0x18/0x40 [ 18.357573] kasan_save_alloc_info+0x3b/0x50 [ 18.357900] __kasan_krealloc+0x190/0x1f0 [ 18.358375] krealloc_noprof+0xf3/0x340 [ 18.359018] krealloc_less_oob_helper+0x1aa/0x11d0 [ 18.359980] krealloc_less_oob+0x1c/0x30 [ 18.360680] kunit_try_run_case+0x1a5/0x480 [ 18.361116] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.361646] kthread+0x337/0x6f0 [ 18.362023] ret_from_fork+0x41/0x80 [ 18.363663] ret_from_fork_asm+0x1a/0x30 [ 18.364657] [ 18.365241] The buggy address belongs to the object at ffff888100aab400 [ 18.365241] which belongs to the cache kmalloc-256 of size 256 [ 18.366637] The buggy address is located 0 bytes to the right of [ 18.366637] allocated 201-byte region [ffff888100aab400, ffff888100aab4c9) [ 18.368118] [ 18.368349] The buggy address belongs to the physical page: [ 18.368866] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa [ 18.370012] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.370677] flags: 0x200000000000040(head|node=0|zone=2) [ 18.371444] page_type: f5(slab) [ 18.371658] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.371927] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.373646] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.374583] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.375595] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff [ 18.376401] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002 [ 18.377766] page dumped because: kasan: bad access detected [ 18.377995] [ 18.378357] Memory state around the buggy address: [ 18.379621] ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.380897] ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.382152] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc [ 18.382684] ^ [ 18.383802] ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.384854] ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.385551] ================================================================== [ 18.712628] ================================================================== [ 18.714389] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd70/0x11d0 [ 18.715431] Write of size 1 at addr ffff8881029f60c9 by task kunit_try_catch/182 [ 18.715981] [ 18.717031] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.717487] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.717515] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.717550] Call Trace: [ 18.717573] <TASK> [ 18.717599] dump_stack_lvl+0x73/0xb0 [ 18.717644] print_report+0xd1/0x650 [ 18.717681] ? __virt_addr_valid+0x1db/0x2d0 [ 18.717716] ? krealloc_less_oob_helper+0xd70/0x11d0 [ 18.717747] ? kasan_addr_to_slab+0x11/0xa0 [ 18.717778] ? krealloc_less_oob_helper+0xd70/0x11d0 [ 18.717809] kasan_report+0x141/0x180 [ 18.717844] ? krealloc_less_oob_helper+0xd70/0x11d0 [ 18.717880] __asan_report_store1_noabort+0x1b/0x30 [ 18.717911] krealloc_less_oob_helper+0xd70/0x11d0 [ 18.717946] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.718439] ? finish_task_switch.isra.0+0x153/0x700 [ 18.718486] ? __switch_to+0x5d9/0xf60 [ 18.718519] ? dequeue_task_fair+0x166/0x4e0 [ 18.718556] ? __schedule+0x10cc/0x2b60 [ 18.718592] ? __pfx_read_tsc+0x10/0x10 [ 18.718629] krealloc_large_less_oob+0x1c/0x30 [ 18.718658] kunit_try_run_case+0x1a5/0x480 [ 18.718698] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.718733] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.718770] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.718805] ? __kthread_parkme+0x82/0x180 [ 18.718838] ? preempt_count_sub+0x50/0x80 [ 18.718873] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.718908] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.718942] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.719048] kthread+0x337/0x6f0 [ 18.719111] ? trace_preempt_on+0x20/0xc0 [ 18.719152] ? __pfx_kthread+0x10/0x10 [ 18.719178] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.719210] ? calculate_sigpending+0x7b/0xa0 [ 18.719241] ? __pfx_kthread+0x10/0x10 [ 18.719266] ret_from_fork+0x41/0x80 [ 18.719323] ? __pfx_kthread+0x10/0x10 [ 18.719352] ret_from_fork_asm+0x1a/0x30 [ 18.719398] </TASK> [ 18.719414] [ 18.741751] The buggy address belongs to the physical page: [ 18.742801] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4 [ 18.743738] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.744666] flags: 0x200000000000040(head|node=0|zone=2) [ 18.745145] page_type: f8(unknown) [ 18.745721] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.746328] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.746922] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.747723] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.749549] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff [ 18.750447] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 18.751508] page dumped because: kasan: bad access detected [ 18.752266] [ 18.752457] Memory state around the buggy address: [ 18.753812] ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.754823] ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.755411] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 18.756532] ^ [ 18.757313] ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.758029] ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.759831] ================================================================== [ 18.762032] ================================================================== [ 18.762610] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe23/0x11d0 [ 18.763526] Write of size 1 at addr ffff8881029f60d0 by task kunit_try_catch/182 [ 18.764742] [ 18.765037] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.765172] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.765499] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.765540] Call Trace: [ 18.765561] <TASK> [ 18.765585] dump_stack_lvl+0x73/0xb0 [ 18.765627] print_report+0xd1/0x650 [ 18.765664] ? __virt_addr_valid+0x1db/0x2d0 [ 18.765696] ? krealloc_less_oob_helper+0xe23/0x11d0 [ 18.765725] ? kasan_addr_to_slab+0x11/0xa0 [ 18.765757] ? krealloc_less_oob_helper+0xe23/0x11d0 [ 18.765787] kasan_report+0x141/0x180 [ 18.765821] ? krealloc_less_oob_helper+0xe23/0x11d0 [ 18.765857] __asan_report_store1_noabort+0x1b/0x30 [ 18.765888] krealloc_less_oob_helper+0xe23/0x11d0 [ 18.765922] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.765963] ? finish_task_switch.isra.0+0x153/0x700 [ 18.766104] ? __switch_to+0x5d9/0xf60 [ 18.766139] ? dequeue_task_fair+0x166/0x4e0 [ 18.766178] ? __schedule+0x10cc/0x2b60 [ 18.766214] ? __pfx_read_tsc+0x10/0x10 [ 18.766251] krealloc_large_less_oob+0x1c/0x30 [ 18.766280] kunit_try_run_case+0x1a5/0x480 [ 18.766343] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.766380] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.766416] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.766452] ? __kthread_parkme+0x82/0x180 [ 18.766485] ? preempt_count_sub+0x50/0x80 [ 18.766521] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.766557] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.766590] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.766626] kthread+0x337/0x6f0 [ 18.766652] ? trace_preempt_on+0x20/0xc0 [ 18.766688] ? __pfx_kthread+0x10/0x10 [ 18.766715] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.766748] ? calculate_sigpending+0x7b/0xa0 [ 18.766781] ? __pfx_kthread+0x10/0x10 [ 18.766806] ret_from_fork+0x41/0x80 [ 18.766838] ? __pfx_kthread+0x10/0x10 [ 18.766864] ret_from_fork_asm+0x1a/0x30 [ 18.766908] </TASK> [ 18.766923] [ 18.787364] The buggy address belongs to the physical page: [ 18.787742] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4 [ 18.788185] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.792063] flags: 0x200000000000040(head|node=0|zone=2) [ 18.793930] page_type: f8(unknown) [ 18.794986] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.795540] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.795981] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.796463] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.796857] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff [ 18.797242] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 18.798817] page dumped because: kasan: bad access detected [ 18.799279] [ 18.799504] Memory state around the buggy address: [ 18.799975] ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.800953] ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.801413] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 18.803752] ^ [ 18.805133] ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.805938] ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.806843] ================================================================== [ 18.446262] ================================================================== [ 18.446859] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xec6/0x11d0 [ 18.447905] Write of size 1 at addr ffff888100aab4da by task kunit_try_catch/178 [ 18.448636] [ 18.448866] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.448991] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.449047] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.449104] Call Trace: [ 18.449141] <TASK> [ 18.449186] dump_stack_lvl+0x73/0xb0 [ 18.449265] print_report+0xd1/0x650 [ 18.449362] ? __virt_addr_valid+0x1db/0x2d0 [ 18.449440] ? krealloc_less_oob_helper+0xec6/0x11d0 [ 18.449509] ? kasan_complete_mode_report_info+0x2a/0x200 [ 18.449584] ? krealloc_less_oob_helper+0xec6/0x11d0 [ 18.449658] kasan_report+0x141/0x180 [ 18.449739] ? krealloc_less_oob_helper+0xec6/0x11d0 [ 18.449824] __asan_report_store1_noabort+0x1b/0x30 [ 18.449894] krealloc_less_oob_helper+0xec6/0x11d0 [ 18.449967] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.450035] ? finish_task_switch.isra.0+0x153/0x700 [ 18.450106] ? __switch_to+0x5d9/0xf60 [ 18.450165] ? dequeue_task_fair+0x166/0x4e0 [ 18.450241] ? __schedule+0x10cc/0x2b60 [ 18.450403] ? __pfx_read_tsc+0x10/0x10 [ 18.450461] krealloc_less_oob+0x1c/0x30 [ 18.450492] kunit_try_run_case+0x1a5/0x480 [ 18.450533] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.450568] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.450607] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.450643] ? __kthread_parkme+0x82/0x180 [ 18.450677] ? preempt_count_sub+0x50/0x80 [ 18.450713] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.450748] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.450785] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.450822] kthread+0x337/0x6f0 [ 18.450847] ? trace_preempt_on+0x20/0xc0 [ 18.450885] ? __pfx_kthread+0x10/0x10 [ 18.450911] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.450944] ? calculate_sigpending+0x7b/0xa0 [ 18.450977] ? __pfx_kthread+0x10/0x10 [ 18.451004] ret_from_fork+0x41/0x80 [ 18.451046] ? __pfx_kthread+0x10/0x10 [ 18.451076] ret_from_fork_asm+0x1a/0x30 [ 18.451120] </TASK> [ 18.451136] [ 18.474849] Allocated by task 178: [ 18.476112] kasan_save_stack+0x45/0x70 [ 18.476471] kasan_save_track+0x18/0x40 [ 18.476860] kasan_save_alloc_info+0x3b/0x50 [ 18.477657] __kasan_krealloc+0x190/0x1f0 [ 18.478042] krealloc_noprof+0xf3/0x340 [ 18.479060] krealloc_less_oob_helper+0x1aa/0x11d0 [ 18.479614] krealloc_less_oob+0x1c/0x30 [ 18.479948] kunit_try_run_case+0x1a5/0x480 [ 18.480630] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.481033] kthread+0x337/0x6f0 [ 18.481427] ret_from_fork+0x41/0x80 [ 18.481762] ret_from_fork_asm+0x1a/0x30 [ 18.482392] [ 18.482724] The buggy address belongs to the object at ffff888100aab400 [ 18.482724] which belongs to the cache kmalloc-256 of size 256 [ 18.485024] The buggy address is located 17 bytes to the right of [ 18.485024] allocated 201-byte region [ffff888100aab400, ffff888100aab4c9) [ 18.486775] [ 18.486962] The buggy address belongs to the physical page: [ 18.487943] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa [ 18.488683] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.489318] flags: 0x200000000000040(head|node=0|zone=2) [ 18.489802] page_type: f5(slab) [ 18.490594] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.491964] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.492850] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.493817] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.494945] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff [ 18.495753] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002 [ 18.496988] page dumped because: kasan: bad access detected [ 18.497842] [ 18.498211] Memory state around the buggy address: [ 18.498899] ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.500170] ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.501231] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc [ 18.501718] ^ [ 18.502502] ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.503643] ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.504203] ================================================================== [ 18.807903] ================================================================== [ 18.808828] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xec6/0x11d0 [ 18.810839] Write of size 1 at addr ffff8881029f60da by task kunit_try_catch/182 [ 18.812631] [ 18.813082] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.813213] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.813252] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.813326] Call Trace: [ 18.813370] <TASK> [ 18.813398] dump_stack_lvl+0x73/0xb0 [ 18.813483] print_report+0xd1/0x650 [ 18.813524] ? __virt_addr_valid+0x1db/0x2d0 [ 18.813558] ? krealloc_less_oob_helper+0xec6/0x11d0 [ 18.813589] ? kasan_addr_to_slab+0x11/0xa0 [ 18.813623] ? krealloc_less_oob_helper+0xec6/0x11d0 [ 18.813654] kasan_report+0x141/0x180 [ 18.813690] ? krealloc_less_oob_helper+0xec6/0x11d0 [ 18.813728] __asan_report_store1_noabort+0x1b/0x30 [ 18.813760] krealloc_less_oob_helper+0xec6/0x11d0 [ 18.813793] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.813824] ? finish_task_switch.isra.0+0x153/0x700 [ 18.813860] ? __switch_to+0x5d9/0xf60 [ 18.813891] ? dequeue_task_fair+0x166/0x4e0 [ 18.813925] ? __schedule+0x10cc/0x2b60 [ 18.814225] ? __pfx_read_tsc+0x10/0x10 [ 18.814279] krealloc_large_less_oob+0x1c/0x30 [ 18.814341] kunit_try_run_case+0x1a5/0x480 [ 18.814383] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.814417] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.814453] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.814488] ? __kthread_parkme+0x82/0x180 [ 18.814520] ? preempt_count_sub+0x50/0x80 [ 18.814556] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.814591] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.814624] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.814658] kthread+0x337/0x6f0 [ 18.814684] ? trace_preempt_on+0x20/0xc0 [ 18.814721] ? __pfx_kthread+0x10/0x10 [ 18.814748] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.814780] ? calculate_sigpending+0x7b/0xa0 [ 18.814813] ? __pfx_kthread+0x10/0x10 [ 18.814840] ret_from_fork+0x41/0x80 [ 18.814872] ? __pfx_kthread+0x10/0x10 [ 18.814898] ret_from_fork_asm+0x1a/0x30 [ 18.814944] </TASK> [ 18.814977] [ 18.839384] The buggy address belongs to the physical page: [ 18.840588] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4 [ 18.841962] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.842597] flags: 0x200000000000040(head|node=0|zone=2) [ 18.843040] page_type: f8(unknown) [ 18.843517] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.844959] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.845652] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.845917] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.847739] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff [ 18.848838] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 18.849655] page dumped because: kasan: bad access detected [ 18.850070] [ 18.850317] Memory state around the buggy address: [ 18.850763] ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.852098] ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.852866] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 18.854107] ^ [ 18.854755] ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.855716] ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.856627] ================================================================== [ 18.566602] ================================================================== [ 18.567257] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd47/0x11d0 [ 18.568429] Write of size 1 at addr ffff888100aab4eb by task kunit_try_catch/178 [ 18.569077] [ 18.569371] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.569506] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.569568] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.569600] Call Trace: [ 18.569630] <TASK> [ 18.569678] dump_stack_lvl+0x73/0xb0 [ 18.569733] print_report+0xd1/0x650 [ 18.569771] ? __virt_addr_valid+0x1db/0x2d0 [ 18.569804] ? krealloc_less_oob_helper+0xd47/0x11d0 [ 18.569833] ? kasan_complete_mode_report_info+0x2a/0x200 [ 18.569867] ? krealloc_less_oob_helper+0xd47/0x11d0 [ 18.569898] kasan_report+0x141/0x180 [ 18.569931] ? krealloc_less_oob_helper+0xd47/0x11d0 [ 18.569968] __asan_report_store1_noabort+0x1b/0x30 [ 18.569999] krealloc_less_oob_helper+0xd47/0x11d0 [ 18.570040] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.570096] ? finish_task_switch.isra.0+0x153/0x700 [ 18.570135] ? __switch_to+0x5d9/0xf60 [ 18.570166] ? dequeue_task_fair+0x166/0x4e0 [ 18.570201] ? __schedule+0x10cc/0x2b60 [ 18.570237] ? __pfx_read_tsc+0x10/0x10 [ 18.570274] krealloc_less_oob+0x1c/0x30 [ 18.570345] kunit_try_run_case+0x1a5/0x480 [ 18.570427] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.570495] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.570566] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.570635] ? __kthread_parkme+0x82/0x180 [ 18.570706] ? preempt_count_sub+0x50/0x80 [ 18.570782] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.570857] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.570934] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.571010] kthread+0x337/0x6f0 [ 18.571055] ? trace_preempt_on+0x20/0xc0 [ 18.571112] ? __pfx_kthread+0x10/0x10 [ 18.571141] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.571175] ? calculate_sigpending+0x7b/0xa0 [ 18.571209] ? __pfx_kthread+0x10/0x10 [ 18.571237] ret_from_fork+0x41/0x80 [ 18.571270] ? __pfx_kthread+0x10/0x10 [ 18.571323] ret_from_fork_asm+0x1a/0x30 [ 18.571370] </TASK> [ 18.571386] [ 18.591399] Allocated by task 178: [ 18.591787] kasan_save_stack+0x45/0x70 [ 18.592188] kasan_save_track+0x18/0x40 [ 18.592624] kasan_save_alloc_info+0x3b/0x50 [ 18.593077] __kasan_krealloc+0x190/0x1f0 [ 18.593708] krealloc_noprof+0xf3/0x340 [ 18.594039] krealloc_less_oob_helper+0x1aa/0x11d0 [ 18.594453] krealloc_less_oob+0x1c/0x30 [ 18.594774] kunit_try_run_case+0x1a5/0x480 [ 18.595429] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.595811] kthread+0x337/0x6f0 [ 18.596748] ret_from_fork+0x41/0x80 [ 18.597172] ret_from_fork_asm+0x1a/0x30 [ 18.598031] [ 18.598281] The buggy address belongs to the object at ffff888100aab400 [ 18.598281] which belongs to the cache kmalloc-256 of size 256 [ 18.599204] The buggy address is located 34 bytes to the right of [ 18.599204] allocated 201-byte region [ffff888100aab400, ffff888100aab4c9) [ 18.600141] [ 18.600464] The buggy address belongs to the physical page: [ 18.601542] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa [ 18.602505] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.602962] flags: 0x200000000000040(head|node=0|zone=2) [ 18.603412] page_type: f5(slab) [ 18.603767] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.604485] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.605790] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.606550] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.607496] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff [ 18.608363] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002 [ 18.608903] page dumped because: kasan: bad access detected [ 18.609461] [ 18.609646] Memory state around the buggy address: [ 18.610084] ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.610689] ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.611468] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc [ 18.612110] ^ [ 18.612545] ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.613230] ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.613955] ================================================================== [ 18.505792] ================================================================== [ 18.506502] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xe90/0x11d0 [ 18.507653] Write of size 1 at addr ffff888100aab4ea by task kunit_try_catch/178 [ 18.509443] [ 18.509642] CPU: 1 UID: 0 PID: 178 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.509769] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.509806] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.509863] Call Trace: [ 18.509917] <TASK> [ 18.509989] dump_stack_lvl+0x73/0xb0 [ 18.510079] print_report+0xd1/0x650 [ 18.510156] ? __virt_addr_valid+0x1db/0x2d0 [ 18.510228] ? krealloc_less_oob_helper+0xe90/0x11d0 [ 18.510339] ? kasan_complete_mode_report_info+0x2a/0x200 [ 18.510435] ? krealloc_less_oob_helper+0xe90/0x11d0 [ 18.510506] kasan_report+0x141/0x180 [ 18.510541] ? krealloc_less_oob_helper+0xe90/0x11d0 [ 18.510578] __asan_report_store1_noabort+0x1b/0x30 [ 18.510612] krealloc_less_oob_helper+0xe90/0x11d0 [ 18.510644] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.510673] ? finish_task_switch.isra.0+0x153/0x700 [ 18.510708] ? __switch_to+0x5d9/0xf60 [ 18.510736] ? dequeue_task_fair+0x166/0x4e0 [ 18.510770] ? __schedule+0x10cc/0x2b60 [ 18.510804] ? __pfx_read_tsc+0x10/0x10 [ 18.510841] krealloc_less_oob+0x1c/0x30 [ 18.510867] kunit_try_run_case+0x1a5/0x480 [ 18.510905] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.510936] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.511035] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.511113] ? __kthread_parkme+0x82/0x180 [ 18.511150] ? preempt_count_sub+0x50/0x80 [ 18.511185] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.511221] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.511256] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.511314] kthread+0x337/0x6f0 [ 18.511343] ? trace_preempt_on+0x20/0xc0 [ 18.511380] ? __pfx_kthread+0x10/0x10 [ 18.511405] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.511435] ? calculate_sigpending+0x7b/0xa0 [ 18.511466] ? __pfx_kthread+0x10/0x10 [ 18.511490] ret_from_fork+0x41/0x80 [ 18.511521] ? __pfx_kthread+0x10/0x10 [ 18.511546] ret_from_fork_asm+0x1a/0x30 [ 18.511589] </TASK> [ 18.511604] [ 18.534967] Allocated by task 178: [ 18.536210] kasan_save_stack+0x45/0x70 [ 18.537676] kasan_save_track+0x18/0x40 [ 18.538457] kasan_save_alloc_info+0x3b/0x50 [ 18.539282] __kasan_krealloc+0x190/0x1f0 [ 18.540184] krealloc_noprof+0xf3/0x340 [ 18.540631] krealloc_less_oob_helper+0x1aa/0x11d0 [ 18.541370] krealloc_less_oob+0x1c/0x30 [ 18.541774] kunit_try_run_case+0x1a5/0x480 [ 18.542565] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.543007] kthread+0x337/0x6f0 [ 18.543557] ret_from_fork+0x41/0x80 [ 18.543968] ret_from_fork_asm+0x1a/0x30 [ 18.544643] [ 18.544866] The buggy address belongs to the object at ffff888100aab400 [ 18.544866] which belongs to the cache kmalloc-256 of size 256 [ 18.545840] The buggy address is located 33 bytes to the right of [ 18.545840] allocated 201-byte region [ffff888100aab400, ffff888100aab4c9) [ 18.547073] [ 18.547420] The buggy address belongs to the physical page: [ 18.547837] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x100aaa [ 18.549594] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.550498] flags: 0x200000000000040(head|node=0|zone=2) [ 18.550949] page_type: f5(slab) [ 18.551702] raw: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.552798] raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.553853] head: 0200000000000040 ffff888100041b40 dead000000000122 0000000000000000 [ 18.554437] head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 [ 18.554987] head: 0200000000000001 ffffea000402aa81 00000000ffffffff 00000000ffffffff [ 18.556526] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000002 [ 18.557713] page dumped because: kasan: bad access detected [ 18.558401] [ 18.558632] Memory state around the buggy address: [ 18.559275] ffff888100aab380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.560432] ffff888100aab400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.560983] >ffff888100aab480: 00 00 00 00 00 00 00 00 00 01 fc fc fc fc fc fc [ 18.561506] ^ [ 18.562054] ffff888100aab500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.562865] ffff888100aab580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 18.563581] ================================================================== [ 18.903171] ================================================================== [ 18.904787] BUG: KASAN: slab-out-of-bounds in krealloc_less_oob_helper+0xd47/0x11d0 [ 18.905666] Write of size 1 at addr ffff8881029f60eb by task kunit_try_catch/182 [ 18.906716] [ 18.906929] CPU: 0 UID: 0 PID: 182 Comm: kunit_try_catch Tainted: G B N 6.15.3-rc1 #1 PREEMPT(voluntary) [ 18.907048] Tainted: [B]=BAD_PAGE, [N]=TEST [ 18.907086] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 18.907142] Call Trace: [ 18.907542] <TASK> [ 18.907575] dump_stack_lvl+0x73/0xb0 [ 18.907619] print_report+0xd1/0x650 [ 18.907656] ? __virt_addr_valid+0x1db/0x2d0 [ 18.907689] ? krealloc_less_oob_helper+0xd47/0x11d0 [ 18.907718] ? kasan_addr_to_slab+0x11/0xa0 [ 18.907749] ? krealloc_less_oob_helper+0xd47/0x11d0 [ 18.907781] kasan_report+0x141/0x180 [ 18.907815] ? krealloc_less_oob_helper+0xd47/0x11d0 [ 18.907852] __asan_report_store1_noabort+0x1b/0x30 [ 18.907893] krealloc_less_oob_helper+0xd47/0x11d0 [ 18.907927] ? __pfx_krealloc_less_oob_helper+0x10/0x10 [ 18.907970] ? finish_task_switch.isra.0+0x153/0x700 [ 18.908430] ? __switch_to+0x5d9/0xf60 [ 18.908464] ? dequeue_task_fair+0x166/0x4e0 [ 18.908502] ? __schedule+0x10cc/0x2b60 [ 18.908536] ? __pfx_read_tsc+0x10/0x10 [ 18.908572] krealloc_large_less_oob+0x1c/0x30 [ 18.908602] kunit_try_run_case+0x1a5/0x480 [ 18.908640] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.908674] ? _raw_spin_lock_irqsave+0xa1/0x100 [ 18.908709] ? _raw_spin_unlock_irqrestore+0x5f/0x90 [ 18.908745] ? __kthread_parkme+0x82/0x180 [ 18.908777] ? preempt_count_sub+0x50/0x80 [ 18.908814] ? __pfx_kunit_try_run_case+0x10/0x10 [ 18.908849] kunit_generic_run_threadfn_adapter+0x85/0xf0 [ 18.908884] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10 [ 18.908918] kthread+0x337/0x6f0 [ 18.908944] ? trace_preempt_on+0x20/0xc0 [ 18.909020] ? __pfx_kthread+0x10/0x10 [ 18.909090] ? _raw_spin_unlock_irq+0x47/0x80 [ 18.909140] ? calculate_sigpending+0x7b/0xa0 [ 18.909175] ? __pfx_kthread+0x10/0x10 [ 18.909201] ret_from_fork+0x41/0x80 [ 18.909234] ? __pfx_kthread+0x10/0x10 [ 18.909261] ret_from_fork_asm+0x1a/0x30 [ 18.909328] </TASK> [ 18.909346] [ 18.932319] The buggy address belongs to the physical page: [ 18.932796] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1029f4 [ 18.934438] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 18.935310] flags: 0x200000000000040(head|node=0|zone=2) [ 18.935827] page_type: f8(unknown) [ 18.936214] raw: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.936806] raw: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.937933] head: 0200000000000040 0000000000000000 dead000000000122 0000000000000000 [ 18.938888] head: 0000000000000000 0000000000000000 00000001f8000000 0000000000000000 [ 18.940335] head: 0200000000000002 ffffea00040a7d01 00000000ffffffff 00000000ffffffff [ 18.941409] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 [ 18.942235] page dumped because: kasan: bad access detected [ 18.942678] [ 18.942901] Memory state around the buggy address: [ 18.943795] ffff8881029f5f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.945141] ffff8881029f6000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 18.945640] >ffff8881029f6080: 00 00 00 00 00 00 00 00 00 01 fe fe fe fe fe fe [ 18.946439] ^ [ 18.947267] ffff8881029f6100: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.947955] ffff8881029f6180: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe [ 18.948673] ==================================================================