Hay
Date
July 3, 2025, 3:13 p.m.

Environment
qemu-arm64
qemu-x86_64

[   49.275603] ==================================================================
[   49.275692] BUG: KFENCE: use-after-free read in test_krealloc+0x51c/0x830
[   49.275692] 
[   49.275780] Use-after-free read at 0x00000000a20e83cf (in kfence-#154):
[   49.275832]  test_krealloc+0x51c/0x830
[   49.275874]  kunit_try_run_case+0x170/0x3f0
[   49.275922]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   49.275982]  kthread+0x328/0x630
[   49.276027]  ret_from_fork+0x10/0x20
[   49.276067] 
[   49.276090] kfence-#154: 0x00000000a20e83cf-0x000000002ade0885, size=32, cache=kmalloc-32
[   49.276090] 
[   49.276142] allocated by task 340 on cpu 0 at 49.274750s (0.001388s ago):
[   49.276212]  test_alloc+0x29c/0x628
[   49.276252]  test_krealloc+0xc0/0x830
[   49.276289]  kunit_try_run_case+0x170/0x3f0
[   49.276330]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   49.276376]  kthread+0x328/0x630
[   49.276413]  ret_from_fork+0x10/0x20
[   49.276451] 
[   49.276475] freed by task 340 on cpu 0 at 49.275201s (0.001270s ago):
[   49.276533]  krealloc_noprof+0x148/0x360
[   49.276571]  test_krealloc+0x1dc/0x830
[   49.276607]  kunit_try_run_case+0x170/0x3f0
[   49.276649]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   49.276695]  kthread+0x328/0x630
[   49.276733]  ret_from_fork+0x10/0x20
[   49.276772] 
[   49.276817] CPU: 0 UID: 0 PID: 340 Comm: kunit_try_catch Tainted: G    B            N  6.15.5-rc1 #1 PREEMPT 
[   49.276895] Tainted: [B]=BAD_PAGE, [N]=TEST
[   49.276924] Hardware name: linux,dummy-virt (DT)
[   49.276970] ==================================================================

[   47.882242] ==================================================================
[   47.882673] BUG: KFENCE: use-after-free read in test_krealloc+0x6fc/0xbe0
[   47.882673] 
[   47.883118] Use-after-free read at 0x(____ptrval____) (in kfence-#138):
[   47.883445]  test_krealloc+0x6fc/0xbe0
[   47.883687]  kunit_try_run_case+0x1a5/0x480
[   47.883916]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   47.884226]  kthread+0x337/0x6f0
[   47.884371]  ret_from_fork+0x41/0x80
[   47.884582]  ret_from_fork_asm+0x1a/0x30
[   47.884828] 
[   47.884950] kfence-#138: 0x(____ptrval____)-0x(____ptrval____), size=32, cache=kmalloc-32
[   47.884950] 
[   47.885501] allocated by task 357 on cpu 0 at 47.881592s (0.003905s ago):
[   47.885737]  test_alloc+0x364/0x10f0
[   47.885946]  test_krealloc+0xad/0xbe0
[   47.886149]  kunit_try_run_case+0x1a5/0x480
[   47.886361]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   47.886650]  kthread+0x337/0x6f0
[   47.886812]  ret_from_fork+0x41/0x80
[   47.886999]  ret_from_fork_asm+0x1a/0x30
[   47.887234] 
[   47.887350] freed by task 357 on cpu 0 at 47.881868s (0.005479s ago):
[   47.887649]  krealloc_noprof+0x108/0x340
[   47.887792]  test_krealloc+0x226/0xbe0
[   47.887928]  kunit_try_run_case+0x1a5/0x480
[   47.888229]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   47.888678]  kthread+0x337/0x6f0
[   47.888857]  ret_from_fork+0x41/0x80
[   47.889058]  ret_from_fork_asm+0x1a/0x30
[   47.889328] 
[   47.889430] CPU: 0 UID: 0 PID: 357 Comm: kunit_try_catch Tainted: G    B            N  6.15.5-rc1 #1 PREEMPT(voluntary) 
[   47.890023] Tainted: [B]=BAD_PAGE, [N]=TEST
[   47.890189] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   47.890614] ==================================================================