Hay
Date
July 4, 2025, 3:11 p.m.

Environment
qemu-arm64

[   15.675636] ==================================================================
[   15.676495] BUG: KFENCE: use-after-free write in __memset+0xc/0x20
[   15.676495] 
[   15.676925] Use-after-free write at 0x00000000c02c8890 (in kfence-#57):
[   15.677575]  __memset+0xc/0x20
[   15.677616]  kmalloc_uaf_memset+0x170/0x310
[   15.677900]  kunit_try_run_case+0x170/0x3f0
[   15.677995]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   15.678170]  kthread+0x328/0x630
[   15.678242]  ret_from_fork+0x10/0x20
[   15.678403] 
[   15.678885] kfence-#57: 0x00000000c02c8890-0x0000000004de3278, size=33, cache=kmalloc-64
[   15.678885] 
[   15.679922] allocated by task 191 on cpu 0 at 15.673777s (0.005932s ago):
[   15.681348]  kmalloc_uaf_memset+0xb8/0x310
[   15.681541]  kunit_try_run_case+0x170/0x3f0
[   15.681761]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   15.681815]  kthread+0x328/0x630
[   15.681851]  ret_from_fork+0x10/0x20
[   15.681999] 
[   15.682161] freed by task 191 on cpu 0 at 15.673839s (0.008221s ago):
[   15.682362]  kmalloc_uaf_memset+0x11c/0x310
[   15.682412]  kunit_try_run_case+0x170/0x3f0
[   15.682449]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   15.682493]  kthread+0x328/0x630
[   15.682536]  ret_from_fork+0x10/0x20
[   15.682590] 
[   15.682671] CPU: 0 UID: 0 PID: 191 Comm: kunit_try_catch Tainted: G    B            N  6.15.5-rc2 #1 PREEMPT 
[   15.682926] Tainted: [B]=BAD_PAGE, [N]=TEST
[   15.683183] Hardware name: linux,dummy-virt (DT)
[   15.683271] ==================================================================