Hay
Date
July 8, 2025, 4:38 p.m.

Environment
qemu-arm64
qemu-x86_64

[   51.785199] ==================================================================
[   51.785259] BUG: KFENCE: use-after-free read in test_krealloc+0x51c/0x830
[   51.785259] 
[   51.785355] Use-after-free read at 0x0000000018d671a8 (in kfence-#158):
[   51.785408]  test_krealloc+0x51c/0x830
[   51.785452]  kunit_try_run_case+0x170/0x3f0
[   51.785499]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   51.785546]  kthread+0x328/0x630
[   51.785589]  ret_from_fork+0x10/0x20
[   51.785631] 
[   51.785654] kfence-#158: 0x0000000018d671a8-0x00000000861d2852, size=32, cache=kmalloc-32
[   51.785654] 
[   51.785707] allocated by task 339 on cpu 1 at 51.784579s (0.001125s ago):
[   51.785776]  test_alloc+0x29c/0x628
[   51.785814]  test_krealloc+0xc0/0x830
[   51.785852]  kunit_try_run_case+0x170/0x3f0
[   51.785894]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   51.785939]  kthread+0x328/0x630
[   51.785980]  ret_from_fork+0x10/0x20
[   51.786019] 
[   51.786044] freed by task 339 on cpu 1 at 51.784826s (0.001215s ago):
[   51.786104]  krealloc_noprof+0x148/0x360
[   51.786145]  test_krealloc+0x1dc/0x830
[   51.786184]  kunit_try_run_case+0x170/0x3f0
[   51.786226]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   51.786271]  kthread+0x328/0x630
[   51.786311]  ret_from_fork+0x10/0x20
[   51.786361] 
[   51.786405] CPU: 1 UID: 0 PID: 339 Comm: kunit_try_catch Tainted: G    B            N  6.15.6-rc1 #1 PREEMPT 
[   51.786485] Tainted: [B]=BAD_PAGE, [N]=TEST
[   51.786516] Hardware name: linux,dummy-virt (DT)
[   51.786552] ==================================================================

[   47.885754] ==================================================================
[   47.886150] BUG: KFENCE: use-after-free read in test_krealloc+0x6fc/0xbe0
[   47.886150] 
[   47.886586] Use-after-free read at 0x(____ptrval____) (in kfence-#132):
[   47.887302]  test_krealloc+0x6fc/0xbe0
[   47.887498]  kunit_try_run_case+0x1a5/0x480
[   47.887915]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   47.888204]  kthread+0x337/0x6f0
[   47.888524]  ret_from_fork+0x41/0x80
[   47.888863]  ret_from_fork_asm+0x1a/0x30
[   47.889101] 
[   47.889185] kfence-#132: 0x(____ptrval____)-0x(____ptrval____), size=32, cache=kmalloc-32
[   47.889185] 
[   47.889816] allocated by task 357 on cpu 0 at 47.885118s (0.004695s ago):
[   47.890309]  test_alloc+0x364/0x10f0
[   47.890497]  test_krealloc+0xad/0xbe0
[   47.890828]  kunit_try_run_case+0x1a5/0x480
[   47.891143]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   47.891406]  kthread+0x337/0x6f0
[   47.891776]  ret_from_fork+0x41/0x80
[   47.892065]  ret_from_fork_asm+0x1a/0x30
[   47.892345] 
[   47.892461] freed by task 357 on cpu 0 at 47.885388s (0.007070s ago):
[   47.892912]  krealloc_noprof+0x108/0x340
[   47.893120]  test_krealloc+0x226/0xbe0
[   47.893442]  kunit_try_run_case+0x1a5/0x480
[   47.893776]  kunit_generic_run_threadfn_adapter+0x85/0xf0
[   47.894051]  kthread+0x337/0x6f0
[   47.894217]  ret_from_fork+0x41/0x80
[   47.894392]  ret_from_fork_asm+0x1a/0x30
[   47.894609] 
[   47.895013] CPU: 0 UID: 0 PID: 357 Comm: kunit_try_catch Tainted: G    B            N  6.15.6-rc1 #1 PREEMPT(voluntary) 
[   47.895540] Tainted: [B]=BAD_PAGE, [N]=TEST
[   47.895845] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   47.896326] ==================================================================