Hay
Date
Feb. 5, 2025, 2:09 p.m.

Environment
qemu-arm64

[  181.295841] ==================================================================
[  181.298655] BUG: KASAN: alloca-out-of-bounds in kasan_alloca_oob_right+0x114/0x200
[  181.300398] Read of size 1 at addr ffff8000807f7c2a by task kunit_try_catch/188
[  181.302012] 
[  181.302857] CPU: 0 PID: 188 Comm: kunit_try_catch Tainted: G    B            N 6.6.76-rc1 #1
[  181.305682] Hardware name: linux,dummy-virt (DT)
[  181.306740] Call trace:
[  181.307606]  dump_backtrace+0x9c/0x128
[  181.308616]  show_stack+0x20/0x38
[  181.309773]  dump_stack_lvl+0x60/0xb0
[  181.311194]  print_report+0x314/0x5d8
[  181.312316]  kasan_report+0xc8/0x118
[  181.313451]  __asan_load1+0x60/0x70
[  181.314805]  kasan_alloca_oob_right+0x114/0x200
[  181.315867]  kunit_try_run_case+0xf8/0x260
[  181.317259]  kunit_generic_run_threadfn_adapter+0x38/0x60
[  181.319060]  kthread+0x18c/0x1a8
[  181.319935]  ret_from_fork+0x10/0x20
[  181.321111] 
[  181.321566] The buggy address belongs to stack of task kunit_try_catch/188
[  181.323442] 
[  181.324072] The buggy address belongs to the virtual mapping at
[  181.324072]  [ffff8000807f0000, ffff8000807f9000) created by:
[  181.324072]  kernel_clone+0xf8/0x540
[  181.327525] 
[  181.328139] The buggy address belongs to the physical page:
[  181.329473] page:000000007d50f7e6 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x106053
[  181.331724] flags: 0xbfffc0000000000(node=0|zone=2|lastcpupid=0xffff)
[  181.333310] page_type: 0xffffffff()
[  181.334667] raw: 0bfffc0000000000 0000000000000000 dead000000000122 0000000000000000
[  181.336359] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[  181.338017] page dumped because: kasan: bad access detected
[  181.339351] 
[  181.340178] Memory state around the buggy address:
[  181.341102]  ffff8000807f7b00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[  181.343073]  ffff8000807f7b80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[  181.344746] >ffff8000807f7c00: ca ca ca ca 00 02 cb cb cb cb cb cb f1 f1 f1 f1
[  181.346154]                                   ^
[  181.348066]  ffff8000807f7c80: 01 f2 04 f2 00 f2 f2 f2 00 00 f3 f3 00 00 00 00
[  181.349907]  ffff8000807f7d00: 00 00 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1
[  181.351522] ==================================================================