Hay
Date
June 17, 2025, 3:39 p.m.

Environment
qemu-arm64

[   96.206180] ==================================================================
[   96.208810] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0xc8/0x320
[   96.210036] Read of size 1 at addr ffff8000800fd7f3 by task kunit_try_catch/220
[   96.211467] 
[   96.211982] CPU: 1 PID: 220 Comm: kunit_try_catch Tainted: G    B            N 6.6.94-rc1 #1
[   96.213511] Hardware name: linux,dummy-virt (DT)
[   96.214340] Call trace:
[   96.214978]  dump_backtrace+0x9c/0x128
[   96.215953]  show_stack+0x20/0x38
[   96.217246]  dump_stack_lvl+0x60/0xb0
[   96.218111]  print_report+0x328/0x5e8
[   96.219231]  kasan_report+0xdc/0x128
[   96.219810]  __asan_load1+0x60/0x70
[   96.220356]  vmalloc_oob+0xc8/0x320
[   96.220870]  kunit_try_run_case+0x114/0x298
[   96.222226]  kunit_generic_run_threadfn_adapter+0x38/0x60
[   96.223299]  kthread+0x18c/0x1a8
[   96.223988]  ret_from_fork+0x10/0x20
[   96.224814] 
[   96.225326] The buggy address belongs to the virtual mapping at
[   96.225326]  [ffff8000800fd000, ffff8000800ff000) created by:
[   96.225326]  vmalloc_oob+0x88/0x320
[   96.227243] 
[   96.227729] The buggy address belongs to the physical page:
[   96.228896] page:00000000d3755588 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x10609b
[   96.230116] flags: 0xbfffc0000000000(node=0|zone=2|lastcpupid=0xffff)
[   96.231321] page_type: 0xffffffff()
[   96.232314] raw: 0bfffc0000000000 0000000000000000 dead000000000122 0000000000000000
[   96.233354] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   96.234086] page dumped because: kasan: bad access detected
[   96.235570] 
[   96.236378] Memory state around the buggy address:
[   96.237377]  ffff8000800fd680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   96.238544]  ffff8000800fd700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   96.239524] >ffff8000800fd780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   96.240475]                                                              ^
[   96.241785]  ffff8000800fd800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   96.242828]  ffff8000800fd880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   96.244001] ==================================================================
[   96.247891] ==================================================================
[   96.249065] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0xec/0x320
[   96.250098] Read of size 1 at addr ffff8000800fd7f8 by task kunit_try_catch/220
[   96.251616] 
[   96.252166] CPU: 1 PID: 220 Comm: kunit_try_catch Tainted: G    B            N 6.6.94-rc1 #1
[   96.253576] Hardware name: linux,dummy-virt (DT)
[   96.254346] Call trace:
[   96.255137]  dump_backtrace+0x9c/0x128
[   96.255933]  show_stack+0x20/0x38
[   96.256593]  dump_stack_lvl+0x60/0xb0
[   96.257763]  print_report+0x328/0x5e8
[   96.258477]  kasan_report+0xdc/0x128
[   96.259150]  __asan_load1+0x60/0x70
[   96.260481]  vmalloc_oob+0xec/0x320
[   96.261329]  kunit_try_run_case+0x114/0x298
[   96.262289]  kunit_generic_run_threadfn_adapter+0x38/0x60
[   96.263338]  kthread+0x18c/0x1a8
[   96.264028]  ret_from_fork+0x10/0x20
[   96.264826] 
[   96.265290] The buggy address belongs to the virtual mapping at
[   96.265290]  [ffff8000800fd000, ffff8000800ff000) created by:
[   96.265290]  vmalloc_oob+0x88/0x320
[   96.267581] 
[   96.268447] The buggy address belongs to the physical page:
[   96.269456] page:00000000d3755588 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x10609b
[   96.270739] flags: 0xbfffc0000000000(node=0|zone=2|lastcpupid=0xffff)
[   96.271645] page_type: 0xffffffff()
[   96.272671] raw: 0bfffc0000000000 0000000000000000 dead000000000122 0000000000000000
[   96.274015] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   96.275181] page dumped because: kasan: bad access detected
[   96.276624] 
[   96.277107] Memory state around the buggy address:
[   96.278024]  ffff8000800fd680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   96.279062]  ffff8000800fd700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   96.280113] >ffff8000800fd780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   96.281044]                                                                 ^
[   96.282301]  ffff8000800fd800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   96.284038]  ffff8000800fd880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   96.285115] ==================================================================