Hay
Date
July 1, 2025, 3:08 p.m.

Environment
qemu-arm64

[   19.999706] ==================================================================
[   19.999758] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x51c/0x5d0
[   19.999826] Read of size 1 at addr ffff8000800fe7f8 by task kunit_try_catch/270
[   19.999879] 
[   19.999910] CPU: 0 UID: 0 PID: 270 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc4 #1 PREEMPT 
[   20.000049] Tainted: [B]=BAD_PAGE, [N]=TEST
[   20.000084] Hardware name: linux,dummy-virt (DT)
[   20.000115] Call trace:
[   20.000138]  show_stack+0x20/0x38 (C)
[   20.000187]  dump_stack_lvl+0x8c/0xd0
[   20.000277]  print_report+0x310/0x608
[   20.000354]  kasan_report+0xdc/0x128
[   20.000419]  __asan_report_load1_noabort+0x20/0x30
[   20.000490]  vmalloc_oob+0x51c/0x5d0
[   20.000667]  kunit_try_run_case+0x170/0x3f0
[   20.000719]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   20.000795]  kthread+0x328/0x630
[   20.000848]  ret_from_fork+0x10/0x20
[   20.000913] 
[   20.000940] The buggy address belongs to the virtual mapping at
[   20.000940]  [ffff8000800fe000, ffff800080100000) created by:
[   20.000940]  vmalloc_oob+0x98/0x5d0
[   20.001016] 
[   20.001044] The buggy address belongs to the physical page:
[   20.001088] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x105785
[   20.001141] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   20.001202] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   20.001341] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   20.001393] page dumped because: kasan: bad access detected
[   20.001427] 
[   20.001463] Memory state around the buggy address:
[   20.001543]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   20.001637]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   20.001691] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   20.001774]                                                                 ^
[   20.001873]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   20.001926]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   20.001998] ==================================================================
[   19.996246] ==================================================================
[   19.996332] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x578/0x5d0
[   19.996393] Read of size 1 at addr ffff8000800fe7f3 by task kunit_try_catch/270
[   19.996445] 
[   19.996484] CPU: 0 UID: 0 PID: 270 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc4 #1 PREEMPT 
[   19.996582] Tainted: [B]=BAD_PAGE, [N]=TEST
[   19.996610] Hardware name: linux,dummy-virt (DT)
[   19.996646] Call trace:
[   19.996670]  show_stack+0x20/0x38 (C)
[   19.996770]  dump_stack_lvl+0x8c/0xd0
[   19.996821]  print_report+0x310/0x608
[   19.996868]  kasan_report+0xdc/0x128
[   19.996915]  __asan_report_load1_noabort+0x20/0x30
[   19.996966]  vmalloc_oob+0x578/0x5d0
[   19.997011]  kunit_try_run_case+0x170/0x3f0
[   19.997060]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   19.997115]  kthread+0x328/0x630
[   19.997480]  ret_from_fork+0x10/0x20
[   19.997624] 
[   19.997661] The buggy address belongs to the virtual mapping at
[   19.997661]  [ffff8000800fe000, ffff800080100000) created by:
[   19.997661]  vmalloc_oob+0x98/0x5d0
[   19.997776] 
[   19.997826] The buggy address belongs to the physical page:
[   19.997896] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x105785
[   19.997955] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   19.998043] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   19.998098] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   19.998143] page dumped because: kasan: bad access detected
[   19.998178] 
[   19.998344] Memory state around the buggy address:
[   19.998381]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   19.998428]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   19.998554] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   19.998657]                                                              ^
[   19.998754]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   19.998833]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   19.998930] ==================================================================