Hay
Date
July 1, 2025, 3:08 p.m.

Environment
qemu-arm64

[   16.936968] ==================================================================
[   16.937067] BUG: KFENCE: use-after-free read in __memcpy+0xc/0x30
[   16.937067] 
[   16.937154] Use-after-free read at 0x00000000dcf6472e (in kfence-#55):
[   16.938116]  __memcpy+0xc/0x30
[   16.938197]  krealloc_uaf+0x180/0x520
[   16.938238]  kunit_try_run_case+0x170/0x3f0
[   16.938435]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   16.938483]  kthread+0x328/0x630
[   16.938555]  ret_from_fork+0x10/0x20
[   16.938701] 
[   16.938910] kfence-#55: 0x00000000dcf6472e-0x00000000a7c9e69c, size=201, cache=kmalloc-256
[   16.938910] 
[   16.939390] allocated by task 165 on cpu 1 at 16.932817s (0.006225s ago):
[   16.940588]  krealloc_uaf+0xc8/0x520
[   16.940666]  kunit_try_run_case+0x170/0x3f0
[   16.940705]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   16.941005]  kthread+0x328/0x630
[   16.941038]  ret_from_fork+0x10/0x20
[   16.941117] 
[   16.941901] freed by task 165 on cpu 1 at 16.932882s (0.008618s ago):
[   16.942270]  krealloc_uaf+0x12c/0x520
[   16.942316]  kunit_try_run_case+0x170/0x3f0
[   16.942450]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   16.942596]  kthread+0x328/0x630
[   16.942648]  ret_from_fork+0x10/0x20
[   16.942816] 
[   16.943046] CPU: 1 UID: 0 PID: 165 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc4 #1 PREEMPT 
[   16.943131] Tainted: [B]=BAD_PAGE, [N]=TEST
[   16.943157] Hardware name: linux,dummy-virt (DT)
[   16.943193] ==================================================================