Hay
Date
July 8, 2025, 7:07 p.m.

Environment
qemu-arm64

[   22.400759] ==================================================================
[   22.400833] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x578/0x5d0
[   22.400995] Read of size 1 at addr ffff8000800fe7f3 by task kunit_try_catch/269
[   22.401052] 
[   22.401109] CPU: 0 UID: 0 PID: 269 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc5 #1 PREEMPT 
[   22.402032] Tainted: [B]=BAD_PAGE, [N]=TEST
[   22.402082] Hardware name: linux,dummy-virt (DT)
[   22.402117] Call trace:
[   22.402144]  show_stack+0x20/0x38 (C)
[   22.402323]  dump_stack_lvl+0x8c/0xd0
[   22.402522]  print_report+0x310/0x608
[   22.402609]  kasan_report+0xdc/0x128
[   22.402895]  __asan_report_load1_noabort+0x20/0x30
[   22.402973]  vmalloc_oob+0x578/0x5d0
[   22.403021]  kunit_try_run_case+0x170/0x3f0
[   22.403072]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.403471]  kthread+0x328/0x630
[   22.403566]  ret_from_fork+0x10/0x20
[   22.403841] 
[   22.403901] The buggy address belongs to the virtual mapping at
[   22.403901]  [ffff8000800fe000, ffff800080100000) created by:
[   22.403901]  vmalloc_oob+0x98/0x5d0
[   22.404147] 
[   22.404183] The buggy address belongs to the physical page:
[   22.404218] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x106422
[   22.404645] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   22.404843] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   22.405127] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   22.405201] page dumped because: kasan: bad access detected
[   22.405283] 
[   22.405495] Memory state around the buggy address:
[   22.405576]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.405836]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.405914] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   22.405974]                                                              ^
[   22.406499]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.406598]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.406848] ==================================================================
[   22.408832] ==================================================================
[   22.409008] BUG: KASAN: vmalloc-out-of-bounds in vmalloc_oob+0x51c/0x5d0
[   22.409070] Read of size 1 at addr ffff8000800fe7f8 by task kunit_try_catch/269
[   22.409122] 
[   22.409155] CPU: 0 UID: 0 PID: 269 Comm: kunit_try_catch Tainted: G    B            N  6.16.0-rc5 #1 PREEMPT 
[   22.409614] Tainted: [B]=BAD_PAGE, [N]=TEST
[   22.409663] Hardware name: linux,dummy-virt (DT)
[   22.409860] Call trace:
[   22.409899]  show_stack+0x20/0x38 (C)
[   22.409953]  dump_stack_lvl+0x8c/0xd0
[   22.410223]  print_report+0x310/0x608
[   22.410618]  kasan_report+0xdc/0x128
[   22.410690]  __asan_report_load1_noabort+0x20/0x30
[   22.410910]  vmalloc_oob+0x51c/0x5d0
[   22.411112]  kunit_try_run_case+0x170/0x3f0
[   22.411172]  kunit_generic_run_threadfn_adapter+0x88/0x100
[   22.411227]  kthread+0x328/0x630
[   22.411306]  ret_from_fork+0x10/0x20
[   22.411357] 
[   22.411384] The buggy address belongs to the virtual mapping at
[   22.411384]  [ffff8000800fe000, ffff800080100000) created by:
[   22.411384]  vmalloc_oob+0x98/0x5d0
[   22.411460] 
[   22.411481] The buggy address belongs to the physical page:
[   22.411722] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x106422
[   22.412092] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   22.412379] raw: 0bfffe0000000000 0000000000000000 dead000000000122 0000000000000000
[   22.412664] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   22.412852] page dumped because: kasan: bad access detected
[   22.412930] 
[   22.413057] Memory state around the buggy address:
[   22.413460]  ffff8000800fe680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.413856]  ffff8000800fe700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   22.414016] >ffff8000800fe780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 f8
[   22.414192]                                                                 ^
[   22.414325]  ffff8000800fe800: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.414461]  ffff8000800fe880: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8
[   22.414511] ==================================================================