====================================== | [ 296.855679][ T293] br0: port 4(s2) entered blocking state | [ 296.856040][ T293] br0: port 4(s2) entered forwarding state | [ 297.610052][ T1670] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI | [ 297.610557][ T1670] KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] [ 297.611214][ T1670] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 297.611454][ T1670] RIP: 0010:xfrm_lookup_with_ifid (net/xfrm/xfrm_policy.c:3181) [ 297.611702][ T1670] Code: f1 f1 f1 c7 40 04 00 00 f2 f2 c7 40 08 00 00 f3 f3 65 48 8b 05 9a 32 e3 02 48 89 84 24 a8 00 00 00 31 c0 48 89 f8 48 c1 e8 03 <80> 3c 10 00 0f 85 cb 08 00 00 48 ba 00 00 00 00 00 fc ff df 48 8b All code ======== 0: f1 int1 1: f1 int1 2: f1 int1 3: c7 40 04 00 00 f2 f2 movl $0xf2f20000,0x4(%rax) a: c7 40 08 00 00 f3 f3 movl $0xf3f30000,0x8(%rax) 11: 65 48 8b 05 9a 32 e3 mov %gs:0x2e3329a(%rip),%rax # 0x2e332b3 18: 02 19: 48 89 84 24 a8 00 00 mov %rax,0xa8(%rsp) 20: 00 21: 31 c0 xor %eax,%eax 23: 48 89 f8 mov %rdi,%rax 26: 48 c1 e8 03 shr $0x3,%rax 2a:* 80 3c 10 00 cmpb $0x0,(%rax,%rdx,1) <-- trapping instruction 2e: 0f 85 cb 08 00 00 jne 0x8ff 34: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx 3b: fc ff df 3e: 48 rex.W 3f: 8b .byte 0x8b Code starting with the faulting instruction =========================================== 0: 80 3c 10 00 cmpb $0x0,(%rax,%rdx,1) 4: 0f 85 cb 08 00 00 jne 0x8d5 a: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx 11: fc ff df 14: 48 rex.W 15: 8b .byte 0x8b [ 297.612379][ T1670] RSP: 0018:ffffc900012679d8 EFLAGS: 00010202 [ 297.612645][ T1670] RAX: 0000000000000001 RBX: 1ffff9200024cf41 RCX: ffff88800bb68040 [ 297.612952][ T1670] RDX: dffffc0000000000 RSI: 0000000000000000 RDI: 0000000000000008 [ 297.613253][ T1670] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 [ 297.613571][ T1670] R10: 0000000000000000 R11: ffffffff8f7796a0 R12: 0000000000000006 [ 297.613877][ T1670] R13: ffff88800bb68040 R14: ffffc90001267be0 R15: ffff88800bc01880 [ 297.614205][ T1670] FS: 00007fb02f6ea300(0000) GS:ffff8880a4e44000(0000) knlGS:0000000000000000 [ 297.614583][ T1670] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 297.614851][ T1670] CR2: 000000000041aae8 CR3: 000000000ba9b006 CR4: 0000000000772ef0 [ 297.615201][ T1670] PKRU: 55555554 [ 297.615359][ T1670] Call Trace: [ 297.615534][ T1670] [ 297.615641][ T1670] ? find_held_lock (kernel/locking/lockdep.c:5353) [ 297.615860][ T1670] ? __pfx_xfrm_lookup_with_ifid (net/xfrm/xfrm_policy.c:3177) [ 297.616140][ T1670] ? dst_release (./arch/x86/include/asm/preempt.h:104 ./include/linux/rcuref.h:174 net/core/dst.c:167) [ 297.616345][ T1670] ? ip6_dst_lookup_tail.constprop.0 (net/ipv6/ip6_output.c:1231) [ 297.616613][ T1670] xfrm_lookup_route (net/xfrm/xfrm_policy.c:3351) [ 297.616832][ T1670] ip6_dst_lookup_flow (net/ipv6/ip6_output.c:1271) [ 297.617032][ T1670] ? __pfx_ip6_dst_lookup_flow (net/ipv6/ip6_output.c:1271) [ 297.617239][ T1670] ? ip6_datagram_dst_update (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 net/ipv6/datagram.c:94) [ 297.617439][ T1670] ? __lock_release (kernel/locking/lockdep.c:5539) [ 297.617628][ T1670] ip6_datagram_dst_update (net/ipv6/datagram.c:96) [ 297.617828][ T1670] ? __pfx_ip6_datagram_dst_update (net/ipv6/datagram.c:73) [ 297.618075][ T1670] ? lockdep_unlock (kernel/locking/lockdep.c:159) [ 297.618279][ T1670] ? validate_chain (kernel/locking/lockdep.c:3922) [ 297.618480][ T1670] ? __lock_acquire (kernel/locking/lockdep.c:5240) [ 297.618682][ T1670] ? __ip6_datagram_connect (net/ipv6/datagram.c:256) [ 297.618906][ T1670] __ip6_datagram_connect (net/ipv6/datagram.c:256) [ 297.619096][ T1670] ? __pfx___ip6_datagram_connect (net/ipv6/datagram.c:143) [ 297.619346][ T1670] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/softirq.c:412) [ 297.619554][ T1670] ? __pfx_inet_dgram_connect (net/ipv4/af_inet.c:570) [ 297.619796][ T1670] udpv6_connect (net/ipv6/udp.c:1310) [ 297.619999][ T1670] ? inet_dgram_connect (net/ipv4/af_inet.c:590 (discriminator 1)) [ 297.620209][ T1670] __sys_connect (./include/linux/file.h:62 ./include/linux/file.h:83 net/socket.c:2095) [ 297.620432][ T1670] ? __pfx___sys_connect (net/socket.c:2093) [ 297.620619][ T1670] ? fd_install (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:953 fs/file.c:661) [ 297.620809][ T1670] ? fd_install (./arch/x86/include/asm/preempt.h:104 ./include/linux/rcupdate.h:955 fs/file.c:661) [ 297.620998][ T1670] ? __sys_socket (net/socket.c:503 net/socket.c:1740) [ 297.621184][ T1670] ? __pfx___sys_socket (net/socket.c:1727) [ 297.621369][ T1670] ? do_user_addr_fault (./arch/x86/include/asm/atomic.h:93 ./include/linux/atomic/atomic-arch-fallback.h:949 ./include/linux/atomic/atomic-instrumented.h:401 ./include/linux/refcount.h:389 ./include/linux/refcount.h:432 ./include/linux/mmap_lock.h:142 ./include/linux/mmap_lock.h:237 arch/x86/mm/fault.c:1338) [ 297.621555][ T1670] __x64_sys_connect (net/socket.c:2108) [ 297.621771][ T1670] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475) [ 297.622012][ T1670] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 297.622235][ T1670] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 297.622518][ T1670] RIP: 0033:0x7fb02f980d77 [ 297.622759][ T1670] Code: 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2a 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 18 89 54 24 0c 48 89 34 24 89 All code ======== 0: 64 89 01 mov %eax,%fs:(%rcx) 3: 48 83 c8 ff or $0xffffffffffffffff,%rax 7: c3 ret 8: 66 2e 0f 1f 84 00 00 cs nopw 0x0(%rax,%rax,1) f: 00 00 00 12: 90 nop 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 2a 00 00 00 mov $0x2a,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 18 sub $0x18,%rsp 37: 89 54 24 0c mov %edx,0xc(%rsp) 3b: 48 89 34 24 mov %rsi,(%rsp) 3f: 89 .byte 0x89 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 18 sub $0x18,%rsp d: 89 54 24 0c mov %edx,0xc(%rsp) 11: 48 89 34 24 mov %rsi,(%rsp) 15: 89 .byte 0x89 [ 297.623504][ T1670] RSP: 002b:00007ffe16edf788 EFLAGS: 00000246 ORIG_RAX: 000000000000002a [ 297.623804][ T1670] RAX: ffffffffffffffda RBX: 0000000000000020 RCX: 00007fb02f980d77 [ 297.624116][ T1670] RDX: 000000000000001c RSI: 000000000041861c RDI: 0000000000000006 [ 297.624431][ T1670] RBP: 00007ffe16edfa70 R08: 00007ffe16edfaa8 R09: 0000000000000002 [ 297.624746][ T1670] R10: 00007fb02f8785a0 R11: 0000000000000246 R12: 00007ffe16edfdc8 Finger prints: xfrm_lookup_with_ifid:xfrm_lookup_route:ip6_dst_lookup_flow:ip6_datagram_dst_update:__ip6_datagram_connect