====================================== | [ 918.134926][T10160] ================================================================== | [918.135274][T10160] BUG: KASAN: global-out-of-bounds in snmp6_seq_show_item64.constprop.0 (net/ipv6/proc.c:211) | [ 918.135635][T10160] Read of size 8 at addr ffffffffa08ed870 by task nstat/10160 | [ 918.135997][T10160] [ 918.136114][T10160] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 918.136118][T10160] Call Trace: [ 918.136121][T10160] [918.136124][T10160] dump_stack_lvl (lib/dump_stack.c:123) [918.136134][T10160] print_address_description.constprop.0 (mm/kasan/report.c:379) [918.136150][T10160] ? snmp6_seq_show_item64.constprop.0 (net/ipv6/proc.c:211) [918.136155][T10160] print_report (mm/kasan/report.c:483) [918.136159][T10160] ? snmp6_seq_show_item64.constprop.0 (net/ipv6/proc.c:211) [918.136162][T10160] ? kasan_addr_to_slab (./include/linux/mm.h:1180 mm/kasan/../slab.h:187 mm/kasan/common.c:38) [918.136166][T10160] ? snmp6_seq_show_item64.constprop.0 (net/ipv6/proc.c:211) [918.136171][T10160] kasan_report (mm/kasan/report.c:597) [918.136176][T10160] ? snmp6_seq_show_item64.constprop.0 (net/ipv6/proc.c:211) [918.136184][T10160] snmp6_seq_show_item64.constprop.0 (net/ipv6/proc.c:211) [918.136190][T10160] ? sockstat6_seq_show (net/ipv6/proc.c:202) [918.136202][T10160] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:751) [918.136206][T10160] ? trace_kmalloc (./include/trace/events/kmem.h:54 (discriminator 21)) [918.136212][T10160] ? __kvmalloc_node_noprof (mm/slub.c:5055) [918.136219][T10160] snmp6_seq_show (net/ipv6/proc.c:224) [918.136224][T10160] seq_read_iter (fs/seq_file.c:231) [918.136242][T10160] seq_read (fs/seq_file.c:163) [918.136249][T10160] ? seq_read_iter (fs/seq_file.c:152) [918.136254][T10160] ? __might_fault (mm/memory.c:6958 mm/memory.c:6952) [918.136265][T10160] ? memtype_check_insert (./include/linux/rbtree.h:62 arch/x86/mm/pat/memtype_interval.c:46 arch/x86/mm/pat/memtype_interval.c:101) [918.136271][T10160] ? __might_fault (mm/memory.c:6958 mm/memory.c:6952) [918.136276][T10160] ? cp_new_stat (fs/stat.c:471) [918.136281][T10160] ? inode_set_bytes (fs/stat.c:471) [918.136286][T10160] proc_reg_read (fs/proc/inode.c:308 fs/proc/inode.c:320) [918.136298][T10160] vfs_read (fs/read_write.c:570) [918.136305][T10160] ? vfs_getattr_nosec (fs/stat.c:218) [918.136309][T10160] ? kernel_read (fs/read_write.c:553) [918.136313][T10160] ? vfs_fstat (./include/linux/file.h:62 ./include/linux/file.h:84 fs/stat.c:278) [918.136317][T10160] ? __do_sys_newfstat (fs/stat.c:551) [918.136320][T10160] ? __do_sys_fstat (fs/stat.c:551) [918.136327][T10160] ksys_read (fs/read_write.c:715) [918.136331][T10160] ? vfs_write (fs/read_write.c:705) [918.136337][T10160] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [918.136343][T10160] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 918.136352][T10160] RIP: 0033:0x7f9eb3ae4292 [ 918.136356][T10160] Code: c0 e9 b2 fe ff ff 50 48 8d 3d 6a 15 0c 00 e8 65 e1 01 00 0f 1f 44 00 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 0f 05 <48> 3d 00 f0 ff ff 77 56 c3 0f 1f 44 00 00 48 83 ec 28 48 89 54 24 All code ======== 0: c0 e9 b2 shr $0xb2,%cl 3: fe (bad) 4: ff (bad) 5: ff 50 48 call *0x48(%rax) 8: 8d 3d 6a 15 0c 00 lea 0xc156a(%rip),%edi # 0xc1578 e: e8 65 e1 01 00 call 0x1e178 13: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 18: f3 0f 1e fa endbr64 1c: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 23: 00 24: 85 c0 test %eax,%eax 26: 75 10 jne 0x38 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 56 ja 0x88 32: c3 ret 33: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 38: 48 83 ec 28 sub $0x28,%rsp 3c: 48 rex.W 3d: 89 .byte 0x89 3e: 54 push %rsp 3f: 24 .byte 0x24 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 56 ja 0x5e 8: c3 ret 9: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) e: 48 83 ec 28 sub $0x28,%rsp 12: 48 rex.W 13: 89 .byte 0x89 14: 54 push %rsp 15: 24 .byte 0x24 [ 918.136359][T10160] RSP: 002b:00007fffd6e0b108 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 918.136367][T10160] RAX: ffffffffffffffda RBX: 0000000018998910 RCX: 00007f9eb3ae4292 [ 918.136371][T10160] RDX: 0000000000000400 RSI: 0000000018998500 RDI: 0000000000000006 [ 918.136374][T10160] RBP: 00007f9eb3bdc5c0 R08: 0000000000000006 R09: 0000000000000000 [ 918.136376][T10160] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000018998910 Finger prints: print_report:kasan_report:snmp6_seq_show:seq_read_iter:seq_read