====================================== | [ 65.783985][ T882] ================================================================== | [ 65.784253][ T882] BUG: KASAN: slab-use-after-free in account_kernel_stack.isra.0 (kernel/fork.c:444) | [ 65.784541][ T882] Read of size 8 at addr ffff888001926740 by task timeout/882 | [ 65.784789][ T882] [ 65.784879][ T882] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 65.784881][ T882] Call Trace: [ 65.784883][ T882] [ 65.784885][ T882] dump_stack_lvl (lib/dump_stack.c:123) [ 65.784892][ T882] print_address_description.constprop.0 (mm/kasan/report.c:409) [ 65.784898][ T882] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 65.784901][ T882] print_report (mm/kasan/report.c:522) [ 65.784904][ T882] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 65.784907][ T882] ? kasan_addr_to_slab (./include/linux/mm.h:1178 mm/kasan/../slab.h:211 mm/kasan/common.c:38) [ 65.784913][ T882] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 65.784916][ T882] kasan_report (mm/kasan/report.c:636) [ 65.784919][ T882] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 65.784925][ T882] account_kernel_stack.isra.0 (kernel/fork.c:444) [ 65.784929][ T882] do_exit (./include/linux/sched/task_stack.h:33 kernel/exit.c:789 kernel/exit.c:849 kernel/exit.c:998) [ 65.784935][ T882] ? __pfx_do_exit (kernel/exit.c:897) [ 65.784939][ T882] ? do_group_exit (./include/linux/spinlock.h:402 kernel/exit.c:1101) [ 65.784941][ T882] ? __lock_release (kernel/locking/lockdep.c:5539) [ 65.784946][ T882] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 65.784952][ T882] do_group_exit (kernel/exit.c:1085) [ 65.784956][ T882] __x64_sys_exit_group (kernel/exit.c:1113) [ 65.784958][ T882] x64_sys_call (arch/x86/entry/syscall_64.c:37) [ 65.784963][ T882] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 65.784968][ T882] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 65.784971][ T882] RIP: 0033:0x7f68948c8abd [ 65.784975][ T882] Code: Unable to access opcode bytes at 0x7f68948c8a93. Code starting with the faulting instruction =========================================== [ 65.784977][ T882] RSP: 002b:00007ffe1c977218 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7 [ 65.784980][ T882] RAX: ffffffffffffffda RBX: 00007f68949a59c0 RCX: 00007f68948c8abd [ 65.784982][ T882] RDX: 00000000000000e7 RSI: ffffffffffffff80 RDI: 0000000000000004 [ 65.784984][ T882] RBP: 0000000000000004 R08: 0000000000000000 R09: 0000000000000020 [ 65.784986][ T882] R10: 00007ffe1c9770c0 R11: 0000000000000246 R12: 00007f68949a59c0 Finger prints: print_report:kasan_report:do_exit:do_group_exit:__x64_sys_exit_group