====================================== | [ 17.428976][ T294] ================================================================== | [ 17.429246][ T294] BUG: KASAN: slab-use-after-free in account_kernel_stack.isra.0 (kernel/fork.c:444) | [ 17.429528][ T294] Read of size 8 at addr ffff888001932740 by task ip/294 | [ 17.429730][ T294] [ 17.429821][ T294] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 17.429823][ T294] Call Trace: [ 17.429825][ T294] [ 17.429827][ T294] dump_stack_lvl (lib/dump_stack.c:123) [ 17.429834][ T294] print_address_description.constprop.0 (mm/kasan/report.c:409) [ 17.429841][ T294] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 17.429844][ T294] print_report (mm/kasan/report.c:522) [ 17.429848][ T294] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 17.429851][ T294] ? kasan_addr_to_slab (./include/linux/mm.h:1178 mm/kasan/../slab.h:211 mm/kasan/common.c:38) [ 17.429854][ T294] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 17.429857][ T294] kasan_report (mm/kasan/report.c:636) [ 17.429861][ T294] ? account_kernel_stack.isra.0 (kernel/fork.c:444) [ 17.429866][ T294] account_kernel_stack.isra.0 (kernel/fork.c:444) [ 17.429870][ T294] do_exit (./include/linux/sched/task_stack.h:33 kernel/exit.c:789 kernel/exit.c:849 kernel/exit.c:998) [ 17.429874][ T294] ? __pfx_do_exit (kernel/exit.c:897) [ 17.429877][ T294] ? do_group_exit (./include/linux/spinlock.h:402 kernel/exit.c:1101) [ 17.429880][ T294] ? __lock_release (kernel/locking/lockdep.c:5539) [ 17.429885][ T294] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 17.429891][ T294] do_group_exit (kernel/exit.c:1085) [ 17.429895][ T294] __x64_sys_exit_group (kernel/exit.c:1113) [ 17.429898][ T294] x64_sys_call (arch/x86/entry/syscall_64.c:37) [ 17.429902][ T294] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 17.429907][ T294] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 17.429910][ T294] RIP: 0033:0x7f7ac9bcaabd [ 17.429914][ T294] Code: Unable to access opcode bytes at 0x7f7ac9bcaa93. Code starting with the faulting instruction =========================================== [ 17.429916][ T294] RSP: 002b:00007fffe7d54548 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7 [ 17.429919][ T294] RAX: ffffffffffffffda RBX: 00007f7ac9ca79c0 RCX: 00007f7ac9bcaabd [ 17.429922][ T294] RDX: 00000000000000e7 RSI: fffffffffffffe90 RDI: 0000000000000000 [ 17.429923][ T294] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000060 [ 17.429925][ T294] R10: 00007fffe7d54370 R11: 0000000000000246 R12: 00007f7ac9ca79c0 Finger prints: print_report:kasan_report:do_exit:do_group_exit:__x64_sys_exit_group