[ 1066.799668][ T5223] br1: port 1(vx10) entered blocking state [ 1066.799932][ T5223] br1: port 1(vx10) entered disabled state [ 1066.800178][ T5223] vx10: entered allmulticast mode [ 1066.803398][ T5223] vx10: entered promiscuous mode [ 1066.804193][ T5223] br1: port 1(vx10) entered blocking state [ 1066.804436][ T5223] br1: port 1(vx10) entered forwarding state [ 1067.544956][ T5228] br1: port 2(vx20) entered blocking state [ 1067.545285][ T5228] br1: port 2(vx20) entered disabled state [ 1067.545567][ T5228] vx20: entered allmulticast mode [ 1067.547583][ T5228] vx20: entered promiscuous mode [ 1067.548208][ T5228] br1: port 2(vx20) entered blocking state [ 1067.548503][ T5228] br1: port 2(vx20) entered forwarding state [ 1067.890158][ T5230] br1: port 3(veth1) entered blocking state [ 1067.890420][ T5230] br1: port 3(veth1) entered disabled state [ 1067.890667][ T5230] veth1: entered allmulticast mode [ 1067.892469][ T5230] veth1: entered promiscuous mode [ 1068.071347][ T38] br1: port 3(veth1) entered blocking state [ 1068.071752][ T38] br1: port 3(veth1) entered forwarding state [ 1068.420959][ T5233] br1: port 4(veth2) entered blocking state [ 1068.421246][ T5233] br1: port 4(veth2) entered disabled state [ 1068.421513][ T5233] veth2: entered allmulticast mode [ 1068.423384][ T5233] veth2: entered promiscuous mode [ 1068.593292][ T4341] br1: port 4(veth2) entered blocking state [ 1068.593734][ T4341] br1: port 4(veth2) entered forwarding state [ 1070.473338][ T5245] br1: entered promiscuous mode [ 1070.475889][ T5245] br1: left promiscuous mode [ 1070.482140][ T5245] br1: entered promiscuous mode [ 1082.712002][ T5331] br1: port 1(vx10) entered blocking state [ 1082.712272][ T5331] br1: port 1(vx10) entered disabled state [ 1082.712569][ T5331] vx10: entered allmulticast mode [ 1082.714456][ T5331] vx10: entered promiscuous mode [ 1082.715217][ T5331] br1: port 1(vx10) entered blocking state [ 1082.715453][ T5331] br1: port 1(vx10) entered forwarding state [ 1083.510863][ T5335] br1: port 2(vx20) entered blocking state [ 1083.511163][ T5335] br1: port 2(vx20) entered disabled state [ 1083.511449][ T5335] vx20: entered allmulticast mode [ 1083.513466][ T5335] vx20: entered promiscuous mode [ 1083.513989][ T5335] br1: port 2(vx20) entered blocking state [ 1083.514236][ T5335] br1: port 2(vx20) entered forwarding state [ 1083.852718][ T5337] br1: port 3(w1) entered blocking state [ 1083.852941][ T5337] br1: port 3(w1) entered disabled state [ 1083.853189][ T5337] w1: entered allmulticast mode [ 1083.855260][ T5337] w1: entered promiscuous mode [ 1084.027957][ T258] br1: port 3(w1) entered blocking state [ 1084.028190][ T258] br1: port 3(w1) entered forwarding state [ 1084.376872][ T5340] br1: port 4(w3) entered blocking state [ 1084.377220][ T5340] br1: port 4(w3) entered disabled state [ 1084.377585][ T5340] w3: entered allmulticast mode [ 1084.380708][ T5340] w3: entered promiscuous mode [ 1084.566049][ T258] br1: port 4(w3) entered blocking state [ 1084.566303][ T258] br1: port 4(w3) entered forwarding state [ 1086.156295][ T5350] br1: entered promiscuous mode [ 1086.158867][ T5350] br1: left promiscuous mode [ 1086.180122][ T5350] br1: entered promiscuous mode [ 1087.812750][ C0] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 1087.813824][ C0] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 1088.068113][ C2] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 1088.069063][ C2] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 1088.228144][ C0] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 1088.395973][ C2] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 1091.524632][ C1] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 1091.971913][ C2] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 1099.587869][ C2] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 1100.100262][ C2] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 1115.972187][ C3] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 1116.995924][ C2] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 1129.882825][ T5639] ================================================================== [ 1129.883068][ T5639] BUG: KASAN: slab-use-after-free in ___neigh_create+0xd58/0xf30 [ 1129.883283][ T5639] Write of size 8 at addr ffff888007b3c018 by task ip/5639 [ 1129.883507][ T5639] [ 1129.883583][ T5639] CPU: 3 UID: 0 PID: 5639 Comm: ip Not tainted 6.12.0-rc3-virtme #1 [ 1129.883798][ T5639] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 1129.884100][ T5639] Call Trace: [ 1129.884205][ T5639] [ 1129.884275][ T5639] dump_stack_lvl+0x82/0xd0 [ 1129.884440][ T5639] print_address_description.constprop.0+0x2c/0x3b0 [ 1129.884601][ T5639] ? ___neigh_create+0xd58/0xf30 [ 1129.884769][ T5639] print_report+0xb4/0x270 [ 1129.884896][ T5639] ? kasan_addr_to_slab+0x25/0x80 [ 1129.885035][ T5639] kasan_report+0xbd/0xf0 [ 1129.885138][ T5639] ? ___neigh_create+0xd58/0xf30 [ 1129.885265][ T5639] ___neigh_create+0xd58/0xf30 [ 1129.885418][ T5639] neigh_add+0x8f8/0xdd0 [ 1129.885515][ T5639] ? __pfx_neigh_add+0x10/0x10 [ 1129.885643][ T5639] ? __mutex_lock+0x170/0xac0 [ 1129.885795][ T5639] rtnetlink_rcv_msg+0x2fb/0xc10 [ 1129.885922][ T5639] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 1129.886064][ T5639] ? hlock_class+0x4e/0x130 [ 1129.886197][ T5639] ? mark_lock+0x38/0x3e0 [ 1129.886296][ T5639] ? __lock_acquire+0xb3f/0x1580 [ 1129.886463][ T5639] netlink_rcv_skb+0x130/0x360 [ 1129.886599][ T5639] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 1129.886742][ T5639] ? __pfx_netlink_rcv_skb+0x10/0x10 [ 1129.886876][ T5639] ? netlink_deliver_tap+0x13e/0x340 [ 1129.887003][ T5639] ? netlink_deliver_tap+0xc3/0x340 [ 1129.887131][ T5639] netlink_unicast+0x44b/0x710 [ 1129.887260][ T5639] ? __pfx_netlink_unicast+0x10/0x10 [ 1129.887394][ T5639] ? find_held_lock+0x2c/0x110 [ 1129.887527][ T5639] netlink_sendmsg+0x723/0xbe0 [ 1129.887657][ T5639] ? __pfx_netlink_sendmsg+0x10/0x10 [ 1129.887782][ T5639] ? __might_fault+0xc3/0x170 [ 1129.887912][ T5639] ? __import_iovec+0x35d/0x5d0 [ 1129.888042][ T5639] ____sys_sendmsg+0x7ac/0xa10 [ 1129.888177][ T5639] ? __pfx_____sys_sendmsg+0x10/0x10 [ 1129.888304][ T5639] ? __pfx_copy_msghdr_from_user+0x10/0x10 [ 1129.888489][ T5639] ___sys_sendmsg+0xee/0x170 [ 1129.888619][ T5639] ? __pfx____sys_sendmsg+0x10/0x10 [ 1129.888775][ T5639] ? ___sys_recvmsg+0xe0/0x150 [ 1129.888904][ T5639] ? __pfx____sys_recvmsg+0x10/0x10 [ 1129.889045][ T5639] ? reacquire_held_locks+0x22f/0x4f0 [ 1129.889195][ T5639] ? do_user_addr_fault+0x8fd/0xe30 [ 1129.889330][ T5639] ? fdget+0x52/0x1e0 [ 1129.889447][ T5639] __sys_sendmsg+0xcd/0x170 [ 1129.889579][ T5639] ? __pfx___sys_sendmsg+0x10/0x10 [ 1129.889720][ T5639] ? __pfx___up_read+0x10/0x10 [ 1129.889861][ T5639] do_syscall_64+0xc1/0x1d0 [ 1129.889992][ T5639] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1129.890156][ T5639] RIP: 0033:0x7fde8ec617b7 [ 1129.890293][ T5639] Code: 0a 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 [ 1129.890749][ T5639] RSP: 002b:00007ffdd55c4538 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 1129.890950][ T5639] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fde8ec617b7 [ 1129.891142][ T5639] RDX: 0000000000000000 RSI: 00007ffdd55c45a0 RDI: 0000000000000005 [ 1129.891337][ T5639] RBP: 0000000000000001 R08: 0000000000000014 R09: 0000000000000000 [ 1129.891528][ T5639] R10: 00007fde8eb1a708 R11: 0000000000000246 R12: 00007ffdd55c5d40 [ 1129.891724][ T5639] R13: 00000000671674b8 R14: 0000000000496600 R15: 00007ffdd55c4ae0 [ 1129.891921][ T5639] [ 1129.892019][ T5639] [ 1129.892083][ T5639] Allocated by task 5501: [ 1129.892186][ T5639] kasan_save_stack+0x24/0x50 [ 1129.892321][ T5639] kasan_save_track+0x14/0x30 [ 1129.892450][ T5639] __kasan_kmalloc+0x7f/0x90 [ 1129.892583][ T5639] __kmalloc_noprof+0x1ab/0x3a0 [ 1129.892712][ T5639] neigh_alloc+0x6f2/0x9d0 [ 1129.892847][ T5639] ___neigh_create+0x6d/0xf30 [ 1129.892972][ T5639] ip_finish_output2+0xb79/0x17f0 [ 1129.893104][ T5639] ip_output+0x16b/0x4f0 [ 1129.893198][ T5639] NF_HOOK.constprop.0+0x7e/0x320 [ 1129.893329][ T5639] ip_rcv+0x62f/0x740 [ 1129.893425][ T5639] __netif_receive_skb_one_core+0x166/0x1b0 [ 1129.893585][ T5639] netif_receive_skb_internal+0xb0/0x330 [ 1129.893713][ T5639] netif_receive_skb+0x1b/0x30 [ 1129.893840][ T5639] br_handle_frame_finish+0x10ca/0x1d00 [bridge] [ 1129.894058][ T5639] br_handle_frame+0x612/0xea0 [bridge] [ 1129.894221][ T5639] __netif_receive_skb_core.constprop.0+0x76a/0x2ee0 [ 1129.894409][ T5639] __netif_receive_skb_one_core+0xaf/0x1b0 [ 1129.894573][ T5639] process_backlog+0x372/0x1180 [ 1129.894701][ T5639] __napi_poll.constprop.0+0xa2/0x460 [ 1129.894830][ T5639] net_rx_action+0x50e/0xce0 [ 1129.894955][ T5639] handle_softirqs+0x1f6/0x5c0 [ 1129.895095][ T5639] do_softirq+0x4d/0xa0 [ 1129.895192][ T5639] __local_bh_enable_ip+0xf6/0x120 [ 1129.895320][ T5639] __dev_queue_xmit+0x7af/0x18b0 [ 1129.895466][ T5639] ip_finish_output2+0x6ff/0x17f0 [ 1129.895620][ T5639] ip_output+0x16b/0x4f0 [ 1129.895716][ T5639] ip_push_pending_frames+0x24b/0x480 [ 1129.895866][ T5639] raw_sendmsg+0xea0/0x1790 [ 1129.896000][ T5639] __sys_sendto+0x32c/0x400 [ 1129.896141][ T5639] __x64_sys_sendto+0xe0/0x1c0 [ 1129.896308][ T5639] do_syscall_64+0xc1/0x1d0 [ 1129.896441][ T5639] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1129.896623][ T5639] [ 1129.896691][ T5639] Freed by task 39: [ 1129.896787][ T5639] kasan_save_stack+0x24/0x50 [ 1129.896916][ T5639] kasan_save_track+0x14/0x30 [ 1129.897049][ T5639] kasan_save_free_info+0x3b/0x60 [ 1129.897254][ T5639] __kasan_slab_free+0x38/0x50 [ 1129.897389][ T5639] kmem_cache_free_bulk.part.0+0x1f2/0x5b0 [ 1129.897551][ T5639] kvfree_rcu_bulk+0x4b9/0x5d0 [ 1129.897679][ T5639] kvfree_rcu_drain_ready+0x2ab/0x860 [ 1129.897881][ T5639] kfree_rcu_monitor+0x26/0xe0 [ 1129.898008][ T5639] process_one_work+0xe55/0x16d0 [ 1129.898138][ T5639] worker_thread+0x58c/0xce0 [ 1129.898272][ T5639] kthread+0x28a/0x350 [ 1129.898405][ T5639] ret_from_fork+0x31/0x70 [ 1129.898608][ T5639] ret_from_fork_asm+0x1a/0x30 [ 1129.898770][ T5639] [ 1129.898846][ T5639] Last potentially related work creation: [ 1129.898972][ T5639] kasan_save_stack+0x24/0x50 [ 1129.899104][ T5639] __kasan_record_aux_stack+0x8e/0xa0 [ 1129.899232][ T5639] kvfree_call_rcu+0x114/0x4b0 [ 1129.899364][ T5639] neigh_remove_one+0x1a3/0x200 [ 1129.899514][ T5639] neigh_delete+0x29f/0x490 [ 1129.899642][ T5639] rtnetlink_rcv_msg+0x2fb/0xc10 [ 1129.899847][ T5639] netlink_rcv_skb+0x130/0x360 [ 1129.899997][ T5639] netlink_unicast+0x44b/0x710 [ 1129.900136][ T5639] netlink_sendmsg+0x723/0xbe0 [ 1129.900281][ T5639] ____sys_sendmsg+0x7ac/0xa10 [ 1129.900567][ T5639] ___sys_sendmsg+0xee/0x170 [ 1129.900695][ T5639] __sys_sendmsg+0xcd/0x170 [ 1129.900823][ T5639] do_syscall_64+0xc1/0x1d0 [ 1129.900974][ T5639] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1129.901133][ T5639] [ 1129.901221][ T5639] The buggy address belongs to the object at ffff888007b3c000 [ 1129.901221][ T5639] which belongs to the cache kmalloc-1k of size 1024 [ 1129.901572][ T5639] The buggy address is located 24 bytes inside of [ 1129.901572][ T5639] freed 1024-byte region [ffff888007b3c000, ffff888007b3c400) [ 1129.901946][ T5639] [ 1129.902011][ T5639] The buggy address belongs to the physical page: [ 1129.902166][ T5639] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x7b38 [ 1129.902486][ T5639] head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 1129.902697][ T5639] flags: 0x80000000000040(head|node=0|zone=1) [ 1129.902860][ T5639] page_type: f5(slab) [ 1129.903073][ T5639] raw: 0080000000000040 ffff8880010430c0 ffffea0000366410 ffffea0000334c10 [ 1129.903301][ T5639] raw: 0000000000000000 00000000000a000a 00000001f5000000 0000000000000000 [ 1129.903527][ T5639] head: 0080000000000040 ffff8880010430c0 ffffea0000366410 ffffea0000334c10 [ 1129.903830][ T5639] head: 0000000000000000 00000000000a000a 00000001f5000000 0000000000000000 [ 1129.904062][ T5639] head: 0080000000000003 ffffea00001ece01 ffffffffffffffff 0000000000000000 [ 1129.904363][ T5639] head: 0000000000000008 0000000000000000 00000000ffffffff 0000000000000000 [ 1129.904587][ T5639] page dumped because: kasan: bad access detected [ 1129.904745][ T5639] [ 1129.904813][ T5639] Memory state around the buggy address: [ 1129.905008][ T5639] ffff888007b3bf00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 1129.905195][ T5639] ffff888007b3bf80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 1129.905382][ T5639] >ffff888007b3c000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 1129.905656][ T5639] ^ [ 1129.905786][ T5639] ffff888007b3c080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 1129.905977][ T5639] ffff888007b3c100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 1129.906229][ T5639] ================================================================== [ 1129.906459][ T5639] Disabling lock debugging due to kernel taint [ 1133.102572][ T11] w3: left allmulticast mode [ 1133.102741][ T11] w3: left promiscuous mode [ 1133.103027][ T11] br1: port 4(w3) entered disabled state [ 1133.104442][ T11] w1: left allmulticast mode [ 1133.104609][ T11] w1: left promiscuous mode [ 1133.104965][ T11] br1: port 3(w1) entered disabled state [ 1133.107687][ T11] vx20: left allmulticast mode [ 1133.107932][ T11] vx20: left promiscuous mode [ 1133.108353][ T11] br1: port 2(vx20) entered disabled state [ 1133.113803][ T11] vx10: left allmulticast mode [ 1133.114042][ T11] vx10: left promiscuous mode [ 1133.114425][ T11] br1: port 1(vx10) entered disabled state [ 1135.880739][ T5698] Oops: general protection fault, probably for non-canonical address 0xe0963c38200002c8: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 1135.881220][ T5698] KASAN: maybe wild-memory-access in range [0x04b201c100001640-0x04b201c100001647] [ 1135.881525][ T5698] CPU: 3 UID: 0 PID: 5698 Comm: ip Tainted: G B 6.12.0-rc3-virtme #1 [ 1135.881843][ T5698] Tainted: [B]=BAD_PAGE [ 1135.881980][ T5698] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 1135.882373][ T5698] RIP: 0010:neigh_flush_dev.isra.0+0x10a/0x650 [ 1135.882606][ T5698] Code: 0f 85 ef 04 00 00 49 8d 7f 08 49 8b 1f 48 89 f8 48 c1 e8 03 42 80 3c 28 00 0f 85 cc 04 00 00 49 8b 6f 08 48 89 e8 48 c1 e8 03 <42> 80 3c 28 00 0f 85 19 05 00 00 48 89 5d 00 48 85 db 74 1a 48 8d [ 1135.883240][ T5698] RSP: 0018:ffffc9000151ef10 EFLAGS: 00010202 [ 1135.883463][ T5698] RAX: 00964038200002c8 RBX: ffff888003639840 RCX: ffffffff84c796f0 [ 1135.883728][ T5698] RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffff888007b3c008 [ 1135.883993][ T5698] RBP: 04b201c100001640 R08: 0000000000000000 R09: 0000000000000000 [ 1135.884265][ T5698] R10: ffffffff87171f0f R11: ffffc9000151eb21 R12: ffff888007b3c13c [ 1135.884530][ T5698] R13: dffffc0000000000 R14: ffff88800a451000 R15: ffff888007b3c000 [ 1135.884807][ T5698] FS: 00007f75dc943800(0000) GS:ffff888036180000(0000) knlGS:0000000000000000 [ 1135.885118][ T5698] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1135.885342][ T5698] CR2: 00000000004e28e0 CR3: 0000000006100002 CR4: 0000000000772ef0 [ 1135.885608][ T5698] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1135.885900][ T5698] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 1135.886165][ T5698] PKRU: 55555554 [ 1135.886305][ T5698] Call Trace: [ 1135.886447][ T5698] [ 1135.886539][ T5698] ? die_addr+0x41/0xa0 [ 1135.886680][ T5698] ? exc_general_protection+0x14d/0x230 [ 1135.886862][ T5698] ? asm_exc_general_protection+0x26/0x30 [ 1135.887042][ T5698] ? neigh_flush_dev.isra.0+0x5d0/0x650 [ 1135.887219][ T5698] ? neigh_flush_dev.isra.0+0x10a/0x650 [ 1135.887400][ T5698] ? lock_acquire+0x32/0xc0 [ 1135.887580][ T5698] __neigh_ifdown.isra.0+0x74/0x440 [ 1135.887780][ T5698] ? fib_flush+0x86/0x110 [ 1135.887917][ T5698] neigh_ifdown+0x10/0x20 [ 1135.888050][ T5698] fib_netdev_event+0x185/0x5a0 [ 1135.888228][ T5698] notifier_call_chain+0xcd/0x150 [ 1135.888416][ T5698] dev_close_many+0x2d8/0x650 [ 1135.888597][ T5698] ? trace_lock_release+0x10e/0x180 [ 1135.888776][ T5698] ? __pfx_dev_close_many+0x10/0x10 [ 1135.888955][ T5698] ? __debug_check_no_obj_freed+0x253/0x520 [ 1135.889185][ T5698] unregister_netdevice_many_notify+0x8e5/0x1580 [ 1135.889406][ T5698] ? __pfx___debug_check_no_obj_freed+0x10/0x10 [ 1135.889625][ T5698] ? __pfx_free_object_rcu+0x10/0x10 [ 1135.889803][ T5698] ? trace_rcu_segcb_stats+0x37/0x1e0 [ 1135.889983][ T5698] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 1135.890202][ T5698] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 1135.890428][ T5698] ? kfree+0xf3/0x340 [ 1135.890568][ T5698] ? netlink_unicast+0x422/0x710 [ 1135.890747][ T5698] ? vlan_vid_del+0x310/0x5e0 [ 1135.890927][ T5698] ? vlan_vid_del+0x310/0x5e0 [ 1135.891105][ T5698] rtnl_dellink+0x329/0xa50 [ 1135.891285][ T5698] ? rtnl_getlink+0x77d/0x970 [ 1135.891461][ T5698] ? __pfx_rtnl_dellink+0x10/0x10 [ 1135.891659][ T5698] ? trace_contention_end+0xeb/0x150 [ 1135.891836][ T5698] ? __mutex_lock+0x170/0xac0 [ 1135.892013][ T5698] ? trace_lock_acquire+0x14d/0x1f0 [ 1135.892195][ T5698] ? rtnetlink_rcv_msg+0x2af/0xc10 [ 1135.892372][ T5698] ? __pfx___mutex_lock+0x10/0x10 [ 1135.892546][ T5698] ? trace_lock_release+0x10e/0x180 [ 1135.892725][ T5698] ? trace_lock_acquire+0x14d/0x1f0 [ 1135.892904][ T5698] rtnetlink_rcv_msg+0x2fb/0xc10 [ 1135.893121][ T5698] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 1135.893298][ T5698] ? stack_trace_save+0x94/0xd0 [ 1135.893489][ T5698] ? __pfx_stack_trace_save+0x10/0x10 [ 1135.893670][ T5698] netlink_rcv_skb+0x130/0x360 [ 1135.893852][ T5698] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 1135.894031][ T5698] ? __pfx_netlink_rcv_skb+0x10/0x10 [ 1135.894217][ T5698] ? trace_lock_release+0x10e/0x180 [ 1135.894401][ T5698] ? netlink_deliver_tap+0xc3/0x340 [ 1135.894578][ T5698] ? netlink_deliver_tap+0x13e/0x340 [ 1135.894756][ T5698] ? lock_release+0x13/0x140 [ 1135.894939][ T5698] ? netlink_deliver_tap+0xc3/0x340 [ 1135.895118][ T5698] netlink_unicast+0x44b/0x710 [ 1135.895299][ T5698] ? __pfx_netlink_unicast+0x10/0x10 [ 1135.895484][ T5698] netlink_sendmsg+0x723/0xbe0 [ 1135.895673][ T5698] ? __pfx_netlink_sendmsg+0x10/0x10 [ 1135.895851][ T5698] ? __might_fault+0xc3/0x170 [ 1135.896028][ T5698] ? __import_iovec+0x35d/0x5d0 [ 1135.896206][ T5698] ? lock_release+0x13/0x140 [ 1135.896391][ T5698] ____sys_sendmsg+0x7ac/0xa10 [ 1135.896575][ T5698] ? __pfx_____sys_sendmsg+0x10/0x10 [ 1135.896750][ T5698] ? __pfx_copy_msghdr_from_user+0x10/0x10 [ 1135.896980][ T5698] ___sys_sendmsg+0xee/0x170 [ 1135.897153][ T5698] ? __pfx_stack_trace_save+0x10/0x10 [ 1135.897337][ T5698] ? __pfx____sys_sendmsg+0x10/0x10 [ 1135.897515][ T5698] ? __pfx_slab_free_after_rcu_debug+0x10/0x10 [ 1135.897741][ T5698] ? kasan_save_stack+0x34/0x50 [ 1135.897922][ T5698] ? kasan_save_stack+0x24/0x50 [ 1135.898097][ T5698] ? __kasan_record_aux_stack+0x8e/0xa0 [ 1135.898275][ T5698] ? __call_rcu_common.constprop.0+0xa1/0x4b0 [ 1135.898526][ T5698] ? __x64_sys_close+0x7c/0xd0 [ 1135.898707][ T5698] ? do_syscall_64+0xc1/0x1d0 [ 1135.898885][ T5698] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1135.899106][ T5698] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 1135.899285][ T5698] ? trace_lock_release+0x10e/0x180 [ 1135.899472][ T5698] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 1135.899691][ T5698] ? fdget+0x52/0x1e0 [ 1135.899846][ T5698] __sys_sendmsg+0xcd/0x170 [ 1135.900033][ T5698] ? __pfx___sys_sendmsg+0x10/0x10 [ 1135.900212][ T5698] ? trace_lock_release+0x10e/0x180 [ 1135.900393][ T5698] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 1135.900613][ T5698] do_syscall_64+0xc1/0x1d0 [ 1135.900801][ T5698] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1135.901026][ T5698] RIP: 0033:0x7f75dcb4f7b7 [ 1135.901212][ T5698] Code: 0a 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 [ 1135.901881][ T5698] RSP: 002b:00007ffead020028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 1135.902154][ T5698] RAX: ffffffffffffffda RBX: 00007ffead020750 RCX: 00007f75dcb4f7b7 [ 1135.902434][ T5698] RDX: 0000000000000000 RSI: 00007ffead020090 RDI: 0000000000000005 [ 1135.902707][ T5698] RBP: 0000000000000002 R08: 0000000000000003 R09: 0000000000000078 [ 1135.902979][ T5698] R10: 00007f75dca0def8 R11: 0000000000000246 R12: 0000000000000002 [ 1135.903256][ T5698] R13: 00000000671674bd R14: 0000000000496600 R15: 0000000000000000 [ 1135.903537][ T5698] [ 1135.903674][ T5698] Modules linked in: macvlan vxlan ip6_udp_tunnel udp_tunnel act_mirred ip6_gre ip6_tunnel tunnel6 cls_matchall ip_gre gre act_pedit act_gact cls_flower dummy sch_ingress bridge stp llc 8021q vrf veth [ 1135.904396][ T5698] ---[ end trace 0000000000000000 ]--- [ 1135.904588][ T5698] RIP: 0010:neigh_flush_dev.isra.0+0x10a/0x650 [ 1135.904826][ T5698] Code: 0f 85 ef 04 00 00 49 8d 7f 08 49 8b 1f 48 89 f8 48 c1 e8 03 42 80 3c 28 00 0f 85 cc 04 00 00 49 8b 6f 08 48 89 e8 48 c1 e8 03 <42> 80 3c 28 00 0f 85 19 05 00 00 48 89 5d 00 48 85 db 74 1a 48 8d [ 1135.905477][ T5698] RSP: 0018:ffffc9000151ef10 EFLAGS: 00010202 [ 1135.905714][ T5698] RAX: 00964038200002c8 RBX: ffff888003639840 RCX: ffffffff84c796f0 [ 1135.905992][ T5698] RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffff888007b3c008 [ 1135.906257][ T5698] RBP: 04b201c100001640 R08: 0000000000000000 R09: 0000000000000000 [ 1135.906544][ T5698] R10: ffffffff87171f0f R11: ffffc9000151eb21 R12: ffff888007b3c13c [ 1135.906815][ T5698] R13: dffffc0000000000 R14: ffff88800a451000 R15: ffff888007b3c000 [ 1135.907083][ T5698] FS: 00007f75dc943800(0000) GS:ffff888036180000(0000) knlGS:0000000000000000 [ 1135.907398][ T5698] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1135.907643][ T5698] CR2: 00000000004e28e0 CR3: 0000000006100002 CR4: 0000000000772ef0 [ 1135.907921][ T5698] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1135.908195][ T5698] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 1135.908483][ T5698] PKRU: 55555554 [ 1135.908622][ T5698] Kernel panic - not syncing: Fatal exception in interrupt [ 1135.908994][ T5698] Kernel Offset: 0x1800000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 1135.909413][ T5698] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr