[ 14.857487][ T300] 8021q: 802.1Q VLAN Support v1.8 [ 19.395183][ T350] br1: port 1(vx10) entered blocking state [ 19.395718][ T350] br1: port 1(vx10) entered disabled state [ 19.396212][ T350] vx10: entered allmulticast mode [ 19.398491][ T350] vx10: entered promiscuous mode [ 19.399817][ T350] br1: port 1(vx10) entered blocking state [ 19.400205][ T350] br1: port 1(vx10) entered forwarding state [ 19.796582][ T355] br1: port 2(vx20) entered blocking state [ 19.796898][ T355] br1: port 2(vx20) entered disabled state [ 19.797209][ T355] vx20: entered allmulticast mode [ 19.799255][ T355] vx20: entered promiscuous mode [ 19.800508][ T355] br1: port 2(vx20) entered blocking state [ 19.800914][ T355] br1: port 2(vx20) entered forwarding state [ 19.996795][ T357] br1: port 3(veth1) entered blocking state [ 19.997157][ T357] br1: port 3(veth1) entered disabled state [ 19.997594][ T357] veth1: entered allmulticast mode [ 20.000532][ T357] veth1: entered promiscuous mode [ 20.104888][ T55] br1: port 3(veth1) entered blocking state [ 20.105355][ T55] br1: port 3(veth1) entered forwarding state [ 20.504187][ T363] br1: port 4(veth2) entered blocking state [ 20.504530][ T363] br1: port 4(veth2) entered disabled state [ 20.504818][ T363] veth2: entered allmulticast mode [ 20.513923][ T363] veth2: entered promiscuous mode [ 20.597060][ T55] br1: port 4(veth2) entered blocking state [ 20.597541][ T55] br1: port 4(veth2) entered forwarding state [ 24.476828][ T413] br2: port 1(w1) entered blocking state [ 24.477187][ T413] br2: port 1(w1) entered disabled state [ 24.477449][ T413] w1: entered allmulticast mode [ 24.479943][ T413] w1: entered promiscuous mode [ 25.171805][ T421] br2: port 2(vx10) entered blocking state [ 25.172849][ T421] br2: port 2(vx10) entered disabled state [ 25.173339][ T421] vx10: entered allmulticast mode [ 25.176598][ T421] vx10: entered promiscuous mode [ 25.177509][ T421] br2: port 2(vx10) entered blocking state [ 25.177911][ T421] br2: port 2(vx10) entered forwarding state [ 25.797245][ T428] br2: port 3(vx20) entered blocking state [ 25.797523][ T428] br2: port 3(vx20) entered disabled state [ 25.797823][ T428] vx20: entered allmulticast mode [ 25.799805][ T428] vx20: entered promiscuous mode [ 25.800394][ T428] br2: port 3(vx20) entered blocking state [ 25.800638][ T428] br2: port 3(vx20) entered forwarding state [ 26.636872][ T40] br2: port 1(w1) entered blocking state [ 26.637293][ T40] br2: port 1(w1) entered forwarding state [ 29.278942][ T470] br2: port 1(w1) entered blocking state [ 29.279291][ T470] br2: port 1(w1) entered disabled state [ 29.279546][ T470] w1: entered allmulticast mode [ 29.281497][ T470] w1: entered promiscuous mode [ 29.997574][ T478] br2: port 2(vx10) entered blocking state [ 29.997877][ T478] br2: port 2(vx10) entered disabled state [ 29.998186][ T478] vx10: entered allmulticast mode [ 30.000639][ T478] vx10: entered promiscuous mode [ 30.001301][ T478] br2: port 2(vx10) entered blocking state [ 30.001556][ T478] br2: port 2(vx10) entered forwarding state [ 30.801102][ T485] br2: port 3(vx20) entered blocking state [ 30.801428][ T485] br2: port 3(vx20) entered disabled state [ 30.801740][ T485] vx20: entered allmulticast mode [ 30.804154][ T485] vx20: entered promiscuous mode [ 30.804750][ T485] br2: port 3(vx20) entered blocking state [ 30.805003][ T485] br2: port 3(vx20) entered forwarding state [ 31.627591][ T40] br2: port 1(w1) entered blocking state [ 31.627922][ T40] br2: port 1(w1) entered forwarding state [ 43.166492][ T572] GACT probability NOT on [ 181.006285][ T1373] veth3: entered promiscuous mode [ 238.886402][ T2300] veth3: left promiscuous mode [ 239.448687][ T2306] veth3: entered promiscuous mode [ 295.619940][ T3233] veth3: left promiscuous mode [ 296.721252][ T3251] vx20: left allmulticast mode [ 296.721683][ T3251] vx20: left promiscuous mode [ 296.722295][ T3251] br1: port 2(vx20) entered disabled state [ 296.842693][ T3252] vx10: left allmulticast mode [ 296.843078][ T3252] vx10: left promiscuous mode [ 296.843463][ T3252] br1: port 1(vx10) entered disabled state [ 302.309188][ T3257] br1: port 1(vx10) entered blocking state [ 302.309632][ T3257] br1: port 1(vx10) entered disabled state [ 302.309959][ T3257] vx10: entered allmulticast mode [ 302.312323][ T3257] vx10: entered promiscuous mode [ 302.312937][ T3257] br1: port 1(vx10) entered blocking state [ 302.313289][ T3257] br1: port 1(vx10) entered forwarding state [ 302.519751][ T3259] br1: port 2(vx20) entered blocking state [ 302.520177][ T3259] br1: port 2(vx20) entered disabled state [ 302.520630][ T3259] vx20: entered allmulticast mode [ 302.524584][ T3259] vx20: entered promiscuous mode [ 302.525193][ T3259] br1: port 2(vx20) entered blocking state [ 302.525456][ T3259] br1: port 2(vx20) entered forwarding state [ 444.618154][ T4087] veth3: entered promiscuous mode [ 500.514338][ T5014] veth3: left promiscuous mode [ 501.102026][ T5020] veth3: entered promiscuous mode [ 558.080705][ T5948] veth3: left promiscuous mode [ 901.578673][ T11] vx20: left allmulticast mode [ 901.579065][ T11] vx20: left promiscuous mode [ 901.579550][ T11] br2: port 3(vx20) entered disabled state [ 901.582629][ T11] vx10: left allmulticast mode [ 901.582923][ T11] vx10: left promiscuous mode [ 901.583253][ T11] br2: port 2(vx10) entered disabled state [ 901.585378][ T11] w1: left allmulticast mode [ 901.585591][ T11] w1: left promiscuous mode [ 901.585937][ T11] br2: port 1(w1) entered disabled state [ 902.083072][ T11] vx20: left allmulticast mode [ 902.083367][ T11] vx20: left promiscuous mode [ 902.083720][ T11] br2: port 3(vx20) entered disabled state [ 902.086554][ T11] vx10: left allmulticast mode [ 902.086813][ T11] vx10: left promiscuous mode [ 902.087179][ T11] br2: port 2(vx10) entered disabled state [ 902.088800][ T11] w1: left allmulticast mode [ 902.089024][ T11] w1: left promiscuous mode [ 902.089377][ T11] br2: port 1(w1) entered disabled state [ 902.468709][ T11] ================================================================== [ 902.468959][ T11] BUG: KASAN: slab-use-after-free in cleanup_net+0x932/0xa40 [ 902.469193][ T11] Read of size 8 at addr ffff888005191a38 by task kworker/u16:0/11 [ 902.469397][ T11] [ 902.469467][ T11] CPU: 2 UID: 0 PID: 11 Comm: kworker/u16:0 Not tainted 6.12.0-virtme #1 [ 902.469674][ T11] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 902.469869][ T11] Workqueue: netns cleanup_net [ 902.470020][ T11] Call Trace: [ 902.470127][ T11] [ 902.470215][ T11] dump_stack_lvl+0x82/0xd0 [ 902.470366][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 902.470553][ T11] ? cleanup_net+0x932/0xa40 [ 902.470693][ T11] print_report+0xb4/0x270 [ 902.470834][ T11] ? kasan_addr_to_slab+0x25/0x80 [ 902.470973][ T11] kasan_report+0xbd/0xf0 [ 902.471080][ T11] ? cleanup_net+0x932/0xa40 [ 902.471222][ T11] cleanup_net+0x932/0xa40 [ 902.471364][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 902.471516][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 902.471662][ T11] ? trace_lock_acquire+0x148/0x1f0 [ 902.471802][ T11] ? lock_acquire+0x32/0xc0 [ 902.471944][ T11] ? process_one_work+0xe0b/0x16d0 [ 902.472087][ T11] process_one_work+0xe55/0x16d0 [ 902.472235][ T11] ? __pfx___lock_release+0x10/0x10 [ 902.472376][ T11] ? __pfx_process_one_work+0x10/0x10 [ 902.472521][ T11] ? assign_work+0x16c/0x240 [ 902.472667][ T11] worker_thread+0x58c/0xce0 [ 902.472812][ T11] ? __pfx_worker_thread+0x10/0x10 [ 902.472950][ T11] kthread+0x28a/0x350 [ 902.473057][ T11] ? __pfx_kthread+0x10/0x10 [ 902.473200][ T11] ret_from_fork+0x31/0x70 [ 902.473343][ T11] ? __pfx_kthread+0x10/0x10 [ 902.473483][ T11] ret_from_fork_asm+0x1a/0x30 [ 902.473626][ T11] [ 902.473736][ T11] [ 902.473807][ T11] Allocated by task 449: [ 902.473911][ T11] kasan_save_stack+0x24/0x50 [ 902.474052][ T11] kasan_save_track+0x14/0x30 [ 902.474196][ T11] __kasan_slab_alloc+0x59/0x70 [ 902.474335][ T11] kmem_cache_alloc_noprof+0x10b/0x350 [ 902.474478][ T11] copy_net_ns+0xc6/0x340 [ 902.474579][ T11] create_new_namespaces+0x35f/0x920 [ 902.474725][ T11] unshare_nsproxy_namespaces+0x8d/0x130 [ 902.474859][ T11] ksys_unshare+0x2a9/0x660 [ 902.475001][ T11] __x64_sys_unshare+0x31/0x40 [ 902.475139][ T11] do_syscall_64+0xc1/0x1d0 [ 902.475303][ T11] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 902.475476][ T11] [ 902.475551][ T11] Freed by task 11: [ 902.475654][ T11] kasan_save_stack+0x24/0x50 [ 902.475802][ T11] kasan_save_track+0x14/0x30 [ 902.475934][ T11] kasan_save_free_info+0x3b/0x60 [ 902.476072][ T11] __kasan_slab_free+0x38/0x50 [ 902.476218][ T11] kmem_cache_free+0xf8/0x330 [ 902.476353][ T11] cleanup_net+0x5a8/0xa40 [ 902.476503][ T11] process_one_work+0xe55/0x16d0 [ 902.476687][ T11] worker_thread+0x58c/0xce0 [ 902.476874][ T11] kthread+0x28a/0x350 [ 902.477036][ T11] ret_from_fork+0x31/0x70 [ 902.477241][ T11] ret_from_fork_asm+0x1a/0x30 [ 902.477435][ T11] [ 902.477545][ T11] Last potentially related work creation: [ 902.477742][ T11] kasan_save_stack+0x24/0x50 [ 902.477951][ T11] __kasan_record_aux_stack+0x8e/0xa0 [ 902.478166][ T11] insert_work+0x34/0x230 [ 902.478311][ T11] __queue_work+0x5fd/0xa40 [ 902.478521][ T11] call_timer_fn+0x13b/0x230 [ 902.478705][ T11] __run_timers+0x3ff/0x810 [ 902.478886][ T11] run_timer_softirq+0x154/0x1c0 [ 902.479077][ T11] handle_softirqs+0x1f6/0x5c0 [ 902.479268][ T11] __irq_exit_rcu+0xc4/0x100 [ 902.479462][ T11] irq_exit_rcu+0xe/0x20 [ 902.479608][ T11] sysvec_apic_timer_interrupt+0x78/0x90 [ 902.479847][ T11] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 902.480095][ T11] [ 902.480193][ T11] Second to last potentially related work creation: [ 902.480419][ T11] kasan_save_stack+0x24/0x50 [ 902.480616][ T11] __kasan_record_aux_stack+0x8e/0xa0 [ 902.480807][ T11] insert_work+0x34/0x230 [ 902.480950][ T11] __queue_work+0x5fd/0xa40 [ 902.481140][ T11] call_timer_fn+0x13b/0x230 [ 902.481341][ T11] __run_timers+0x3ff/0x810 [ 902.481615][ T11] run_timer_softirq+0x154/0x1c0 [ 902.481807][ T11] handle_softirqs+0x1f6/0x5c0 [ 902.481992][ T11] __irq_exit_rcu+0xc4/0x100 [ 902.482181][ T11] irq_exit_rcu+0xe/0x20 [ 902.482329][ T11] sysvec_apic_timer_interrupt+0x78/0x90 [ 902.482522][ T11] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 902.482755][ T11] [ 902.482861][ T11] The buggy address belongs to the object at ffff888005191980 [ 902.482861][ T11] which belongs to the cache net_namespace of size 6080 [ 902.483392][ T11] The buggy address is located 184 bytes inside of [ 902.483392][ T11] freed 6080-byte region [ffff888005191980, ffff888005193140) [ 902.483884][ T11] [ 902.483997][ T11] The buggy address belongs to the physical page: [ 902.484249][ T11] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff8880051932c0 pfn:0x5190 [ 902.484670][ T11] head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 902.484955][ T11] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 902.485212][ T11] page_type: f5(slab) [ 902.485373][ T11] raw: 0080000000000240 ffff888001963240 ffff888001968088 ffff888001968088 [ 902.485662][ T11] raw: ffff8880051932c0 0000000000050002 00000001f5000000 0000000000000000 [ 902.485898][ T11] head: 0080000000000240 ffff888001963240 ffff888001968088 ffff888001968088 [ 902.486136][ T11] head: ffff8880051932c0 0000000000050002 00000001f5000000 0000000000000000 [ 902.486376][ T11] head: 0080000000000003 ffffea0000146401 ffffffffffffffff 0000000000000000 [ 902.486601][ T11] head: 0000000000000008 0000000000000000 00000000ffffffff 0000000000000000 [ 902.486815][ T11] page dumped because: kasan: bad access detected [ 902.486971][ T11] [ 902.487035][ T11] Memory state around the buggy address: [ 902.487163][ T11] ffff888005191900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 902.487349][ T11] ffff888005191980: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 902.487526][ T11] >ffff888005191a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 902.487715][ T11] ^ [ 902.487873][ T11] ffff888005191a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 902.488059][ T11] ffff888005191b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 902.488244][ T11] ================================================================== [ 902.488550][ T11] Disabling lock debugging due to kernel taint [ 904.165055][T10513] br1: port 4(veth2) entered disabled state [ 904.227041][T10514] veth2: left allmulticast mode [ 904.227323][T10514] veth2: left promiscuous mode [ 904.227628][T10514] br1: port 4(veth2) entered disabled state [ 904.526073][T10518] br1: port 3(veth1) entered disabled state [ 904.595881][T10519] veth1: left allmulticast mode [ 904.596390][T10519] veth1: left promiscuous mode [ 904.596707][T10519] br1: port 3(veth1) entered disabled state [ 904.723170][T10521] vx20: left allmulticast mode [ 904.723416][T10521] vx20: left promiscuous mode [ 904.723708][T10521] br1: port 2(vx20) entered disabled state [ 905.053940][T10525] vx10: left allmulticast mode [ 905.054252][T10525] vx10: left promiscuous mode [ 905.054548][T10525] br1: port 1(vx10) entered disabled state