====================================== | xx__-> [ 5869.247411][ T276] ================================================================== | [ 5869.247758][ T276] BUG: KASAN: slab-use-after-free in unix_vertex_dead (net/unix/garbage.c:119 net/unix/garbage.c:323) | [ 5869.248001][ T276] Read of size 8 at addr ffff888017d29850 by task kworker/u18:2/276 | [ 5869.248232][ T276] [ 5869.248319][ T276] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 5869.248322][ T276] Workqueue: events_unbound __unix_gc [ 5869.248327][ T276] Call Trace: [ 5869.248329][ T276] [ 5869.248331][ T276] dump_stack_lvl (lib/dump_stack.c:123) [ 5869.248341][ T276] print_address_description.constprop.0 (mm/kasan/report.c:409) [ 5869.248350][ T276] ? unix_vertex_dead (net/unix/garbage.c:119 net/unix/garbage.c:323) [ 5869.248354][ T276] print_report (mm/kasan/report.c:522) [ 5869.248358][ T276] ? unix_vertex_dead (net/unix/garbage.c:119 net/unix/garbage.c:323) [ 5869.248361][ T276] ? kasan_addr_to_slab (./include/linux/mm.h:1178 mm/kasan/../slab.h:211 mm/kasan/common.c:38) [ 5869.248365][ T276] ? unix_vertex_dead (net/unix/garbage.c:119 net/unix/garbage.c:323) [ 5869.248368][ T276] kasan_report (mm/kasan/report.c:636) [ 5869.248372][ T276] ? unix_vertex_dead (net/unix/garbage.c:119 net/unix/garbage.c:323) [ 5869.248377][ T276] unix_vertex_dead (net/unix/garbage.c:119 net/unix/garbage.c:323) [ 5869.248382][ T276] unix_walk_scc_fast (net/unix/garbage.c:543) [ 5869.248386][ T276] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 5869.248394][ T276] ? __pfx_unix_walk_scc_fast (net/unix/garbage.c:528) [ 5869.248397][ T276] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 5869.248400][ T276] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5834) [ 5869.248403][ T276] ? __unix_gc (net/unix/garbage.c:566) [ 5869.248408][ T276] __unix_gc (./include/linux/spinlock.h:391 net/unix/garbage.c:578) [ 5869.248412][ T276] ? __pfx___unix_gc (net/unix/garbage.c:560) [ 5869.248419][ T276] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 5869.248427][ T276] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 5869.248431][ T276] process_one_work (kernel/workqueue.c:3243) [ 5869.248440][ T276] ? __pfx_process_one_work (kernel/workqueue.c:3140) [ 5869.248446][ T276] ? assign_work (kernel/workqueue.c:1200) [ 5869.248453][ T276] worker_thread (kernel/workqueue.c:3315 kernel/workqueue.c:3402) [ 5869.248459][ T276] ? __pfx_worker_thread (kernel/workqueue.c:3348) [ 5869.248462][ T276] kthread (kernel/kthread.c:464) [ 5869.248466][ T276] ? __pfx_kthread (kernel/kthread.c:413) [ 5869.248469][ T276] ? ret_from_fork (arch/x86/kernel/process.c:147) [ 5869.248475][ T276] ? __lock_release (kernel/locking/lockdep.c:5539) [ 5869.248479][ T276] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 5869.248482][ T276] ? __pfx_kthread (kernel/kthread.c:413) [ 5869.248485][ T276] ret_from_fork (arch/x86/kernel/process.c:148) [ 5869.248488][ T276] ? __pfx_kthread (kernel/kthread.c:413) Finger prints: print_report:kasan_report:unix_vertex_dead:unix_walk_scc_fast:__unix_gc