====================================== | xx__-> [ 5716.340166][T26625] ================================================================== | [5716.340494][T26625] BUG: KASAN: slab-use-after-free in __unix_walk_scc (net/unix/garbage.c:119 net/unix/garbage.c:425) | [ 5716.340761][T26625] Read of size 8 at addr ffff88801d8c6fd0 by task kworker/u17:0/26625 | [ 5716.341015][T26625] [ 5716.341109][T26625] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 5716.341112][T26625] Workqueue: events_unbound __unix_gc [ 5716.341118][T26625] Call Trace: [ 5716.341120][T26625] [5716.341123][T26625] dump_stack_lvl (lib/dump_stack.c:123) [5716.341133][T26625] print_address_description.constprop.0 (mm/kasan/report.c:409) [5716.341141][T26625] ? __unix_walk_scc (net/unix/garbage.c:119 net/unix/garbage.c:425) [5716.341145][T26625] print_report (mm/kasan/report.c:522) [5716.341148][T26625] ? __unix_walk_scc (net/unix/garbage.c:119 net/unix/garbage.c:425) [5716.341152][T26625] ? kasan_addr_to_slab (./include/linux/mm.h:1178 mm/kasan/../slab.h:211 mm/kasan/common.c:38) [5716.341155][T26625] ? __unix_walk_scc (net/unix/garbage.c:119 net/unix/garbage.c:425) [5716.341158][T26625] kasan_report (mm/kasan/report.c:636) [5716.341163][T26625] ? __unix_walk_scc (net/unix/garbage.c:119 net/unix/garbage.c:425) [5716.341168][T26625] __unix_walk_scc (net/unix/garbage.c:119 net/unix/garbage.c:425) [5716.341174][T26625] ? __pfx___unix_walk_scc (net/unix/garbage.c:407) [5716.341178][T26625] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [5716.341185][T26625] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [5716.341189][T26625] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5834) [5716.341192][T26625] ? __unix_gc (net/unix/garbage.c:566) [5716.341197][T26625] __unix_gc (./include/linux/list.h:373 net/unix/garbage.c:514 net/unix/garbage.c:576) [5716.341201][T26625] ? __pfx___unix_gc (net/unix/garbage.c:560) [5716.341207][T26625] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [5716.341215][T26625] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [5716.341219][T26625] process_one_work (kernel/workqueue.c:3243) [5716.341228][T26625] ? __pfx_process_one_work (kernel/workqueue.c:3140) [5716.341233][T26625] ? assign_work (kernel/workqueue.c:1200) [5716.341241][T26625] worker_thread (kernel/workqueue.c:3315 kernel/workqueue.c:3402) [5716.341246][T26625] ? __pfx_worker_thread (kernel/workqueue.c:3348) [5716.341250][T26625] kthread (kernel/kthread.c:464) [5716.341254][T26625] ? __pfx_kthread (kernel/kthread.c:413) [5716.341256][T26625] ? ret_from_fork (arch/x86/kernel/process.c:147) [5716.341261][T26625] ? __lock_release (kernel/locking/lockdep.c:5539) [5716.341265][T26625] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [5716.341268][T26625] ? __pfx_kthread (kernel/kthread.c:413) [5716.341271][T26625] ret_from_fork (arch/x86/kernel/process.c:148) [5716.341274][T26625] ? __pfx_kthread (kernel/kthread.c:413) Finger prints: print_report:kasan_report:__unix_walk_scc:__unix_gc:process_one_work