[ 15.139732][ T268] ip (268) used greatest stack depth: 24448 bytes left [ 16.742027][ T281] link0: entered promiscuous mode [ 17.747198][ T281] link0: left promiscuous mode [ 18.152838][ T292] ================================================================== [ 18.153145][ T292] BUG: KASAN: null-ptr-deref in try_to_grab_pending+0x81/0x6c0 [ 18.153412][ T292] Write of size 8 at addr 0000000000000000 by task ip/292 [ 18.153627][ T292] [ 18.153722][ T292] CPU: 1 UID: 0 PID: 292 Comm: ip Not tainted 6.18.0-rc5-virtme #1 PREEMPT(full) [ 18.153727][ T292] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 18.153729][ T292] Call Trace: [ 18.153731][ T292] [ 18.153732][ T292] dump_stack_lvl+0x82/0xc0 [ 18.153740][ T292] ? try_to_grab_pending+0x81/0x6c0 [ 18.153743][ T292] kasan_report+0xca/0x100 [ 18.153750][ T292] ? try_to_grab_pending+0x81/0x6c0 [ 18.153755][ T292] kasan_check_range+0x39/0x1b0 [ 18.153759][ T292] try_to_grab_pending+0x81/0x6c0 [ 18.153764][ T292] __cancel_work+0x7c/0x260 [ 18.153767][ T292] ? enable_delayed_work+0x10/0x10 [ 18.153772][ T292] ? queue_delayed_work_on+0x6a/0xa0 [ 18.153777][ T292] __cancel_work_sync+0x18/0xc0 [ 18.153781][ T292] __dev_close_many+0x1cf/0x980 [ 18.153786][ T292] ? netdev_notify_peers+0x20/0x20 [ 18.153789][ T292] ? netif_close_many+0x201/0x650 [ 18.153794][ T292] netif_close_many+0x201/0x650 [ 18.153797][ T292] ? __mutex_handoff+0x2b0/0x2b0 [ 18.153802][ T292] ? __dev_close_many+0x980/0x980 [ 18.153805][ T292] ? netif_close_many_and_unlock+0x21/0x2a0 [ 18.153810][ T292] unregister_netdevice_many_notify+0x30a/0x1c90 [ 18.153814][ T292] ? rtnl_dellink+0x227/0xa30 [ 18.153820][ T292] ? mutex_is_locked+0x1c/0x50 [ 18.153823][ T292] ? dev_ingress_queue_create+0x190/0x190 [ 18.153826][ T292] ? rtnl_is_locked+0x15/0x20 [ 18.153829][ T292] ? unregister_netdevice_queue+0x6f/0x410 [ 18.153832][ T292] ? unregister_netdevice_many+0x20/0x20 [ 18.153835][ T292] ? unregister_netdevice_many+0x20/0x20 [ 18.153841][ T292] rtnl_dellink+0x344/0xa30 [ 18.153846][ T292] ? valid_bridge_getlink_req.constprop.0+0x640/0x640 [ 18.153866][ T292] ? find_held_lock+0x2b/0x80 [ 18.153871][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.153877][ T292] ? find_held_lock+0x2b/0x80 [ 18.153881][ T292] ? rtnetlink_rcv_msg+0x6e6/0xc00 [ 18.153883][ T292] ? __lock_release+0x5d/0x170 [ 18.153887][ T292] ? valid_bridge_getlink_req.constprop.0+0x640/0x640 [ 18.153891][ T292] rtnetlink_rcv_msg+0x709/0xc00 [ 18.153895][ T292] ? rtnl_port_fill+0x890/0x890 [ 18.153898][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.153905][ T292] netlink_rcv_skb+0x121/0x340 [ 18.153910][ T292] ? rtnl_port_fill+0x890/0x890 [ 18.153914][ T292] ? netlink_ack+0xdf0/0xdf0 [ 18.153920][ T292] ? netlink_deliver_tap+0x13e/0x340 [ 18.153923][ T292] ? netlink_deliver_tap+0xc3/0x340 [ 18.153926][ T292] netlink_unicast+0x4aa/0x780 [ 18.153930][ T292] ? netlink_attachskb+0x810/0x810 [ 18.153933][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.153938][ T292] netlink_sendmsg+0x714/0xbd0 [ 18.153942][ T292] ? netlink_unicast+0x780/0x780 [ 18.153945][ T292] ? __import_iovec+0x230/0x3b0 [ 18.153951][ T292] ? netlink_unicast+0x780/0x780 [ 18.153954][ T292] ____sys_sendmsg+0x3dd/0x890 [ 18.153958][ T292] ? get_timestamp.constprop.0+0x370/0x370 [ 18.153960][ T292] ? __copy_msghdr+0x3c0/0x3c0 [ 18.153968][ T292] ___sys_sendmsg+0xed/0x170 [ 18.153970][ T292] ? kasan_record_aux_stack+0x8c/0xa0 [ 18.153974][ T292] ? __call_rcu_common.constprop.0+0xa8/0x630 [ 18.153978][ T292] ? copy_msghdr_from_user+0x110/0x110 [ 18.153982][ T292] ? find_held_lock+0x2b/0x80 [ 18.153987][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.153992][ T292] ? find_held_lock+0x2b/0x80 [ 18.153996][ T292] ? __virt_addr_valid+0x22a/0x450 [ 18.154000][ T292] ? __lock_release+0x5d/0x170 [ 18.154006][ T292] __sys_sendmsg+0x10b/0x1a0 [ 18.154008][ T292] ? __call_rcu_common.constprop.0+0x318/0x630 [ 18.154011][ T292] ? __sys_sendmsg_sock+0x20/0x20 [ 18.154018][ T292] ? rcu_is_watching+0x12/0xb0 [ 18.154023][ T292] do_syscall_64+0xc1/0xfd0 [ 18.154027][ T292] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 18.154031][ T292] RIP: 0033:0x7fcc911841d7 [ 18.154035][ T292] Code: 0e 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 [ 18.154038][ T292] RSP: 002b:00007ffd0f4e10a8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 18.154043][ T292] RAX: ffffffffffffffda RBX: 00007ffd0f4e17e0 RCX: 00007fcc911841d7 [ 18.154046][ T292] RDX: 0000000000000000 RSI: 00007ffd0f4e1110 RDI: 0000000000000005 [ 18.154048][ T292] RBP: 0000000000000001 R08: 0000000000000003 R09: 0000000000000078 [ 18.154050][ T292] R10: 00007fcc91080510 R11: 0000000000000246 R12: 0000000000000001 [ 18.154053][ T292] R13: 00000000691cdcd9 R14: 0000000000499600 R15: 0000000000000000 [ 18.154062][ T292] [ 18.154063][ T292] ================================================================== [ 18.168844][ T292] Disabling lock debugging due to kernel taint [ 18.169062][ T292] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 18.169306][ T292] #PF: supervisor write access in kernel mode [ 18.169509][ T292] #PF: error_code(0x0002) - not-present page [ 18.169714][ T292] PGD 2331067 P4D 2331067 PUD 9652067 PMD 0 [ 18.169926][ T292] Oops: Oops: 0002 [#1] SMP KASAN [ 18.170101][ T292] CPU: 1 UID: 0 PID: 292 Comm: ip Tainted: G B 6.18.0-rc5-virtme #1 PREEMPT(full) [ 18.170441][ T292] Tainted: [B]=BAD_PAGE [ 18.170567][ T292] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 18.170775][ T292] RIP: 0010:try_to_grab_pending+0x81/0x6c0 [ 18.170990][ T292] Code: 00 41 89 c0 b8 01 00 00 00 45 85 c0 74 0f 48 83 c4 10 5b 5d 41 5c 41 5d 41 5e 41 5f c3 be 08 00 00 00 48 89 df e8 1f 93 82 00 48 0f ba 2b 00 72 11 48 83 c4 10 31 c0 5b 5d 41 5c 41 5d 41 5e [ 18.171584][ T292] RSP: 0018:ffffc90000d76f08 EFLAGS: 00010046 [ 18.171899][ T292] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffffab449b8a [ 18.172157][ T292] RDX: fffffbfff602cacd RSI: 0000000000000008 RDI: ffffffffb0165660 [ 18.172404][ T292] RBP: ffffc90000d76f70 R08: 0000000000000001 R09: fffffbfff602cacc [ 18.172768][ T292] R10: ffffffffb0165667 R11: ffffc90000d769c0 R12: 0000000000000000 [ 18.173015][ T292] R13: 0000000000000282 R14: ffff88800ef11000 R15: dffffc0000000000 [ 18.173267][ T292] FS: 00007fcc90fb6800(0000) GS:ffff8880b6987000(0000) knlGS:0000000000000000 [ 18.173657][ T292] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 18.173870][ T292] CR2: 0000000000000000 CR3: 00000000096c7001 CR4: 0000000000772ef0 [ 18.174228][ T292] PKRU: 55555554 [ 18.174353][ T292] Call Trace: [ 18.174476][ T292] [ 18.174561][ T292] __cancel_work+0x7c/0x260 [ 18.174726][ T292] ? enable_delayed_work+0x10/0x10 [ 18.174994][ T292] ? queue_delayed_work_on+0x6a/0xa0 [ 18.175169][ T292] __cancel_work_sync+0x18/0xc0 [ 18.175334][ T292] __dev_close_many+0x1cf/0x980 [ 18.175500][ T292] ? netdev_notify_peers+0x20/0x20 [ 18.175764][ T292] ? netif_close_many+0x201/0x650 [ 18.175929][ T292] netif_close_many+0x201/0x650 [ 18.176098][ T292] ? __mutex_handoff+0x2b0/0x2b0 [ 18.176264][ T292] ? __dev_close_many+0x980/0x980 [ 18.176429][ T292] ? netif_close_many_and_unlock+0x21/0x2a0 [ 18.176637][ T292] unregister_netdevice_many_notify+0x30a/0x1c90 [ 18.176844][ T292] ? rtnl_dellink+0x227/0xa30 [ 18.177011][ T292] ? mutex_is_locked+0x1c/0x50 [ 18.177281][ T292] ? dev_ingress_queue_create+0x190/0x190 [ 18.177446][ T292] ? rtnl_is_locked+0x15/0x20 [ 18.177609][ T292] ? unregister_netdevice_queue+0x6f/0x410 [ 18.177913][ T292] ? unregister_netdevice_many+0x20/0x20 [ 18.178089][ T292] ? unregister_netdevice_many+0x20/0x20 [ 18.178257][ T292] rtnl_dellink+0x344/0xa30 [ 18.178422][ T292] ? valid_bridge_getlink_req.constprop.0+0x640/0x640 [ 18.178739][ T292] ? find_held_lock+0x2b/0x80 [ 18.178905][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.179075][ T292] ? find_held_lock+0x2b/0x80 [ 18.179239][ T292] ? rtnetlink_rcv_msg+0x6e6/0xc00 [ 18.179507][ T292] ? __lock_release+0x5d/0x170 [ 18.179673][ T292] ? valid_bridge_getlink_req.constprop.0+0x640/0x640 [ 18.179876][ T292] rtnetlink_rcv_msg+0x709/0xc00 [ 18.180045][ T292] ? rtnl_port_fill+0x890/0x890 [ 18.180311][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.180478][ T292] netlink_rcv_skb+0x121/0x340 [ 18.180642][ T292] ? rtnl_port_fill+0x890/0x890 [ 18.180809][ T292] ? netlink_ack+0xdf0/0xdf0 [ 18.181084][ T292] ? netlink_deliver_tap+0x13e/0x340 [ 18.181249][ T292] ? netlink_deliver_tap+0xc3/0x340 [ 18.181413][ T292] netlink_unicast+0x4aa/0x780 [ 18.181578][ T292] ? netlink_attachskb+0x810/0x810 [ 18.181843][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.182008][ T292] netlink_sendmsg+0x714/0xbd0 [ 18.182178][ T292] ? netlink_unicast+0x780/0x780 [ 18.182344][ T292] ? __import_iovec+0x230/0x3b0 [ 18.182623][ T292] ? netlink_unicast+0x780/0x780 [ 18.182787][ T292] ____sys_sendmsg+0x3dd/0x890 [ 18.182951][ T292] ? get_timestamp.constprop.0+0x370/0x370 [ 18.183159][ T292] ? __copy_msghdr+0x3c0/0x3c0 [ 18.183427][ T292] ___sys_sendmsg+0xed/0x170 [ 18.183590][ T292] ? kasan_record_aux_stack+0x8c/0xa0 [ 18.183759][ T292] ? __call_rcu_common.constprop.0+0xa8/0x630 [ 18.184070][ T292] ? copy_msghdr_from_user+0x110/0x110 [ 18.184236][ T292] ? find_held_lock+0x2b/0x80 [ 18.184400][ T292] ? __lock_acquire+0x449/0x7e0 [ 18.184566][ T292] ? find_held_lock+0x2b/0x80 [ 18.184829][ T292] ? __virt_addr_valid+0x22a/0x450 [ 18.184994][ T292] ? __lock_release+0x5d/0x170 [ 18.185166][ T292] __sys_sendmsg+0x10b/0x1a0 [ 18.185333][ T292] ? __call_rcu_common.constprop.0+0x318/0x630 [ 18.185635][ T292] ? __sys_sendmsg_sock+0x20/0x20 [ 18.185802][ T292] ? rcu_is_watching+0x12/0xb0 [ 18.185966][ T292] do_syscall_64+0xc1/0xfd0 [ 18.186138][ T292] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 18.186443][ T292] RIP: 0033:0x7fcc911841d7 [ 18.186612][ T292] Code: 0e 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 [ 18.187312][ T292] RSP: 002b:00007ffd0f4e10a8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 18.187561][ T292] RAX: ffffffffffffffda RBX: 00007ffd0f4e17e0 RCX: 00007fcc911841d7 [ 18.187911][ T292] RDX: 0000000000000000 RSI: 00007ffd0f4e1110 RDI: 0000000000000005 [ 18.188167][ T292] RBP: 0000000000000001 R08: 0000000000000003 R09: 0000000000000078 [ 18.188413][ T292] R10: 00007fcc91080510 R11: 0000000000000246 R12: 0000000000000001 [ 18.188762][ T292] R13: 00000000691cdcd9 R14: 0000000000499600 R15: 0000000000000000 [ 18.189011][ T292] [ 18.189139][ T292] Modules linked in: [ 18.189272][ T292] CR2: 0000000000000000 [ 18.189490][ T292] ---[ end trace 0000000000000000 ]--- [ 18.189656][ T292] RIP: 0010:try_to_grab_pending+0x81/0x6c0 [ 18.189867][ T292] Code: 00 41 89 c0 b8 01 00 00 00 45 85 c0 74 0f 48 83 c4 10 5b 5d 41 5c 41 5d 41 5e 41 5f c3 be 08 00 00 00 48 89 df e8 1f 93 82 00 48 0f ba 2b 00 72 11 48 83 c4 10 31 c0 5b 5d 41 5c 41 5d 41 5e [ 18.190558][ T292] RSP: 0018:ffffc90000d76f08 EFLAGS: 00010046 [ 18.190766][ T292] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffffab449b8a [ 18.191115][ T292] RDX: fffffbfff602cacd RSI: 0000000000000008 RDI: ffffffffb0165660 [ 18.191359][ T292] RBP: ffffc90000d76f70 R08: 0000000000000001 R09: fffffbfff602cacc [ 18.191610][ T292] R10: ffffffffb0165667 R11: ffffc90000d769c0 R12: 0000000000000000 [ 18.191955][ T292] R13: 0000000000000282 R14: ffff88800ef11000 R15: dffffc0000000000 [ 18.192205][ T292] FS: 00007fcc90fb6800(0000) GS:ffff8880b6987000(0000) knlGS:0000000000000000 [ 18.192489][ T292] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 18.192704][ T292] CR2: 0000000000000000 CR3: 00000000096c7001 CR4: 0000000000772ef0 [ 18.192951][ T292] PKRU: 55555554 [ 18.193183][ T292] Kernel panic - not syncing: Fatal exception [ 18.193463][ T292] Kernel Offset: 0x29e00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 18.193851][ T292] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr