[ 23.922116][ C0] ================================================================== [ 23.922351][ C0] BUG: KASAN: null-ptr-deref in sock_def_write_space_wfree+0x210/0x370 [ 23.922570][ C0] Read of size 8 at addr 0000000000000008 by task cmsg_sender/254 [ 23.922783][ C0] [ 23.922868][ C0] CPU: 0 PID: 254 Comm: cmsg_sender Not tainted 6.9.0-rc2-virtme #1 [ 23.923081][ C0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 23.923390][ C0] Call Trace: [ 23.923501][ C0] <IRQ> [ 23.923573][ C0] dump_stack_lvl+0x82/0xd0 [ 23.923719][ C0] kasan_report+0xbd/0xf0 [ 23.923827][ C0] ? sock_def_write_space_wfree+0x210/0x370 [ 23.924006][ C0] kasan_check_range+0x39/0x1c0 [ 23.924155][ C0] sock_def_write_space_wfree+0x210/0x370 [ 23.924294][ C0] sock_wfree+0x25f/0x3e0 [ 23.924401][ C0] skb_release_head_state+0x7a/0x1e0 [ 23.924541][ C0] consume_skb+0x76/0x110 [ 23.924646][ C0] dummy_xmit+0x106/0x170 [ 23.924751][ C0] ? trace_net_dev_start_xmit+0xff/0x170 [ 23.924891][ C0] dev_hard_start_xmit+0x10e/0x360 [ 23.925034][ C0] sch_direct_xmit+0x203/0x11c0 [ 23.925178][ C0] ? __pfx_sch_direct_xmit+0x10/0x10 [ 23.925319][ C0] __qdisc_run+0x1cd/0x3d0 [ 23.925459][ C0] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 23.925601][ C0] ? __pfx___qdisc_run+0x10/0x10 [ 23.925740][ C0] ? do_raw_spin_lock+0x131/0x270 [ 23.925877][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 23.926016][ C0] ? lock_acquire+0x32/0xc0 [ 23.926156][ C0] ? net_tx_action+0x3a5/0x680 [ 23.926298][ C0] net_tx_action+0x3f6/0x680 [ 23.926438][ C0] __do_softirq+0x1f8/0x5df [ 23.926580][ C0] irq_exit_rcu+0x97/0xc0 [ 23.926687][ C0] sysvec_apic_timer_interrupt+0x75/0x80 [ 23.926826][ C0] </IRQ> [ 23.926899][ C0] <TASK> [ 23.926971][ C0] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 23.927175][ C0] RIP: 0010:_raw_spin_unlock_irqrestore+0x43/0x70 [ 23.927360][ C0] Code: 10 e8 a1 f0 78 fd 48 89 ef e8 d9 60 79 fd 81 e3 00 02 00 00 75 1d 9c 58 f6 c4 02 75 29 48 85 db 74 01 fb 65 ff 0d 05 4c ed 7b <74> 0e 5b 5d c3 cc cc cc cc e8 ff c0 9c fd eb dc 0f 1f 44 00 00 5b [ 23.927866][ C0] RSP: 0018:ffffc900005bfbd0 EFLAGS: 00000282 [ 23.928051][ C0] RAX: 0000000000000006 RBX: 0000000000000200 RCX: 1ffffffff0bb23a1 [ 23.928279][ C0] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff84167dd1 [ 23.928488][ C0] RBP: ffff88800196e180 R08: 0000000000000001 R09: fffffbfff0bb2c22 [ 23.928695][ C0] R10: ffffffff85d96117 R11: 0000000000000040 R12: ffff88800196e180 [ 23.928906][ C0] R13: ffffea0000146e00 R14: ffff88800196b3c0 R15: ffff8880051bd7c0 [ 23.929116][ C0] ? _raw_spin_unlock_irqrestore+0x51/0x70 [ 23.929291][ C0] get_partial_node.part.0+0x1c5/0x3a0 [ 23.929435][ C0] ___slab_alloc+0xb70/0x10a0 [ 23.929578][ C0] ? kmem_cache_alloc+0x42/0x270 [ 23.929720][ C0] ? getname_flags+0x53/0x3d0 [ 23.929860][ C0] ? __pfx___lock_release+0x10/0x10 [ 23.930007][ C0] ? getname_flags+0x53/0x3d0 [ 23.930147][ C0] ? kmem_cache_alloc+0x243/0x270 [ 23.930285][ C0] kmem_cache_alloc+0x243/0x270 [ 23.930425][ C0] getname_flags+0x53/0x3d0 [ 23.930566][ C0] do_sys_openat2+0xdb/0x160 [ 23.930707][ C0] ? vfs_fstatat+0x9e/0xc0 [ 23.930849][ C0] ? __pfx_do_sys_openat2+0x10/0x10 [ 23.930990][ C0] ? __pfx___do_sys_newfstatat+0x10/0x10 [ 23.931137][ C0] __x64_sys_openat+0x123/0x1e0 [ 23.931278][ C0] ? __pfx___x64_sys_openat+0x10/0x10 [ 23.931416][ C0] ? __pfx_do_faccessat+0x10/0x10 [ 23.931558][ C0] do_syscall_64+0xc6/0x1e0 [ 23.931698][ C0] entry_SYSCALL_64_after_hwframe+0x72/0x7a [ 23.931871][ C0] RIP: 0033:0x7fb5a33970e8 [ 23.932024][ C0] Code: f9 41 89 f0 41 83 e2 40 75 30 89 f0 25 00 00 41 00 3d 00 00 41 00 74 22 44 89 c2 4c 89 ce bf 9c ff ff ff b8 01 01 00 00 0f 05 <48> 3d 00 f0 ff ff 77 30 c3 0f 1f 80 00 00 00 00 48 8d 44 24 08 c7 [ 23.932542][ C0] RSP: 002b:00007ffe6ca08358 EFLAGS: 00000287 ORIG_RAX: 0000000000000101 [ 23.932757][ C0] RAX: ffffffffffffffda RBX: 00007ffe6ca085df RCX: 00007fb5a33970e8 [ 23.932970][ C0] RDX: 0000000000080000 RSI: 00007ffe6ca083d0 RDI: 00000000ffffff9c [ 23.933186][ C0] RBP: 00007ffe6ca083c0 R08: 0000000000080000 R09: 00007ffe6ca083d0 [ 23.933398][ C0] R10: 0000000000000000 R11: 0000000000000287 R12: 00007ffe6ca083d7 [ 23.933608][ C0] R13: 00007ffe6ca085f0 R14: 00007ffe6ca083d0 R15: 00007fb5a3368000 [ 23.933824][ C0] </TASK> [ 23.933932][ C0] ================================================================== [ 23.934154][ C0] Disabling lock debugging due to kernel taint [ 23.934349][ C0] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 23.934650][ C0] KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] [ 23.934853][ C0] CPU: 0 PID: 254 Comm: cmsg_sender Tainted: G B 6.9.0-rc2-virtme #1 [ 23.935095][ C0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 23.935396][ C0] RIP: 0010:sock_def_write_space_wfree+0x221/0x370 [ 23.935573][ C0] Code: 00 4c 8b b3 a0 01 00 00 be 08 00 00 00 4d 8d 7e 08 4c 89 ff e8 b0 0b 8b fe 4c 89 fa 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80> 3c 02 00 0f 85 1e 01 00 00 49 8b 46 08 a8 04 0f 84 5c fe ff ff [ 23.936056][ C0] RSP: 0018:ffffc90000007c30 EFLAGS: 00010202 [ 23.936228][ C0] RAX: dffffc0000000000 RBX: ffff888007dd8040 RCX: ffffffff8179564a [ 23.936431][ C0] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffffffff86cffa00 [ 23.936635][ C0] RBP: ffff888007dd80a0 R08: 0000000000000001 R09: fffffbfff0d9ff40 [ 23.936836][ C0] R10: ffffffff86cffa07 R11: 205d304320202020 R12: 0000000000000000 [ 23.937066][ C0] R13: ffff888007dd81c0 R14: 0000000000000000 R15: 0000000000000008 [ 23.937275][ C0] FS: 0000000000000000(0000) GS:ffff888036000000(0000) knlGS:0000000000000000 [ 23.937519][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 23.937697][ C0] CR2: 00007fb5a3363270 CR3: 00000000065ce001 CR4: 0000000000770ef0 [ 23.937908][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 23.938120][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 23.938335][ C0] PKRU: 55555554 [ 23.938518][ C0] Call Trace: [ 23.938622][ C0] <IRQ> [ 23.938692][ C0] ? die_addr+0x41/0xa0 [ 23.938798][ C0] ? exc_general_protection+0x149/0x220 [ 23.938938][ C0] ? asm_exc_general_protection+0x26/0x30 [ 23.939075][ C0] ? add_taint+0x2a/0x90 [ 23.939259][ C0] ? sock_def_write_space_wfree+0x221/0x370 [ 23.939429][ C0] sock_wfree+0x25f/0x3e0 [ 23.939534][ C0] skb_release_head_state+0x7a/0x1e0 [ 23.939669][ C0] consume_skb+0x76/0x110 [ 23.939849][ C0] dummy_xmit+0x106/0x170 [ 23.939953][ C0] ? trace_net_dev_start_xmit+0xff/0x170 [ 23.940090][ C0] dev_hard_start_xmit+0x10e/0x360 [ 23.940228][ C0] sch_direct_xmit+0x203/0x11c0 [ 23.940370][ C0] ? __pfx_sch_direct_xmit+0x10/0x10 [ 23.940587][ C0] __qdisc_run+0x1cd/0x3d0 [ 23.940725][ C0] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 23.940863][ C0] ? __pfx___qdisc_run+0x10/0x10 [ 23.941000][ C0] ? do_raw_spin_lock+0x131/0x270 [ 23.941213][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 23.941349][ C0] ? lock_acquire+0x32/0xc0 [ 23.941487][ C0] ? net_tx_action+0x3a5/0x680 [ 23.941626][ C0] net_tx_action+0x3f6/0x680 [ 23.941841][ C0] __do_softirq+0x1f8/0x5df [ 23.941980][ C0] irq_exit_rcu+0x97/0xc0 [ 23.942083][ C0] sysvec_apic_timer_interrupt+0x75/0x80 [ 23.942219][ C0] </IRQ> [ 23.942289][ C0] <TASK> [ 23.942357][ C0] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 23.942604][ C0] RIP: 0010:_raw_spin_unlock_irqrestore+0x43/0x70 [ 23.942781][ C0] Code: 10 e8 a1 f0 78 fd 48 89 ef e8 d9 60 79 fd 81 e3 00 02 00 00 75 1d 9c 58 f6 c4 02 75 29 48 85 db 74 01 fb 65 ff 0d 05 4c ed 7b <74> 0e 5b 5d c3 cc cc cc cc e8 ff c0 9c fd eb dc 0f 1f 44 00 00 5b [ 23.943345][ C0] RSP: 0018:ffffc900005bfbd0 EFLAGS: 00000282 [ 23.943517][ C0] RAX: 0000000000000006 RBX: 0000000000000200 RCX: 1ffffffff0bb23a1 [ 23.943719][ C0] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff84167dd1 [ 23.944001][ C0] RBP: ffff88800196e180 R08: 0000000000000001 R09: fffffbfff0bb2c22 [ 23.944206][ C0] R10: ffffffff85d96117 R11: 0000000000000040 R12: ffff88800196e180 [ 23.944486][ C0] R13: ffffea0000146e00 R14: ffff88800196b3c0 R15: ffff8880051bd7c0 [ 23.944690][ C0] ? _raw_spin_unlock_irqrestore+0x51/0x70 [ 23.944860][ C0] get_partial_node.part.0+0x1c5/0x3a0 [ 23.944999][ C0] ___slab_alloc+0xb70/0x10a0 [ 23.945215][ C0] ? kmem_cache_alloc+0x42/0x270 [ 23.945353][ C0] ? getname_flags+0x53/0x3d0 [ 23.945489][ C0] ? __pfx___lock_release+0x10/0x10 [ 23.945627][ C0] ? getname_flags+0x53/0x3d0 [ 23.945842][ C0] ? kmem_cache_alloc+0x243/0x270 [ 23.945977][ C0] kmem_cache_alloc+0x243/0x270 [ 23.946115][ C0] getname_flags+0x53/0x3d0 [ 23.946250][ C0] do_sys_openat2+0xdb/0x160 [ 23.946461][ C0] ? vfs_fstatat+0x9e/0xc0 [ 23.946596][ C0] ? __pfx_do_sys_openat2+0x10/0x10 [ 23.946734][ C0] ? __pfx___do_sys_newfstatat+0x10/0x10 [ 23.946870][ C0] __x64_sys_openat+0x123/0x1e0 [ 23.947013][ C0] ? __pfx___x64_sys_openat+0x10/0x10 [ 23.947328][ C0] ? __pfx_do_faccessat+0x10/0x10 [ 23.947468][ C0] do_syscall_64+0xc6/0x1e0 [ 23.947608][ C0] entry_SYSCALL_64_after_hwframe+0x72/0x7a [ 23.947780][ C0] RIP: 0033:0x7fb5a33970e8 [ 23.948007][ C0] Code: f9 41 89 f0 41 83 e2 40 75 30 89 f0 25 00 00 41 00 3d 00 00 41 00 74 22 44 89 c2 4c 89 ce bf 9c ff ff ff b8 01 01 00 00 0f 05 <48> 3d 00 f0 ff ff 77 30 c3 0f 1f 80 00 00 00 00 48 8d 44 24 08 c7 [ 23.948500][ C0] RSP: 002b:00007ffe6ca08358 EFLAGS: 00000287 ORIG_RAX: 0000000000000101 [ 23.948704][ C0] RAX: ffffffffffffffda RBX: 00007ffe6ca085df RCX: 00007fb5a33970e8 [ 23.948905][ C0] RDX: 0000000000080000 RSI: 00007ffe6ca083d0 RDI: 00000000ffffff9c [ 23.949190][ C0] RBP: 00007ffe6ca083c0 R08: 0000000000080000 R09: 00007ffe6ca083d0 [ 23.949391][ C0] R10: 0000000000000000 R11: 0000000000000287 R12: 00007ffe6ca083d7 [ 23.949591][ C0] R13: 00007ffe6ca085f0 R14: 00007ffe6ca083d0 R15: 00007fb5a3368000 [ 23.949871][ C0] </TASK> [ 23.949972][ C0] Modules linked in: sch_fq [ 23.950121][ C0] ---[ end trace 0000000000000000 ]--- [ 23.950260][ C0] RIP: 0010:sock_def_write_space_wfree+0x221/0x370 [ 23.950516][ C0] Code: 00 4c 8b b3 a0 01 00 00 be 08 00 00 00 4d 8d 7e 08 4c 89 ff e8 b0 0b 8b fe 4c 89 fa 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80> 3c 02 00 0f 85 1e 01 00 00 49 8b 46 08 a8 04 0f 84 5c fe ff ff [ 23.951029][ C0] RSP: 0018:ffffc90000007c30 EFLAGS: 00010202 [ 23.951285][ C0] RAX: dffffc0000000000 RBX: ffff888007dd8040 RCX: ffffffff8179564a [ 23.951495][ C0] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffffffff86cffa00 [ 23.951703][ C0] RBP: ffff888007dd80a0 R08: 0000000000000001 R09: fffffbfff0d9ff40 [ 23.952006][ C0] R10: ffffffff86cffa07 R11: 205d304320202020 R12: 0000000000000000 [ 23.952207][ C0] R13: ffff888007dd81c0 R14: 0000000000000000 R15: 0000000000000008 [ 23.952409][ C0] FS: 0000000000000000(0000) GS:ffff888036000000(0000) knlGS:0000000000000000 [ 23.952723][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 23.952903][ C0] CR2: 00007fb5a3363270 CR3: 00000000065ce001 CR4: 0000000000770ef0 [ 23.953183][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 23.953385][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 23.953586][ C0] PKRU: 55555554 [ 23.953689][ C0] Kernel panic - not syncing: Fatal exception in interrupt [ 23.954174][ C0] Kernel Offset: 0x400000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 23.954497][ C0] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr