====================================== | [ 13.199034][ T330] ================================================================== | [ 13.199318][ T330] BUG: KASAN: use-after-free in page_pool_item_uninit (net/core/page_pool.c:523) | [ 13.199580][ T330] Read of size 8 at addr ffff88800fd3c008 by task ethtool/330 | [ 13.199822][ T330] [ 13.200161][ T330] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 13.200370][ T330] Call Trace: [ 13.200495][ T330] [ 13.200579][ T330] dump_stack_lvl (lib/dump_stack.c:123) [ 13.200750][ T330] print_address_description.constprop.0 (mm/kasan/report.c:379) [ 13.200955][ T330] ? page_pool_item_uninit (net/core/page_pool.c:523) [ 13.201122][ T330] print_report (mm/kasan/report.c:490) [ 13.201284][ T330] ? kasan_addr_to_slab (./include/linux/mm.h:1295 mm/kasan/../slab.h:211 mm/kasan/common.c:38) [ 13.201446][ T330] kasan_report (mm/kasan/report.c:604) [ 13.201570][ T330] ? page_pool_item_uninit (net/core/page_pool.c:523) [ 13.201734][ T330] page_pool_item_uninit (net/core/page_pool.c:523) [ 13.201900][ T330] page_pool_release (net/core/page_pool.c:1431 net/core/page_pool.c:1484) [ 13.202065][ T330] ? __pfx_page_pool_release (net/core/page_pool.c:1478) [ 13.202229][ T330] page_pool_destroy (net/core/page_pool.c:1555) [ 13.202394][ T330] veth_napi_del_range (drivers/net/veth.c:1054 (discriminator 3)) [ 13.202559][ T330] ? __pfx_call_netdevice_notifiers (net/core/dev.c:2095) [ 13.202775][ T330] veth_set_features (drivers/net/veth.c:1060 drivers/net/veth.c:1494 drivers/net/veth.c:1472) [ 13.202933][ T330] ? netdev_upper_get_next_dev_rcu (net/core/dev.c:7309 (discriminator 1)) [ 13.203135][ T330] __netdev_update_features (net/core/dev.c:10251) [ 13.203300][ T330] ? __pfx___netdev_update_features (net/core/dev.c:10224) [ 13.203502][ T330] ? __pfx_ethnl_parse_header_dev_get.part.0 (net/ethtool/netlink.c:137) [ 13.203710][ T330] ethnl_set_features (net/ethtool/features.c:262) [ 13.203879][ T330] ? __pfx_ethnl_set_features (net/ethtool/features.c:211) [ 13.204044][ T330] ? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4347 kernel/locking/lockdep.c:4406) [ 13.204252][ T330] ? __nla_validate_parse (lib/nlattr.c:638) [ 13.204418][ T330] ? __nla_parse (lib/nlattr.c:732) [ 13.204583][ T330] ? genl_family_rcv_msg_attrs_parse.constprop.0 (net/netlink/genetlink.c:947) [ 13.204827][ T330] genl_family_rcv_msg_doit (net/netlink/genetlink.c:1115) [ 13.204993][ T330] ? __pfx_genl_family_rcv_msg_doit (net/netlink/genetlink.c:1088) [ 13.205201][ T330] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 13.205365][ T330] ? validate_chain (kernel/locking/lockdep.c:3797 kernel/locking/lockdep.c:3817 kernel/locking/lockdep.c:3872) [ 13.205527][ T330] genl_family_rcv_msg (net/netlink/genetlink.c:1195) [ 13.205688][ T330] ? __pfx_genl_family_rcv_msg (net/netlink/genetlink.c:1160) [ 13.205868][ T330] ? __pfx_ethnl_set_features (net/ethtool/features.c:211) [ 13.206032][ T330] genl_rcv_msg (net/netlink/genetlink.c:65 net/netlink/genetlink.c:1211) [ 13.206193][ T330] netlink_rcv_skb (net/netlink/af_netlink.c:2543) [ 13.206355][ T330] ? __pfx_genl_rcv_msg (net/netlink/genetlink.c:1201) [ 13.206518][ T330] ? __pfx_netlink_rcv_skb (net/netlink/af_netlink.c:2520) [ 13.206682][ T330] ? genl_rcv (net/netlink/genetlink.c:1219) [ 13.206805][ T330] ? __pfx_down_read (kernel/locking/rwsem.c:1522) [ 13.206968][ T330] ? netlink_deliver_tap (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 net/netlink/af_netlink.c:340) [ 13.207134][ T330] genl_rcv (net/netlink/genetlink.c:1220) [ 13.207255][ T330] netlink_unicast (net/netlink/af_netlink.c:1322 net/netlink/af_netlink.c:1348) [ 13.207418][ T330] ? __pfx_netlink_unicast (net/netlink/af_netlink.c:1333) [ 13.207581][ T330] ? find_held_lock (kernel/locking/lockdep.c:5339) [ 13.207745][ T330] netlink_sendmsg (net/netlink/af_netlink.c:1892) [ 13.207909][ T330] ? __pfx_netlink_sendmsg (net/netlink/af_netlink.c:1811) [ 13.208067][ T330] ? lock_acquire (kernel/locking/lockdep.c:5822) [ 13.208228][ T330] ? __might_fault (mm/memory.c:6751 mm/memory.c:6744) [ 13.208397][ T330] __sys_sendto (net/socket.c:711 net/socket.c:726 net/socket.c:2208) [ 13.208562][ T330] ? __pfx___sys_sendto (net/socket.c:2175) [ 13.208726][ T330] ? __lock_release (kernel/locking/lockdep.c:5525) [ 13.208897][ T330] ? __sys_recvmsg (net/socket.c:2889) [ 13.209063][ T330] ? __pfx___sys_recvmsg (net/socket.c:2874) [ 13.209225][ T330] ? do_user_addr_fault (./include/linux/rcupdate.h:882 ./include/linux/mm.h:742 arch/x86/mm/fault.c:1340) [ 13.209397][ T330] __x64_sys_sendto (net/socket.c:2211) [ 13.209562][ T330] ? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4347 kernel/locking/lockdep.c:4406) [ 13.209768][ T330] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 13.209935][ T330] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 13.210146][ T330] RIP: 0033:0x7fe646747a4a [ 13.210316][ T330] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 15 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 7e c3 0f 1f 44 00 00 41 54 48 83 ec 30 44 89 All code ======== 0: d8 64 89 02 fsubs 0x2(%rcx,%rcx,4) 4: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax b: eb b8 jmp 0xffffffffffffffc5 d: 0f 1f 00 nopl (%rax) 10: f3 0f 1e fa endbr64 14: 41 89 ca mov %ecx,%r10d 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 15 jne 0x38 23: b8 2c 00 00 00 mov $0x2c,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 7e ja 0xb0 32: c3 ret 33: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 38: 41 54 push %r12 3a: 48 83 ec 30 sub $0x30,%rsp 3e: 44 rex.R 3f: 89 .byte 0x89 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 7e ja 0x86 8: c3 ret 9: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) e: 41 54 push %r12 10: 48 83 ec 30 sub $0x30,%rsp 14: 44 rex.R 15: 89 .byte 0x89 [ 13.210888][ T330] RSP: 002b:00007ffe443cd948 EFLAGS: 00000246 ORIG_RAX: 000000000000002c [ 13.211142][ T330] RAX: ffffffffffffffda RBX: 000000000940b2a0 RCX: 00007fe646747a4a [ 13.211386][ T330] RDX: 0000000000000044 RSI: 000000000940b3b0 RDI: 0000000000000005 [ 13.211631][ T330] RBP: 0000000000486020 R08: 00007fe646804200 R09: 000000000000000c [ 13.211879][ T330] R10: 0000000000000000 R11: 0000000000000246 R12: 000000000940b340 Finger prints: print_report:kasan_report:page_pool_item_uninit:page_pool_release:page_pool_destroy