[ 2790.822237][ C2] ================================================================== [ 2790.822521][ C2] BUG: KASAN: slab-use-after-free in xfrm_lookup_with_ifid+0x9bf/0xa90 [ 2790.822780][ C2] Read of size 8 at addr ffff8880061acb50 by task socat/20472 [ 2790.823024][ C2] [ 2790.823120][ C2] CPU: 2 UID: 0 PID: 20472 Comm: socat Not tainted 6.12.0-rc1-virtme #1 [ 2790.823364][ C2] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 2790.823716][ C2] Call Trace: [ 2790.823841][ C2] [ 2790.823924][ C2] dump_stack_lvl+0x82/0xd0 [ 2790.824087][ C2] print_address_description.constprop.0+0x2c/0x3b0 [ 2790.824285][ C2] ? xfrm_lookup_with_ifid+0x9bf/0xa90 [ 2790.824454][ C2] print_report+0xb4/0x270 [ 2790.824613][ C2] ? kasan_addr_to_slab+0x25/0x80 [ 2790.824772][ C2] kasan_report+0xbd/0xf0 [ 2790.824894][ C2] ? xfrm_lookup_with_ifid+0x9bf/0xa90 [ 2790.825055][ C2] xfrm_lookup_with_ifid+0x9bf/0xa90 [ 2790.825217][ C2] ? __pfx_xfrm_lookup_with_ifid+0x10/0x10 [ 2790.825421][ C2] ? l4proto_manip_pkt+0x670/0x10f0 [nf_nat] [ 2790.825632][ C2] nf_xfrm_me_harder+0x1a8/0x5e0 [nf_nat] [ 2790.825799][ C2] ? __pfx_nf_xfrm_me_harder+0x10/0x10 [nf_nat] [ 2790.826005][ C2] ? nft_do_chain_ipv4+0x184/0x210 [nf_tables] [ 2790.826242][ C2] ? __pfx_nft_do_chain_ipv4+0x10/0x10 [nf_tables] [ 2790.826468][ C2] nf_nat_ipv4_out+0x3c7/0x470 [nf_nat] [ 2790.826635][ C2] ? __pfx_nf_nat_ipv4_out+0x10/0x10 [nf_nat] [ 2790.826838][ C2] nf_hook_slow+0xba/0x200 [ 2790.827002][ C2] nf_hook+0x374/0x4f0 [ 2790.827123][ C2] ? __pfx_ip_finish_output+0x10/0x10 [ 2790.827284][ C2] ? __pfx_nf_hook+0x10/0x10 [ 2790.827444][ C2] ? __ip_append_data+0x25e4/0x3900 [ 2790.827602][ C2] ? __pfx_ip_finish_output+0x10/0x10 [ 2790.827763][ C2] ip_output+0x172/0x240 [ 2790.827883][ C2] ? __pfx_ip_finish_output+0x10/0x10 [ 2790.828048][ C2] ip_push_pending_frames+0x24b/0x480 [ 2790.828212][ C2] ip_send_unicast_reply+0xac1/0x14b0 [ 2790.828371][ C2] ? hlock_class+0x4e/0x130 [ 2790.828532][ C2] ? mark_lock+0x38/0x3e0 [ 2790.828656][ C2] ? __pfx_ip_send_unicast_reply+0x10/0x10 [ 2790.828854][ C2] ? __lock_acquire+0xb3f/0x1580 [ 2790.829019][ C2] ? lock_acquire.part.0+0xeb/0x330 [ 2790.829179][ C2] ? tcp_v4_send_ack.constprop.0+0x4c4/0x1050 [ 2790.829378][ C2] ? mark_lock+0x38/0x3e0 [ 2790.829504][ C2] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 2790.829662][ C2] ? trace_lock_acquire+0x14d/0x1f0 [ 2790.829821][ C2] tcp_v4_send_ack.constprop.0+0x7c6/0x1050 [ 2790.830044][ C2] ? __pfx_tcp_v4_send_ack.constprop.0+0x10/0x10 [ 2790.830250][ C2] ? __pfx___lock_release+0x10/0x10 [ 2790.830408][ C2] ? mark_held_locks+0x9e/0xe0 [ 2790.830567][ C2] ? tcp_v4_rcv+0x2251/0x3460 [ 2790.830727][ C2] tcp_v4_rcv+0x2251/0x3460 [ 2790.830893][ C2] ? __pfx_tcp_v4_rcv+0x10/0x10 [ 2790.831051][ C2] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 2790.831213][ C2] ip_protocol_deliver_rcu+0x93/0x360 [ 2790.831375][ C2] ? process_backlog+0x332/0x1180 [ 2790.831533][ C2] ip_local_deliver_finish+0x2af/0x490 [ 2790.831694][ C2] ? process_backlog+0x332/0x1180 [ 2790.831854][ C2] ? __pfx_ip_rcv+0x10/0x10 [ 2790.832015][ C2] __netif_receive_skb_one_core+0x166/0x1b0 [ 2790.832220][ C2] ? __pfx___netif_receive_skb_one_core+0x10/0x10 [ 2790.832417][ C2] ? process_backlog+0x332/0x1180 [ 2790.832576][ C2] ? lock_acquire+0x32/0xc0 [ 2790.832735][ C2] ? process_backlog+0x332/0x1180 [ 2790.832894][ C2] process_backlog+0x372/0x1180 [ 2790.833055][ C2] __napi_poll.constprop.0+0xa2/0x460 [ 2790.833214][ C2] net_rx_action+0x50e/0xce0 [ 2790.833377][ C2] ? __pfx_net_rx_action+0x10/0x10 [ 2790.833543][ C2] ? __pfx_rcu_do_batch+0x10/0x10 [ 2790.833702][ C2] ? hlock_class+0x4e/0x130 [ 2790.833863][ C2] ? mark_lock+0x38/0x3e0 [ 2790.833982][ C2] ? lockdep_hardirqs_on_prepare+0x12b/0x410 [ 2790.834185][ C2] ? mark_held_locks+0x9e/0xe0 [ 2790.834347][ C2] handle_softirqs+0x1f6/0x5c0 [ 2790.834508][ C2] ? __dev_queue_xmit+0x78e/0x18b0 [ 2790.834666][ C2] do_softirq+0x4d/0xa0 [ 2790.834787][ C2] [ 2790.834874][ C2] [ 2790.834954][ C2] __local_bh_enable_ip+0xf6/0x120 [ 2790.835113][ C2] ? __dev_queue_xmit+0x78e/0x18b0 [ 2790.835270][ C2] __dev_queue_xmit+0x7a3/0x18b0 [ 2790.835433][ C2] ? __lock_release+0x103/0x460 [ 2790.835592][ C2] ? ip_finish_output2+0xac2/0x18f0 [ 2790.835750][ C2] ? __pfx___lock_release+0x10/0x10 [ 2790.835908][ C2] ? hlock_class+0x4e/0x130 [ 2790.836070][ C2] ? __pfx___dev_queue_xmit+0x10/0x10 [ 2790.836230][ C2] ? mark_held_locks+0x9e/0xe0 [ 2790.836391][ C2] ? lockdep_hardirqs_on_prepare+0x275/0x410 [ 2790.836586][ C2] ? neigh_hh_output+0x36f/0x560 [ 2790.836746][ C2] ip_finish_output2+0xac2/0x18f0 [ 2790.836912][ C2] ? __pfx_ip_finish_output2+0x10/0x10 [ 2790.837070][ C2] ? __ip_finish_output+0x10f/0x760 [ 2790.837227][ C2] __ip_queue_xmit+0x64f/0x1790 [ 2790.837389][ C2] ? __skb_clone+0x571/0x750 [ 2790.837557][ C2] __tcp_transmit_skb+0x2291/0x2d10 [ 2790.837717][ C2] ? __pfx___tcp_transmit_skb+0x10/0x10 [ 2790.837873][ C2] ? mark_held_locks+0x9e/0xe0 [ 2790.838032][ C2] ? lockdep_hardirqs_on_prepare+0x275/0x410 [ 2790.838230][ C2] ? tcp_small_queue_check.isra.0+0xe9/0x380 [ 2790.838428][ C2] tcp_write_xmit+0x8a3/0x2cf0 [ 2790.838593][ C2] ? tcp_current_mss+0x40a/0x510 [ 2790.838757][ C2] ? __pfx_tcp_current_mss+0x10/0x10 [ 2790.838915][ C2] ? __alloc_skb+0x23d/0x2e0 [ 2790.839076][ C2] ? __pfx_tcp_write_xmit+0x10/0x10 [ 2790.839232][ C2] ? tcp_set_state+0x10b/0x510 [ 2790.839389][ C2] ? __pfx_tcp_set_state+0x10/0x10 [ 2790.839554][ C2] __tcp_push_pending_frames+0x96/0x320 [ 2790.839711][ C2] inet_shutdown+0x164/0x390 [ 2790.839868][ C2] ? sockfd_lookup_light+0x1a/0x140 [ 2790.840040][ C2] __sys_shutdown+0xcb/0x160 [ 2790.840198][ C2] ? __pfx___sys_shutdown+0x10/0x10 [ 2790.840357][ C2] ? audit_reset_context.part.0.constprop.0+0x987/0xe50 [ 2790.840559][ C2] __x64_sys_shutdown+0x53/0x80 [ 2790.840716][ C2] do_syscall_64+0xc1/0x1d0 [ 2790.840874][ C2] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 2790.841073][ C2] RIP: 0033:0x7fbecd837beb [ 2790.841235][ C2] Code: 73 01 c3 48 8b 0d 15 92 1b 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa b8 30 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e5 91 1b 00 f7 d8 64 89 01 48 [ 2790.841800][ C2] RSP: 002b:00007ffc5d1681a8 EFLAGS: 00000202 ORIG_RAX: 0000000000000030 [ 2790.842038][ C2] RAX: ffffffffffffffda RBX: 0000560df33ff610 RCX: 00007fbecd837beb [ 2790.842276][ C2] RDX: 0000000000000008 RSI: 0000000000000002 RDI: 0000000000000008 [ 2790.842514][ C2] RBP: 0000000000000008 R08: 0000000000000001 R09: 0000000000000000 [ 2790.842752][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: ffffffffffffffff [ 2790.843096][ C2] R13: 0000000000000000 R14: 0000560ddd41a10e R15: 0000000000000001 [ 2790.843337][ C2] [ 2790.843454][ C2] [ 2790.843536][ C2] Allocated by task 18772: [ 2790.843694][ C2] kasan_save_stack+0x24/0x50 [ 2790.843965][ C2] kasan_save_track+0x14/0x30 [ 2790.844122][ C2] __kasan_slab_alloc+0x59/0x70 [ 2790.844279][ C2] kmem_cache_alloc_noprof+0xdb/0x250 [ 2790.844437][ C2] inet_twsk_alloc+0x115/0x970 [ 2790.844795][ C2] tcp_time_wait+0x60/0xe70 [ 2790.844951][ C2] tcp_fin+0x2fb/0x470 [ 2790.845075][ C2] tcp_data_queue+0xe66/0x22b0 [ 2790.845235][ C2] tcp_rcv_state_process+0x6cb/0x2030 [ 2790.845396][ C2] tcp_v4_do_rcv+0x14d/0x8c0 [ 2790.845669][ C2] tcp_v4_rcv+0x25e8/0x3460 [ 2790.845825][ C2] ip_protocol_deliver_rcu+0x93/0x360 [ 2790.845983][ C2] ip_local_deliver_finish+0x2af/0x490 [ 2790.846146][ C2] __netif_receive_skb_one_core+0x166/0x1b0 [ 2790.846345][ C2] process_backlog+0x372/0x1180 [ 2790.846502][ C2] __napi_poll.constprop.0+0xa2/0x460 [ 2790.846659][ C2] net_rx_action+0x50e/0xce0 [ 2790.846820][ C2] handle_softirqs+0x1f6/0x5c0 [ 2790.846977][ C2] do_softirq+0x4d/0xa0 [ 2790.847095][ C2] __local_bh_enable_ip+0xf6/0x120 [ 2790.847251][ C2] __dev_queue_xmit+0x7a3/0x18b0 [ 2790.847411][ C2] ip_finish_output2+0x9ca/0x18f0 [ 2790.847568][ C2] __ip_queue_xmit+0x64f/0x1790 [ 2790.847724][ C2] __tcp_transmit_skb+0x2291/0x2d10 [ 2790.847880][ C2] tcp_write_xmit+0x8a3/0x2cf0 [ 2790.848035][ C2] __tcp_push_pending_frames+0x96/0x320 [ 2790.848196][ C2] inet_shutdown+0x164/0x390 [ 2790.848459][ C2] __sys_shutdown+0xcb/0x160 [ 2790.848615][ C2] __x64_sys_shutdown+0x53/0x80 [ 2790.848781][ C2] do_syscall_64+0xc1/0x1d0 [ 2790.848937][ C2] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 2790.849234][ C2] [ 2790.849314][ C2] Freed by task 0: [ 2790.849432][ C2] kasan_save_stack+0x24/0x50 [ 2790.849593][ C2] kasan_save_track+0x14/0x30 [ 2790.849753][ C2] kasan_save_free_info+0x3b/0x60 [ 2790.850027][ C2] __kasan_slab_free+0x38/0x50 [ 2790.850184][ C2] slab_free_after_rcu_debug+0xd7/0x2b0 [ 2790.850341][ C2] rcu_do_batch+0x34f/0xf20 [ 2790.850498][ C2] rcu_core+0x2bd/0x4f0 [ 2790.850718][ C2] handle_softirqs+0x1f6/0x5c0 [ 2790.850878][ C2] irq_exit_rcu+0x99/0xc0 [ 2790.850996][ C2] sysvec_apic_timer_interrupt+0x78/0x90 [ 2790.851154][ C2] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 2790.851456][ C2] [ 2790.851537][ C2] Last potentially related work creation: [ 2790.851695][ C2] kasan_save_stack+0x24/0x50 [ 2790.851864][ C2] __kasan_record_aux_stack+0x8e/0xa0 [ 2790.852024][ C2] kmem_cache_free+0x207/0x340 [ 2790.852286][ C2] inet_twsk_free+0x11d/0x180 [ 2790.852444][ C2] inet_twsk_purge+0x4c8/0x660 [ 2790.852602][ C2] tcp_twsk_purge+0x112/0x160 [ 2790.852765][ C2] tcp_sk_exit_batch+0x28/0x140 [ 2790.853028][ C2] cleanup_net+0x4ef/0x9d0 [ 2790.853189][ C2] process_one_work+0xe55/0x16d0 [ 2790.853348][ C2] worker_thread+0x58c/0xce0 [ 2790.853505][ C2] kthread+0x28a/0x350 [ 2790.853625][ C2] ret_from_fork+0x31/0x70 [ 2790.853888][ C2] ret_from_fork_asm+0x1a/0x30 [ 2790.854047][ C2] [ 2790.854131][ C2] The buggy address belongs to the object at ffff8880061acb30 [ 2790.854131][ C2] which belongs to the cache tw_sock_TCP of size 280 [ 2790.854630][ C2] The buggy address is located 32 bytes inside of [ 2790.854630][ C2] freed 280-byte region [ffff8880061acb30, ffff8880061acc48) [ 2790.855012][ C2] [ 2790.855093][ C2] The buggy address belongs to the physical page: [ 2790.855292][ C2] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff8880061ade50 pfn:0x61ac [ 2790.855617][ C2] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 2790.855853][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 2790.856056][ C2] page_type: f5(slab) [ 2790.856181][ C2] raw: 0080000000000240 ffff888003718c40 ffffea00002a6110 ffff888003712bc8 [ 2790.856459][ C2] raw: ffff8880061ade50 0000000000140001 00000001f5000000 0000000000000000 [ 2790.856844][ C2] head: 0080000000000240 ffff888003718c40 ffffea00002a6110 ffff888003712bc8 [ 2790.857124][ C2] head: ffff8880061ade50 0000000000140001 00000001f5000000 0000000000000000 [ 2790.857508][ C2] head: 0080000000000001 ffffea0000186b01 ffffffffffffffff 0000000000000000 [ 2790.857787][ C2] head: 0000000000000002 0000000000000000 00000000ffffffff 0000000000000000 [ 2790.858063][ C2] page dumped because: kasan: bad access detected [ 2790.858258][ C2] [ 2790.858342][ C2] Memory state around the buggy address: [ 2790.858496][ C2] ffff8880061aca00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 2790.858726][ C2] ffff8880061aca80: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc [ 2790.858959][ C2] >ffff8880061acb00: fc fc fc fc fc fc fa fb fb fb fb fb fb fb fb fb [ 2790.859190][ C2] ^ [ 2790.859384][ C2] ffff8880061acb80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 2790.859617][ C2] ffff8880061acc00: fb fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc [ 2790.859848][ C2] ================================================================== [ 2790.860130][ C2] Disabling lock debugging due to kernel taint [ 2792.783750][ C0] Oops: general protection fault, probably for non-canonical address 0xfbd5a5d5a0000047: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 2792.784220][ C0] KASAN: maybe wild-memory-access in range [0xdead4ead00000238-0xdead4ead0000023f] [ 2792.784523][ C0] CPU: 0 UID: 0 PID: 20482 Comm: socat Tainted: G B 6.12.0-rc1-virtme #1 [ 2792.784840][ C0] Tainted: [B]=BAD_PAGE [ 2792.784974][ C0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 2792.785365][ C0] RIP: 0010:xfrm_sk_policy_lookup+0x10f/0x4e0 [ 2792.785594][ C0] Code: 48 89 44 24 18 0f b7 44 24 06 89 44 24 28 e9 a9 01 00 00 4d 85 ed 0f 84 2f 02 00 00 49 8d bd 3e 02 00 00 48 89 f8 48 c1 e8 03 <0f> b6 14 18 48 89 f8 83 e0 07 83 c0 01 38 d0 7c 08 84 d2 0f 85 8c [ 2792.786196][ C0] RSP: 0018:ffffc90000006a80 EFLAGS: 00010a07 [ 2792.786420][ C0] RAX: 1bd5a9d5a0000047 RBX: dffffc0000000000 RCX: ffffffffb7b17087 [ 2792.786686][ C0] RDX: ffffffffb7b17087 RSI: 0000000000000008 RDI: dead4ead0000023e [ 2792.786944][ C0] RBP: ffff8880061ade50 R08: 0000000000000000 R09: 0000000000000000 [ 2792.787197][ C0] R10: ffffffffb9b7388f R11: dffffc0000000000 R12: 0000000000000000 [ 2792.787450][ C0] R13: dead4ead00000000 R14: ffff8880061ade50 R15: ffffc90000006c70 [ 2792.787717][ C0] FS: 00007fbecd7a9740(0000) GS:ffff888036000000(0000) knlGS:0000000000000000 [ 2792.788013][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 2792.788230][ C0] CR2: 0000560df3405b88 CR3: 0000000009482001 CR4: 0000000000772ef0 [ 2792.788485][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 2792.788748][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 2792.789011][ C0] PKRU: 55555554 [ 2792.789139][ C0] Call Trace: [ 2792.789269][ C0] [ 2792.789364][ C0] ? die_addr+0x41/0xa0 [ 2792.789499][ C0] ? exc_general_protection+0x14d/0x230 [ 2792.789677][ C0] ? asm_exc_general_protection+0x26/0x30 [ 2792.789996][ C0] ? xfrm_sk_policy_lookup+0x97/0x4e0 [ 2792.790169][ C0] ? xfrm_sk_policy_lookup+0x97/0x4e0 [ 2792.790336][ C0] ? xfrm_sk_policy_lookup+0x10f/0x4e0 [ 2792.790618][ C0] ? __pfx_xfrm_sk_policy_lookup+0x10/0x10 [ 2792.790838][ C0] xfrm_lookup_with_ifid+0x154/0xa90 [ 2792.791006][ C0] ? __pfx_xfrm_lookup_with_ifid+0x10/0x10 [ 2792.791220][ C0] ? l4proto_manip_pkt+0x670/0x10f0 [nf_nat] [ 2792.791559][ C0] nf_xfrm_me_harder+0x1a8/0x5e0 [nf_nat] [ 2792.791740][ C0] ? __pfx_nf_xfrm_me_harder+0x10/0x10 [nf_nat] [ 2792.792076][ C0] ? nft_do_chain_ipv4+0x184/0x210 [nf_tables] [ 2792.792326][ C0] ? __pfx_nft_do_chain_ipv4+0x10/0x10 [nf_tables] [ 2792.792560][ C0] nf_nat_ipv4_out+0x3c7/0x470 [nf_nat] [ 2792.792737][ C0] ? __pfx_nf_nat_ipv4_out+0x10/0x10 [nf_nat] [ 2792.793068][ C0] nf_hook_slow+0xba/0x200 [ 2792.793242][ C0] nf_hook+0x374/0x4f0 [ 2792.793367][ C0] ? __pfx_ip_finish_output+0x10/0x10 [ 2792.793536][ C0] ? __pfx_nf_hook+0x10/0x10 [ 2792.793710][ C0] ? __pfx_ip_finish_output+0x10/0x10 [ 2792.793892][ C0] ? nf_nat_ipv4_local_fn+0x103/0x4d0 [nf_nat] [ 2792.794225][ C0] ip_output+0x172/0x240 [ 2792.794347][ C0] ? __pfx_ip_finish_output+0x10/0x10 [ 2792.794514][ C0] vrf_ip_local_out+0x692/0x860 [ 2792.794700][ C0] ? __pfx_vrf_ip_local_out+0x10/0x10 [ 2792.794875][ C0] ? hpet_cpuhp_online+0x1a3/0x6d0 [ 2792.795161][ C0] ? __pfx_dst_output+0x10/0x10 [ 2792.795324][ C0] vrf_process_v4_outbound+0x5d3/0xca0 [ 2792.795495][ C0] ? __pfx_vrf_process_v4_outbound+0x10/0x10 [ 2792.795823][ C0] ? arch_stack_walk+0x79/0xf0 [ 2792.796111][ C0] vrf_xmit+0x129/0x180 [ 2792.796242][ C0] dev_hard_start_xmit+0x10e/0x360 [ 2792.796411][ C0] sch_direct_xmit+0x1e0/0xa60 [ 2792.796582][ C0] ? __pfx_sch_direct_xmit+0x10/0x10 [ 2792.796756][ C0] ? do_raw_spin_lock+0x131/0x270 [ 2792.797038][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 2792.797209][ C0] ? lock_acquire+0x32/0xc0 [ 2792.797506][ C0] ? __dev_xmit_skb+0x301/0x10a0 [ 2792.797685][ C0] __dev_xmit_skb+0x7b2/0x10a0 [ 2792.797975][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 2792.798150][ C0] ? __pfx___dev_xmit_skb+0x10/0x10 [ 2792.798320][ C0] ? __dev_queue_xmit+0x1e1/0x18b0 [ 2792.798489][ C0] ? lock_acquire+0x32/0xc0 [ 2792.798770][ C0] ? __dev_queue_xmit+0x1e1/0x18b0 [ 2792.799070][ C0] __dev_queue_xmit+0x76c/0x18b0 [ 2792.799238][ C0] ? __pfx___alloc_skb+0x10/0x10 [ 2792.799423][ C0] ? __pfx_nft_do_chain_ipv4+0x10/0x10 [nf_tables] [ 2792.799781][ C0] ? __pfx_nf_confirm+0x10/0x10 [nf_conntrack] [ 2792.800028][ C0] ? __pfx___dev_queue_xmit+0x10/0x10 [ 2792.800199][ C0] ? trace_lock_release+0x10e/0x180 [ 2792.800488][ C0] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 2792.800819][ C0] ? neigh_hh_output+0x36f/0x560 [ 2792.800989][ C0] ? vrf_finish_output+0x1c9/0x17d0 [ 2792.801159][ C0] vrf_finish_output+0xa26/0x17d0 [ 2792.801329][ C0] ? __pfx_vrf_finish_output+0x10/0x10 [ 2792.801626][ C0] ? __pfx_vrf_finish_output+0x10/0x10 [ 2792.801800][ C0] ? vrf_output+0x1cb/0x290 [ 2792.801966][ C0] ip_push_pending_frames+0x2c0/0x480 [ 2792.802140][ C0] ip_send_unicast_reply+0xac1/0x14b0 [ 2792.802309][ C0] ? do_raw_spin_lock+0x131/0x270 [ 2792.802476][ C0] ? __pfx_ip_send_unicast_reply+0x10/0x10 [ 2792.802686][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 2792.802855][ C0] ? trace_lock_release+0x10e/0x180 [ 2792.803025][ C0] ? lock_timer_base+0x4e/0x1d0 [ 2792.803194][ C0] ? lock_acquire+0x32/0xc0 [ 2792.803472][ C0] ? lock_timer_base+0x4e/0x1d0 [ 2792.803643][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 2792.803821][ C0] ? trace_lock_release+0x10e/0x180 [ 2792.804103][ C0] tcp_v4_send_ack.constprop.0+0x7c6/0x1050 [ 2792.804315][ C0] ? __pfx_tcp_v4_send_ack.constprop.0+0x10/0x10 [ 2792.804532][ C0] ? trace_lock_release+0x10e/0x180 [ 2792.804830][ C0] ? tcp_v4_rcv+0x2251/0x3460 [ 2792.804999][ C0] tcp_v4_rcv+0x2251/0x3460 [ 2792.805182][ C0] ? __pfx_tcp_v4_rcv+0x10/0x10 [ 2792.805471][ C0] ? nf_hook.constprop.0+0x102/0x4d0 [ 2792.805870][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 2792.806181][ C0] ip_protocol_deliver_rcu+0x93/0x360 [ 2792.806491][ C0] ? process_backlog+0x332/0x1180 [ 2792.806676][ C0] ip_local_deliver_finish+0x2af/0x490 [ 2792.806864][ C0] ? process_backlog+0x332/0x1180 [ 2792.807164][ C0] ? __pfx_ip_rcv+0x10/0x10 [ 2792.807357][ C0] __netif_receive_skb_one_core+0x166/0x1b0 [ 2792.807584][ C0] ? __pfx___netif_receive_skb_one_core+0x10/0x10 [ 2792.807818][ C0] ? process_backlog+0x332/0x1180 [ 2792.808118][ C0] ? lock_acquire+0x32/0xc0 [ 2792.808298][ C0] ? process_backlog+0x332/0x1180 [ 2792.808482][ C0] process_backlog+0x372/0x1180 [ 2792.808662][ C0] __napi_poll.constprop.0+0xa2/0x460 [ 2792.809084][ C0] net_rx_action+0x50e/0xce0 [ 2792.809270][ C0] ? __pfx_net_rx_action+0x10/0x10 [ 2792.809454][ C0] ? try_to_wake_up+0x122/0xc80 [ 2792.809636][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 2792.809943][ C0] ? __pfx_try_to_wake_up+0x10/0x10 [ 2792.810127][ C0] ? swake_up_one+0x1f/0x1f0 [ 2792.810420][ C0] ? lock_acquire+0x32/0xc0 [ 2792.810602][ C0] ? swake_up_one+0x1f/0x1f0 [ 2792.810893][ C0] ? trace_lock_release+0x10e/0x180 [ 2792.811080][ C0] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 2792.811312][ C0] handle_softirqs+0x1f6/0x5c0 [ 2792.811622][ C0] ? __dev_queue_xmit+0x78e/0x18b0 [ 2792.811808][ C0] do_softirq+0x4d/0xa0 [ 2792.811946][ C0] [ 2792.812038][ C0] [ 2792.812134][ C0] __local_bh_enable_ip+0xf6/0x120 [ 2792.812433][ C0] ? __dev_queue_xmit+0x78e/0x18b0 [ 2792.812620][ C0] __dev_queue_xmit+0x7a3/0x18b0 [ 2792.812918][ C0] ? __kernel_text_address+0x12/0x40 [ 2792.813105][ C0] ? unwind_get_return_address+0x5e/0xa0 [ 2792.813293][ C0] ? __pfx_stack_trace_consume_entry+0x10/0x10 [ 2792.813520][ C0] ? arch_stack_walk+0xa2/0xf0 [ 2792.813824][ C0] ? __pfx___dev_queue_xmit+0x10/0x10 [ 2792.814015][ C0] ? trace_lock_release+0x10e/0x180 [ 2792.814197][ C0] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 2792.814426][ C0] ? neigh_hh_output+0x36f/0x560 [ 2792.814723][ C0] ? ip_finish_output2+0x265/0x18f0 [ 2792.814908][ C0] ip_finish_output2+0xac2/0x18f0 [ 2792.815092][ C0] ? lock_release+0x13/0x140 [ 2792.815278][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 2792.815596][ C0] ? __pfx_ip_finish_output2+0x10/0x10 [ 2792.815785][ C0] ? rcu_read_lock_held+0xe/0x50 [ 2792.815967][ C0] ? __ip_finish_output+0x10f/0x760 [ 2792.816153][ C0] __ip_queue_xmit+0x64f/0x1790 [ 2792.816331][ C0] ? __skb_clone+0x571/0x750 [ 2792.816513][ C0] __tcp_transmit_skb+0x2291/0x2d10 [ 2792.816701][ C0] ? __pfx___tcp_transmit_skb+0x10/0x10 [ 2792.817002][ C0] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 2792.817344][ C0] ? tcp_small_queue_check.isra.0+0xe9/0x380 [ 2792.817575][ C0] tcp_write_xmit+0x8a3/0x2cf0 [ 2792.817756][ C0] ? tcp_current_mss+0x40a/0x510 [ 2792.817930][ C0] ? __pfx_tcp_current_mss+0x10/0x10 [ 2792.818338][ C0] ? __alloc_skb+0x23d/0x2e0 [ 2792.818529][ C0] ? __pfx_tcp_write_xmit+0x10/0x10 [ 2792.818709][ C0] ? tcp_set_state+0x10b/0x510 [ 2792.819022][ C0] ? __pfx_tcp_set_state+0x10/0x10 [ 2792.819210][ C0] ? lock_acquire+0x32/0xc0 [ 2792.819392][ C0] ? lock_sock_nested+0x59/0xe0 [ 2792.819712][ C0] __tcp_push_pending_frames+0x96/0x320 [ 2792.819902][ C0] inet_shutdown+0x164/0x390 [ 2792.820092][ C0] ? sockfd_lookup_light+0x1a/0x140 [ 2792.820390][ C0] __sys_shutdown+0xcb/0x160 [ 2792.820575][ C0] ? __pfx___sys_shutdown+0x10/0x10 [ 2792.820878][ C0] ? audit_reset_context.part.0.constprop.0+0x987/0xe50 [ 2792.821106][ C0] __x64_sys_shutdown+0x53/0x80 [ 2792.821290][ C0] do_syscall_64+0xc1/0x1d0 [ 2792.821466][ C0] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 2792.821689][ C0] RIP: 0033:0x7fbecd837beb [ 2792.821870][ C0] Code: 73 01 c3 48 8b 0d 15 92 1b 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa b8 30 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e5 91 1b 00 f7 d8 64 89 01 48 [ 2792.822779][ C0] RSP: 002b:00007ffc5d1681a8 EFLAGS: 00000202 ORIG_RAX: 0000000000000030 [ 2792.823173][ C0] RAX: ffffffffffffffda RBX: 0000560df33ff610 RCX: 00007fbecd837beb [ 2792.823449][ C0] RDX: 0000000000000008 RSI: 0000000000000002 RDI: 0000000000000008 [ 2792.823847][ C0] RBP: 0000000000000008 R08: 0000000000000001 R09: 0000000000000000 [ 2792.824122][ C0] R10: 0000000000000000 R11: 0000000000000202 R12: ffffffffffffffff [ 2792.824398][ C0] R13: 0000000000000000 R14: 0000560ddd41a10e R15: 0000000000000001 [ 2792.824669][ C0] [ 2792.824805][ C0] Modules linked in: ts_kmp ts_bm xt_string nf_log_syslog nft_log nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib ip6t_rpfilter ipt_rpfilter dummy nft_tproxy nf_tproxy_ipv6 nf_tproxy_ipv4 nft_quota ipip ip_vs_rr ip_vs xt_tcpudp xt_conntrack nft_compat x_tables tun sctp_diag nft_limit nfnetlink_queue nft_queue sctp ip6_udp_tunnel udp_tunnel nft_meta_bridge br_netfilter macvlan nft_numgen nf_conntrack_netlink nft_redir esp4 sha1_generic xfrm_user 8021q bridge stp llc nft_masq nft_nat nft_chain_nat nf_nat nft_flow_offload nft_ct nf_flow_table_inet nf_flow_table nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 tcp_diag inet_diag veth nf_tables libcrc32c [ 2792.827177][ C0] ---[ end trace 0000000000000000 ]--- [ 2792.827479][ C0] RIP: 0010:xfrm_sk_policy_lookup+0x10f/0x4e0 [ 2792.827828][ C0] Code: 48 89 44 24 18 0f b7 44 24 06 89 44 24 28 e9 a9 01 00 00 4d 85 ed 0f 84 2f 02 00 00 49 8d bd 3e 02 00 00 48 89 f8 48 c1 e8 03 <0f> b6 14 18 48 89 f8 83 e0 07 83 c0 01 38 d0 7c 08 84 d2 0f 85 8c [ 2792.828469][ C0] RSP: 0018:ffffc90000006a80 EFLAGS: 00010a07 [ 2792.828813][ C0] RAX: 1bd5a9d5a0000047 RBX: dffffc0000000000 RCX: ffffffffb7b17087 [ 2792.829085][ C0] RDX: ffffffffb7b17087 RSI: 0000000000000008 RDI: dead4ead0000023e [ 2792.829355][ C0] RBP: ffff8880061ade50 R08: 0000000000000000 R09: 0000000000000000 [ 2792.829751][ C0] R10: ffffffffb9b7388f R11: dffffc0000000000 R12: 0000000000000000 [ 2792.830031][ C0] R13: dead4ead00000000 R14: ffff8880061ade50 R15: ffffc90000006c70 [ 2792.830300][ C0] FS: 00007fbecd7a9740(0000) GS:ffff888036000000(0000) knlGS:0000000000000000 [ 2792.830617][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 2792.830848][ C0] CR2: 0000560df3405b88 CR3: 0000000009482001 CR4: 0000000000772ef0 [ 2792.831244][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 2792.831516][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 2792.831785][ C0] PKRU: 55555554 [ 2792.832033][ C0] Kernel panic - not syncing: Fatal exception in interrupt [ 2792.832507][ C0] Kernel Offset: 0x34200000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 2792.832915][ C0] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr