[ 1829.896275][ C3] ================================================================== [ 1829.896575][ C3] BUG: KASAN: slab-use-after-free in xfrm_lookup_with_ifid+0x9bf/0xa90 [ 1829.896853][ C3] Read of size 8 at addr ffff8880146f1b40 by task socat/9405 [ 1829.897113][ C3] [ 1829.897208][ C3] CPU: 3 UID: 0 PID: 9405 Comm: socat Not tainted 6.12.0-rc1-virtme #1 [ 1829.897485][ C3] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 1829.897872][ C3] Call Trace: [ 1829.898014][ C3] [ 1829.898103][ C3] dump_stack_lvl+0x82/0xd0 [ 1829.898284][ C3] print_address_description.constprop.0+0x2c/0x3b0 [ 1829.898505][ C3] ? xfrm_lookup_with_ifid+0x9bf/0xa90 [ 1829.898685][ C3] print_report+0xb4/0x270 [ 1829.898873][ C3] ? kasan_addr_to_slab+0x25/0x80 [ 1829.899051][ C3] kasan_report+0xbd/0xf0 [ 1829.899181][ C3] ? xfrm_lookup_with_ifid+0x9bf/0xa90 [ 1829.899359][ C3] xfrm_lookup_with_ifid+0x9bf/0xa90 [ 1829.899536][ C3] ? __pfx_xfrm_lookup_with_ifid+0x10/0x10 [ 1829.899761][ C3] ? l4proto_manip_pkt+0x670/0x10f0 [nf_nat] [ 1829.899990][ C3] nf_xfrm_me_harder+0x1a8/0x5e0 [nf_nat] [ 1829.900172][ C3] ? __pfx_nf_xfrm_me_harder+0x10/0x10 [nf_nat] [ 1829.900396][ C3] ? nft_do_chain_ipv4+0x184/0x210 [nf_tables] [ 1829.900657][ C3] ? __pfx_nft_do_chain_ipv4+0x10/0x10 [nf_tables] [ 1829.900906][ C3] nf_nat_ipv4_out+0x3c7/0x470 [nf_nat] [ 1829.901089][ C3] ? __pfx_nf_nat_ipv4_out+0x10/0x10 [nf_nat] [ 1829.901311][ C3] nf_hook_slow+0xba/0x200 [ 1829.901492][ C3] nf_hook+0x374/0x4f0 [ 1829.901632][ C3] ? __pfx_ip_finish_output+0x10/0x10 [ 1829.901812][ C3] ? __pfx_nf_hook+0x10/0x10 [ 1829.901989][ C3] ? __ip_append_data+0x25e4/0x3900 [ 1829.902174][ C3] ? __pfx_ip_finish_output+0x10/0x10 [ 1829.902352][ C3] ip_output+0x172/0x240 [ 1829.902485][ C3] ? __pfx_ip_finish_output+0x10/0x10 [ 1829.902660][ C3] ip_push_pending_frames+0x24b/0x480 [ 1829.902836][ C3] ip_send_unicast_reply+0xac1/0x14b0 [ 1829.903018][ C3] ? hlock_class+0x4e/0x130 [ 1829.903198][ C3] ? mark_lock+0x38/0x3e0 [ 1829.903333][ C3] ? __pfx_ip_send_unicast_reply+0x10/0x10 [ 1829.903550][ C3] ? __lock_acquire+0xb3f/0x1580 [ 1829.903743][ C3] ? lock_acquire.part.0+0xeb/0x330 [ 1829.903929][ C3] ? tcp_v4_send_ack.constprop.0+0x4c4/0x1050 [ 1829.904157][ C3] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 1829.904342][ C3] ? trace_lock_acquire+0x14d/0x1f0 [ 1829.904530][ C3] tcp_v4_send_ack.constprop.0+0x7c6/0x1050 [ 1829.904763][ C3] ? __pfx_tcp_v4_send_ack.constprop.0+0x10/0x10 [ 1829.904986][ C3] ? __pfx___lock_release+0x10/0x10 [ 1829.905166][ C3] ? mark_held_locks+0x9e/0xe0 [ 1829.905349][ C3] ? tcp_v4_rcv+0x2251/0x3460 [ 1829.905527][ C3] tcp_v4_rcv+0x2251/0x3460 [ 1829.905707][ C3] ? __pfx_tcp_v4_rcv+0x10/0x10 [ 1829.905887][ C3] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 1829.906070][ C3] ip_protocol_deliver_rcu+0x93/0x360 [ 1829.906256][ C3] ? process_backlog+0x332/0x1180 [ 1829.906424][ C3] ip_local_deliver_finish+0x2af/0x490 [ 1829.906600][ C3] ? process_backlog+0x332/0x1180 [ 1829.906777][ C3] ? __pfx_ip_rcv+0x10/0x10 [ 1829.906967][ C3] __netif_receive_skb_one_core+0x166/0x1b0 [ 1829.907189][ C3] ? __pfx___netif_receive_skb_one_core+0x10/0x10 [ 1829.907420][ C3] ? process_backlog+0x332/0x1180 [ 1829.907591][ C3] ? lock_acquire+0x32/0xc0 [ 1829.907769][ C3] ? process_backlog+0x332/0x1180 [ 1829.907960][ C3] process_backlog+0x372/0x1180 [ 1829.908138][ C3] __napi_poll.constprop.0+0xa2/0x460 [ 1829.908327][ C3] net_rx_action+0x50e/0xce0 [ 1829.908505][ C3] ? __pfx_net_rx_action+0x10/0x10 [ 1829.908686][ C3] ? clockevents_program_event+0xf6/0x300 [ 1829.908861][ C3] ? kvm_clock_get_cycles+0x18/0x30 [ 1829.909052][ C3] ? ktime_get+0xb7/0x200 [ 1829.909296][ C3] ? hlock_class+0x4e/0x130 [ 1829.909474][ C3] ? mark_lock+0x38/0x3e0 [ 1829.909744][ C3] ? mark_held_locks+0x9e/0xe0 [ 1829.909931][ C3] handle_softirqs+0x1f6/0x5c0 [ 1829.910226][ C3] ? __dev_queue_xmit+0x78e/0x18b0 [ 1829.910407][ C3] do_softirq+0x4d/0xa0 [ 1829.910642][ C3] [ 1829.910739][ C3] [ 1829.910822][ C3] __local_bh_enable_ip+0xf6/0x120 [ 1829.911108][ C3] ? __dev_queue_xmit+0x78e/0x18b0 [ 1829.911397][ C3] __dev_queue_xmit+0x7a3/0x18b0 [ 1829.911576][ C3] ? __lock_release+0x103/0x460 [ 1829.911756][ C3] ? ip_finish_output2+0xac2/0x18f0 [ 1829.911932][ C3] ? __pfx___lock_release+0x10/0x10 [ 1829.912221][ C3] ? hlock_class+0x4e/0x130 [ 1829.912399][ C3] ? __pfx___dev_queue_xmit+0x10/0x10 [ 1829.912578][ C3] ? mark_held_locks+0x9e/0xe0 [ 1829.912864][ C3] ? lockdep_hardirqs_on_prepare+0x275/0x410 [ 1829.913086][ C3] ? neigh_hh_output+0x36f/0x560 [ 1829.913268][ C3] ip_finish_output2+0xac2/0x18f0 [ 1829.913452][ C3] ? __pfx_ip_finish_output2+0x10/0x10 [ 1829.913630][ C3] ? __ip_finish_output+0x10f/0x760 [ 1829.913910][ C3] __ip_queue_xmit+0x64f/0x1790 [ 1829.914092][ C3] ? __skb_clone+0x571/0x750 [ 1829.914276][ C3] __tcp_transmit_skb+0x2291/0x2d10 [ 1829.914466][ C3] ? __pfx___tcp_transmit_skb+0x10/0x10 [ 1829.914655][ C3] ? mark_held_locks+0x9e/0xe0 [ 1829.914939][ C3] ? lockdep_hardirqs_on_prepare+0x275/0x410 [ 1829.915176][ C3] ? tcp_small_queue_check.isra.0+0xe9/0x380 [ 1829.915398][ C3] tcp_write_xmit+0x8a3/0x2cf0 [ 1829.915687][ C3] ? tcp_current_mss+0x40a/0x510 [ 1829.915872][ C3] ? __pfx_tcp_current_mss+0x10/0x10 [ 1829.916065][ C3] ? __alloc_skb+0x23d/0x2e0 [ 1829.916244][ C3] ? __pfx_tcp_write_xmit+0x10/0x10 [ 1829.916423][ C3] ? tcp_set_state+0x10b/0x510 [ 1829.916697][ C3] ? __pfx_tcp_set_state+0x10/0x10 [ 1829.916866][ C3] __tcp_push_pending_frames+0x96/0x320 [ 1829.917151][ C3] inet_shutdown+0x164/0x390 [ 1829.917334][ C3] ? sockfd_lookup_light+0x1a/0x140 [ 1829.917513][ C3] __sys_shutdown+0xcb/0x160 [ 1829.917798][ C3] ? __pfx___sys_shutdown+0x10/0x10 [ 1829.917963][ C3] ? audit_reset_context.part.0.constprop.0+0x987/0xe50 [ 1829.918171][ C3] __x64_sys_shutdown+0x53/0x80 [ 1829.918438][ C3] do_syscall_64+0xc1/0x1d0 [ 1829.918603][ C3] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1829.918807][ C3] RIP: 0033:0x7f8f33226beb [ 1829.918978][ C3] Code: 73 01 c3 48 8b 0d 15 92 1b 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa b8 30 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e5 91 1b 00 f7 d8 64 89 01 48 [ 1829.919551][ C3] RSP: 002b:00007ffd823f5608 EFLAGS: 00000202 ORIG_RAX: 0000000000000030 [ 1829.919909][ C3] RAX: ffffffffffffffda RBX: 00005636628cf610 RCX: 00007f8f33226beb [ 1829.920260][ C3] RDX: 0000000000000008 RSI: 0000000000000002 RDI: 0000000000000008 [ 1829.920505][ C3] RBP: 0000000000000008 R08: 0000000000000001 R09: 0000000000000000 [ 1829.920867][ C3] R10: 0000000000000000 R11: 0000000000000202 R12: ffffffffffffffff [ 1829.921114][ C3] R13: 0000000000000000 R14: 000056363940810e R15: 0000000000000001 [ 1829.921362][ C3] [ 1829.921589][ C3] [ 1829.921676][ C3] Allocated by task 4930: [ 1829.921811][ C3] kasan_save_stack+0x24/0x50 [ 1829.922085][ C3] kasan_save_track+0x14/0x30 [ 1829.922246][ C3] __kasan_slab_alloc+0x59/0x70 [ 1829.922409][ C3] kmem_cache_alloc_noprof+0xdb/0x250 [ 1829.922575][ C3] inet_twsk_alloc+0x115/0x970 [ 1829.922838][ C3] tcp_time_wait+0x60/0xe70 [ 1829.923007][ C3] tcp_rcv_state_process+0xab4/0x2030 [ 1829.923170][ C3] tcp_v4_do_rcv+0x14d/0x8c0 [ 1829.923533][ C3] tcp_v4_rcv+0x25e8/0x3460 [ 1829.923699][ C3] ip_protocol_deliver_rcu+0x93/0x360 [ 1829.923862][ C3] ip_local_deliver_finish+0x2af/0x490 [ 1829.924026][ C3] __netif_receive_skb_one_core+0x166/0x1b0 [ 1829.924330][ C3] process_backlog+0x372/0x1180 [ 1829.924492][ C3] __napi_poll.constprop.0+0xa2/0x460 [ 1829.924674][ C3] net_rx_action+0x50e/0xce0 [ 1829.924836][ C3] handle_softirqs+0x1f6/0x5c0 [ 1829.925109][ C3] do_softirq+0x4d/0xa0 [ 1829.925242][ C3] __local_bh_enable_ip+0xf6/0x120 [ 1829.925422][ C3] nf_reinject+0x2a7/0x900 [nfnetlink_queue] [ 1829.925643][ C3] nfqnl_recv_verdict+0x9a0/0x1320 [nfnetlink_queue] [ 1829.925977][ C3] nfnetlink_rcv_msg+0x4a9/0xed0 [ 1829.926153][ C3] netlink_rcv_skb+0x130/0x360 [ 1829.926324][ C3] nfnetlink_rcv+0x14c/0x340 [ 1829.926490][ C3] netlink_unicast+0x44b/0x710 [ 1829.926653][ C3] netlink_sendmsg+0x723/0xbe0 [ 1829.926918][ C3] __sys_sendto+0x385/0x400 [ 1829.927088][ C3] __x64_sys_sendto+0xe0/0x1c0 [ 1829.927250][ C3] do_syscall_64+0xc1/0x1d0 [ 1829.927409][ C3] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1829.927718][ C3] [ 1829.927801][ C3] Freed by task 0: [ 1829.927914][ C3] kasan_save_stack+0x24/0x50 [ 1829.928080][ C3] kasan_save_track+0x14/0x30 [ 1829.928244][ C3] kasan_save_free_info+0x3b/0x60 [ 1829.928412][ C3] __kasan_slab_free+0x38/0x50 [ 1829.928687][ C3] slab_free_after_rcu_debug+0xd7/0x2b0 [ 1829.928851][ C3] rcu_do_batch+0x34f/0xf20 [ 1829.929132][ C3] rcu_core+0x2bd/0x4f0 [ 1829.929266][ C3] handle_softirqs+0x1f6/0x5c0 [ 1829.929542][ C3] irq_exit_rcu+0x99/0xc0 [ 1829.929666][ C3] sysvec_apic_timer_interrupt+0x78/0x90 [ 1829.929830][ C3] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 1829.930034][ C3] [ 1829.930120][ C3] Last potentially related work creation: [ 1829.930393][ C3] kasan_save_stack+0x24/0x50 [ 1829.930558][ C3] __kasan_record_aux_stack+0x8e/0xa0 [ 1829.930827][ C3] kmem_cache_free+0x207/0x340 [ 1829.931101][ C3] inet_twsk_free+0x11d/0x180 [ 1829.931264][ C3] inet_twsk_purge+0x4c8/0x660 [ 1829.931429][ C3] tcp_twsk_purge+0x112/0x160 [ 1829.931593][ C3] tcp_sk_exit_batch+0x28/0x140 [ 1829.931860][ C3] cleanup_net+0x4ef/0x9d0 [ 1829.932035][ C3] process_one_work+0xe55/0x16d0 [ 1829.932199][ C3] worker_thread+0x58c/0xce0 [ 1829.932361][ C3] kthread+0x28a/0x350 [ 1829.932590][ C3] ret_from_fork+0x31/0x70 [ 1829.932754][ C3] ret_from_fork_asm+0x1a/0x30 [ 1829.932917][ C3] [ 1829.933009][ C3] The buggy address belongs to the object at ffff8880146f1b20 [ 1829.933009][ C3] which belongs to the cache tw_sock_TCP of size 280 [ 1829.933514][ C3] The buggy address is located 32 bytes inside of [ 1829.933514][ C3] freed 280-byte region [ffff8880146f1b20, ffff8880146f1c38) [ 1829.933919][ C3] [ 1829.934015][ C3] The buggy address belongs to the physical page: [ 1829.934224][ C3] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff8880146f1e50 pfn:0x146f0 [ 1829.934562][ C3] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 1829.934917][ C3] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 1829.935139][ C3] page_type: f5(slab) [ 1829.935268][ C3] raw: 0080000000000240 ffff88800370cc40 ffffea0000225910 ffff8880034b0bc8 [ 1829.935675][ C3] raw: ffff8880146f1e50 0000000000140001 00000001f5000000 0000000000000000 [ 1829.935978][ C3] head: 0080000000000240 ffff88800370cc40 ffffea0000225910 ffff8880034b0bc8 [ 1829.936381][ C3] head: ffff8880146f1e50 0000000000140001 00000001f5000000 0000000000000000 [ 1829.936675][ C3] head: 0080000000000001 ffffea000051bc01 ffffffffffffffff 0000000000000000 [ 1829.937073][ C3] head: 0000000000000002 0000000000000000 00000000ffffffff 0000000000000000 [ 1829.937462][ C3] page dumped because: kasan: bad access detected [ 1829.937672][ C3] [ 1829.937753][ C3] Memory state around the buggy address: [ 1829.938025][ C3] ffff8880146f1a00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 1829.938265][ C3] ffff8880146f1a80: 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc fc [ 1829.938617][ C3] >ffff8880146f1b00: fc fc fc fc fa fb fb fb fb fb fb fb fb fb fb fb [ 1829.938853][ C3] ^ [ 1829.939071][ C3] ffff8880146f1b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 1829.939327][ C3] ffff8880146f1c00: fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc fc [ 1829.939581][ C3] ================================================================== [ 1829.939868][ C3] Disabling lock debugging due to kernel taint [ 1831.883171][ C0] Oops: general protection fault, probably for non-canonical address 0xf9999599999999e1: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 1831.883679][ C0] KASAN: maybe wild-memory-access in range [0xcccccccccccccf08-0xcccccccccccccf0f] [ 1831.883998][ C0] CPU: 0 UID: 0 PID: 9414 Comm: socat Tainted: G B 6.12.0-rc1-virtme #1 [ 1831.884324][ C0] Tainted: [B]=BAD_PAGE [ 1831.884467][ C0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 1831.884893][ C0] RIP: 0010:xfrm_sk_policy_lookup+0x10f/0x4e0 [ 1831.885136][ C0] Code: 48 89 44 24 18 0f b7 44 24 06 89 44 24 28 e9 a9 01 00 00 4d 85 ed 0f 84 2f 02 00 00 49 8d bd 3e 02 00 00 48 89 f8 48 c1 e8 03 <0f> b6 14 18 48 89 f8 83 e0 07 83 c0 01 38 d0 7c 08 84 d2 0f 85 8c [ 1831.885786][ C0] RSP: 0018:ffffc90000006a80 EFLAGS: 00010a06 [ 1831.886027][ C0] RAX: 19999999999999e1 RBX: dffffc0000000000 RCX: ffffffff9d3174b8 [ 1831.886312][ C0] RDX: 0000000000000000 RSI: 0000000000000008 RDI: cccccccccccccf0a [ 1831.886585][ C0] RBP: ffff8880146f1e50 R08: 0000000000000000 R09: 0000000000000000 [ 1831.886858][ C0] R10: ffffffff9f37388f R11: dffffc0000000000 R12: 0000000000000000 [ 1831.887132][ C0] R13: cccccccccccccccc R14: ffff8880146f1e50 R15: ffffc90000006c70 [ 1831.887408][ C0] FS: 00007f8f33198740(0000) GS:ffff888036000000(0000) knlGS:0000000000000000 [ 1831.887726][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1831.887975][ C0] CR2: 00005636628d5b88 CR3: 0000000002592003 CR4: 0000000000772ef0 [ 1831.888256][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1831.888535][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 1831.888805][ C0] PKRU: 55555554 [ 1831.888960][ C0] Call Trace: [ 1831.889109][ C0] [ 1831.889206][ C0] ? die_addr+0x41/0xa0 [ 1831.889356][ C0] ? exc_general_protection+0x14d/0x230 [ 1831.889546][ C0] ? asm_exc_general_protection+0x26/0x30 [ 1831.889731][ C0] ? xfrm_sk_policy_lookup+0x4c8/0x4e0 [ 1831.889922][ C0] ? xfrm_sk_policy_lookup+0x10f/0x4e0 [ 1831.890106][ C0] ? __pfx_xfrm_sk_policy_lookup+0x10/0x10 [ 1831.890340][ C0] xfrm_lookup_with_ifid+0x154/0xa90 [ 1831.890546][ C0] ? __pfx_xfrm_lookup_with_ifid+0x10/0x10 [ 1831.890794][ C0] ? l4proto_manip_pkt+0x670/0x10f0 [nf_nat] [ 1831.891043][ C0] nf_xfrm_me_harder+0x1a8/0x5e0 [nf_nat] [ 1831.891247][ C0] ? __pfx_nf_xfrm_me_harder+0x10/0x10 [nf_nat] [ 1831.891492][ C0] ? nft_do_chain_ipv4+0x184/0x210 [nf_tables] [ 1831.891765][ C0] ? __pfx_nft_do_chain_ipv4+0x10/0x10 [nf_tables] [ 1831.892024][ C0] nf_nat_ipv4_out+0x3c7/0x470 [nf_nat] [ 1831.892209][ C0] ? __pfx_nf_nat_ipv4_out+0x10/0x10 [nf_nat] [ 1831.892435][ C0] nf_hook_slow+0xba/0x200 [ 1831.892619][ C0] nf_hook+0x374/0x4f0 [ 1831.892763][ C0] ? __pfx_ip_finish_output+0x10/0x10 [ 1831.892944][ C0] ? __pfx_nf_hook+0x10/0x10 [ 1831.893129][ C0] ? __pfx_ip_finish_output+0x10/0x10 [ 1831.893314][ C0] ? nf_nat_ipv4_local_fn+0x103/0x4d0 [nf_nat] [ 1831.893540][ C0] ip_output+0x172/0x240 [ 1831.893676][ C0] ? __pfx_ip_finish_output+0x10/0x10 [ 1831.893864][ C0] vrf_ip_local_out+0x692/0x860 [ 1831.894047][ C0] ? __pfx_vrf_ip_local_out+0x10/0x10 [ 1831.894226][ C0] ? hpet_cpuhp_online+0x1a3/0x6d0 [ 1831.894410][ C0] ? __pfx_dst_output+0x10/0x10 [ 1831.894604][ C0] vrf_process_v4_outbound+0x5d3/0xca0 [ 1831.894788][ C0] ? __pfx_vrf_process_v4_outbound+0x10/0x10 [ 1831.895019][ C0] ? arch_stack_walk+0x79/0xf0 [ 1831.895206][ C0] vrf_xmit+0x129/0x180 [ 1831.895350][ C0] dev_hard_start_xmit+0x10e/0x360 [ 1831.895535][ C0] sch_direct_xmit+0x1e0/0xa60 [ 1831.895722][ C0] ? __pfx_sch_direct_xmit+0x10/0x10 [ 1831.895901][ C0] ? do_raw_spin_lock+0x131/0x270 [ 1831.896087][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 1831.896262][ C0] ? lock_acquire+0x32/0xc0 [ 1831.896451][ C0] ? __dev_xmit_skb+0x301/0x10a0 [ 1831.896636][ C0] __dev_xmit_skb+0x7b2/0x10a0 [ 1831.896827][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 1831.897028][ C0] ? __pfx___dev_xmit_skb+0x10/0x10 [ 1831.897317][ C0] ? __dev_queue_xmit+0x1e1/0x18b0 [ 1831.897526][ C0] ? lock_acquire+0x32/0xc0 [ 1831.897707][ C0] ? __dev_queue_xmit+0x1e1/0x18b0 [ 1831.897896][ C0] __dev_queue_xmit+0x76c/0x18b0 [ 1831.898186][ C0] ? __pfx___alloc_skb+0x10/0x10 [ 1831.898384][ C0] ? __pfx_nft_do_chain_ipv4+0x10/0x10 [nf_tables] [ 1831.898768][ C0] ? __pfx_nf_confirm+0x10/0x10 [nf_conntrack] [ 1831.899137][ C0] ? __pfx___dev_queue_xmit+0x10/0x10 [ 1831.899341][ C0] ? trace_lock_release+0x10e/0x180 [ 1831.899526][ C0] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 1831.899878][ C0] ? neigh_hh_output+0x36f/0x560 [ 1831.900063][ C0] ? vrf_finish_output+0x1c9/0x17d0 [ 1831.900255][ C0] vrf_finish_output+0xa26/0x17d0 [ 1831.900445][ C0] ? __pfx_vrf_finish_output+0x10/0x10 [ 1831.900744][ C0] ? __pfx_vrf_finish_output+0x10/0x10 [ 1831.901045][ C0] ? vrf_output+0x1cb/0x290 [ 1831.901236][ C0] ip_push_pending_frames+0x2c0/0x480 [ 1831.901419][ C0] ip_send_unicast_reply+0xac1/0x14b0 [ 1831.901714][ C0] ? do_raw_spin_lock+0x131/0x270 [ 1831.901890][ C0] ? __pfx_ip_send_unicast_reply+0x10/0x10 [ 1831.902232][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 1831.902399][ C0] ? trace_lock_release+0x10e/0x180 [ 1831.902691][ C0] ? lock_timer_base+0x4e/0x1d0 [ 1831.902866][ C0] ? lock_acquire+0x32/0xc0 [ 1831.903033][ C0] ? lock_timer_base+0x4e/0x1d0 [ 1831.903202][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 1831.903484][ C0] ? trace_lock_release+0x10e/0x180 [ 1831.903769][ C0] tcp_v4_send_ack.constprop.0+0x7c6/0x1050 [ 1831.904000][ C0] ? __pfx_tcp_v4_send_ack.constprop.0+0x10/0x10 [ 1831.904334][ C0] ? trace_lock_release+0x10e/0x180 [ 1831.904508][ C0] ? tcp_v4_rcv+0x2251/0x3460 [ 1831.904689][ C0] tcp_v4_rcv+0x2251/0x3460 [ 1831.904975][ C0] ? __pfx_tcp_v4_rcv+0x10/0x10 [ 1831.905159][ C0] ? nf_hook.constprop.0+0x102/0x4d0 [ 1831.905332][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 1831.905613][ C0] ip_protocol_deliver_rcu+0x93/0x360 [ 1831.905783][ C0] ? process_backlog+0x332/0x1180 [ 1831.905957][ C0] ip_local_deliver_finish+0x2af/0x490 [ 1831.906141][ C0] ? process_backlog+0x332/0x1180 [ 1831.906327][ C0] ? __pfx_ip_rcv+0x10/0x10 [ 1831.906508][ C0] __netif_receive_skb_one_core+0x166/0x1b0 [ 1831.906738][ C0] ? __pfx___netif_receive_skb_one_core+0x10/0x10 [ 1831.907070][ C0] ? process_backlog+0x332/0x1180 [ 1831.907237][ C0] ? lock_acquire+0x32/0xc0 [ 1831.907409][ C0] ? process_backlog+0x332/0x1180 [ 1831.907578][ C0] process_backlog+0x372/0x1180 [ 1831.907746][ C0] __napi_poll.constprop.0+0xa2/0x460 [ 1831.908033][ C0] net_rx_action+0x50e/0xce0 [ 1831.908206][ C0] ? __pfx_net_rx_action+0x10/0x10 [ 1831.908484][ C0] ? do_raw_spin_lock+0x131/0x270 [ 1831.908653][ C0] ? trace_lock_release+0x10e/0x180 [ 1831.908935][ C0] ? _nohz_idle_balance.isra.0+0x228/0x660 [ 1831.909258][ C0] ? kvm_sched_clock_read+0x11/0x20 [ 1831.909549][ C0] ? sched_clock+0x10/0x30 [ 1831.909717][ C0] ? sched_clock_cpu+0x6d/0x500 [ 1831.910004][ C0] ? trace_lock_release+0x10e/0x180 [ 1831.910188][ C0] ? tick_nohz_start_idle+0xb3/0x210 [ 1831.910365][ C0] handle_softirqs+0x1f6/0x5c0 [ 1831.910540][ C0] ? __dev_queue_xmit+0x78e/0x18b0 [ 1831.910821][ C0] do_softirq+0x4d/0xa0 [ 1831.910950][ C0] [ 1831.911037][ C0] [ 1831.911122][ C0] __local_bh_enable_ip+0xf6/0x120 [ 1831.911292][ C0] ? __dev_queue_xmit+0x78e/0x18b0 [ 1831.911478][ C0] __dev_queue_xmit+0x7a3/0x18b0 [ 1831.911761][ C0] ? __kernel_text_address+0x12/0x40 [ 1831.912062][ C0] ? unwind_get_return_address+0x5e/0xa0 [ 1831.912252][ C0] ? __pfx_stack_trace_consume_entry+0x10/0x10 [ 1831.912463][ C0] ? arch_stack_walk+0xa2/0xf0 [ 1831.912749][ C0] ? __pfx___dev_queue_xmit+0x10/0x10 [ 1831.913027][ C0] ? trace_lock_release+0x10e/0x180 [ 1831.913197][ C0] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 1831.913415][ C0] ? neigh_hh_output+0x36f/0x560 [ 1831.913706][ C0] ? ip_finish_output2+0x265/0x18f0 [ 1831.913876][ C0] ip_finish_output2+0xac2/0x18f0 [ 1831.914168][ C0] ? lock_release+0x13/0x140 [ 1831.914337][ C0] ? trace_lock_acquire+0x14d/0x1f0 [ 1831.914635][ C0] ? __pfx_ip_finish_output2+0x10/0x10 [ 1831.914804][ C0] ? rcu_read_lock_held+0xe/0x50 [ 1831.914986][ C0] ? __ip_finish_output+0x10f/0x760 [ 1831.915154][ C0] __ip_queue_xmit+0x64f/0x1790 [ 1831.915439][ C0] ? __skb_clone+0x571/0x750 [ 1831.915608][ C0] __tcp_transmit_skb+0x2291/0x2d10 [ 1831.915927][ C0] ? __pfx___tcp_transmit_skb+0x10/0x10 [ 1831.916097][ C0] ? trace_irq_enable.constprop.0+0xe4/0x140 [ 1831.916440][ C0] ? tcp_small_queue_check.isra.0+0xe9/0x380 [ 1831.916650][ C0] tcp_write_xmit+0x8a3/0x2cf0 [ 1831.916822][ C0] ? tcp_current_mss+0x40a/0x510 [ 1831.916998][ C0] ? __pfx_tcp_current_mss+0x10/0x10 [ 1831.917166][ C0] ? __alloc_skb+0x23d/0x2e0 [ 1831.917337][ C0] ? __pfx_tcp_write_xmit+0x10/0x10 [ 1831.917615][ C0] ? tcp_set_state+0x10b/0x510 [ 1831.917783][ C0] ? __pfx_tcp_set_state+0x10/0x10 [ 1831.917956][ C0] ? lock_acquire+0x32/0xc0 [ 1831.918237][ C0] ? lock_sock_nested+0x59/0xe0 [ 1831.918408][ C0] __tcp_push_pending_frames+0x96/0x320 [ 1831.918578][ C0] inet_shutdown+0x164/0x390 [ 1831.918862][ C0] ? sockfd_lookup_light+0x1a/0x140 [ 1831.919035][ C0] __sys_shutdown+0xcb/0x160 [ 1831.919315][ C0] ? __pfx___sys_shutdown+0x10/0x10 [ 1831.919483][ C0] ? audit_reset_context.part.0.constprop.0+0x987/0xe50 [ 1831.919695][ C0] __x64_sys_shutdown+0x53/0x80 [ 1831.919866][ C0] do_syscall_64+0xc1/0x1d0 [ 1831.920145][ C0] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 1831.920358][ C0] RIP: 0033:0x7f8f33226beb [ 1831.920530][ C0] Code: 73 01 c3 48 8b 0d 15 92 1b 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa b8 30 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e5 91 1b 00 f7 d8 64 89 01 48 [ 1831.921264][ C0] RSP: 002b:00007ffd823f5608 EFLAGS: 00000202 ORIG_RAX: 0000000000000030 [ 1831.921661][ C0] RAX: ffffffffffffffda RBX: 00005636628cf610 RCX: 00007f8f33226beb [ 1831.922069][ C0] RDX: 0000000000000008 RSI: 0000000000000002 RDI: 0000000000000008 [ 1831.922341][ C0] RBP: 0000000000000008 R08: 0000000000000001 R09: 0000000000000000 [ 1831.922610][ C0] R10: 0000000000000000 R11: 0000000000000202 R12: ffffffffffffffff [ 1831.922997][ C0] R13: 0000000000000000 R14: 000056363940810e R15: 0000000000000001 [ 1831.923297][ C0] [ 1831.923554][ C0] Modules linked in: sch_netem cls_u32 sch_htb nft_synproxy nf_synproxy_core xt_REDIRECT xt_nat nf_conntrack_ftp ebtable_filter ebt_redirect ebt_ip ebtable_broute ebtables ts_kmp ts_bm xt_string vxlan nf_log_syslog nft_log nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib ip6t_rpfilter ipt_rpfilter dummy nft_tproxy nf_tproxy_ipv6 nf_tproxy_ipv4 nft_quota ipip ip_vs_rr ip_vs xt_tcpudp xt_conntrack nft_compat x_tables tun sctp_diag nft_limit nfnetlink_queue nft_queue sctp ip6_udp_tunnel udp_tunnel nft_meta_bridge br_netfilter macvlan nft_numgen nf_conntrack_netlink nft_redir esp4 sha1_generic xfrm_user 8021q bridge stp llc nft_masq nft_nat nft_chain_nat nf_nat tcp_diag inet_diag nft_flow_offload nft_ct nf_flow_table_inet nf_flow_table nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables libcrc32c veth [ 1831.926272][ C0] ---[ end trace 0000000000000000 ]--- [ 1831.926464][ C0] RIP: 0010:xfrm_sk_policy_lookup+0x10f/0x4e0 [ 1831.926811][ C0] Code: 48 89 44 24 18 0f b7 44 24 06 89 44 24 28 e9 a9 01 00 00 4d 85 ed 0f 84 2f 02 00 00 49 8d bd 3e 02 00 00 48 89 f8 48 c1 e8 03 <0f> b6 14 18 48 89 f8 83 e0 07 83 c0 01 38 d0 7c 08 84 d2 0f 85 8c [ 1831.927711][ C0] RSP: 0018:ffffc90000006a80 EFLAGS: 00010a06 [ 1831.927945][ C0] RAX: 19999999999999e1 RBX: dffffc0000000000 RCX: ffffffff9d3174b8 [ 1831.928214][ C0] RDX: 0000000000000000 RSI: 0000000000000008 RDI: cccccccccccccf0a [ 1831.928495][ C0] RBP: ffff8880146f1e50 R08: 0000000000000000 R09: 0000000000000000 [ 1831.928755][ C0] R10: ffffffff9f37388f R11: dffffc0000000000 R12: 0000000000000000 [ 1831.929031][ C0] R13: cccccccccccccccc R14: ffff8880146f1e50 R15: ffffc90000006c70 [ 1831.929428][ C0] FS: 00007f8f33198740(0000) GS:ffff888036000000(0000) knlGS:0000000000000000 [ 1831.929739][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1831.930086][ C0] CR2: 00005636628d5b88 CR3: 0000000002592003 CR4: 0000000000772ef0 [ 1831.930368][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1831.930650][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 1831.931041][ C0] PKRU: 55555554 [ 1831.931181][ C0] Kernel panic - not syncing: Fatal exception in interrupt [ 1831.931658][ C0] Kernel Offset: 0x19a00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 1831.932064][ C0] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr