====================================== | [ 18.418650] ata10: SATA link down (SStatus 0 SControl 300) | [ 18.566212] ------------[ cut here ]------------ | [ 18.572684] UBSAN: array-index-out-of-bounds in drivers/net/ethernet/broadcom/bnxt/bnxt.c:2588:26 | [ 18.583547] index 12 is out of range for type 'bnxt_bs_trace_info [11]' | [ 18.591773] CPU: 0 UID: 0 PID: 243 Comm: kworker/0:2 Not tainted 7.0.0-rc3-qoaf-g32dca9ae1adf #1 PREEMPT(full) [ 18.591777] Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R30_F44 12/24/2025 [ 18.591778] Workqueue: sync_wq local_pci_probe_callback [ 18.591788] Call Trace: [ 18.591789] [ 18.591793] dump_stack_lvl+0x6f/0xa0 [ 18.591800] ubsan_epilogue+0x5/0x2b [ 18.591804] __ubsan_handle_out_of_bounds.cold+0x54/0x59 [ 18.591808] bnxt_backing_store_cfg_v2+0x8d5/0xa00 [ 18.591815] bnxt_alloc_ctx_mem+0x610/0x970 [ 18.591820] bnxt_hwrm_func_qcaps.part.0+0x62f/0xb20 [ 18.591824] ? __bnxt_hwrm_func_qcaps+0xe15/0x1c30 [ 18.591828] ? bnxt_hwrm_func_resc_qcaps+0x1040/0x1040 [ 18.591834] bnxt_fw_init_one_p2+0x89/0xda0 [ 18.591837] ? bnxt_hwrm_func_qcaps.part.0+0xb20/0xb20 [ 18.591839] ? trace_kmalloc+0x107/0x130 [ 18.591843] ? __kasan_kmalloc+0x7b/0x90 [ 18.591847] ? __kmalloc_noprof+0x30c/0x7e0 [ 18.591852] bnxt_init_one+0x55b/0x29b0 [ 18.591857] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 18.591861] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 18.591865] ? lockdep_hardirqs_on+0x84/0x130 [ 18.591869] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 18.591872] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 18.591875] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 18.591878] local_pci_probe+0xcc/0x170 [ 18.591881] local_pci_probe_callback+0x35/0x80 [ 18.591883] ? process_one_work+0xd30/0x1390 [ 18.591886] process_one_work+0xd57/0x1390 [ 18.591892] ? pwq_dec_nr_in_flight+0x700/0x700 [ 18.591894] ? lock_acquire.part.0+0xbc/0x260 [ 18.591902] worker_thread+0x4d6/0xd40 [ 18.591906] ? rescuer_thread+0x1330/0x1330 [ 18.591908] ? __kthread_parkme+0xb3/0x200 [ 18.591912] ? rescuer_thread+0x1330/0x1330 [ 18.591914] kthread+0x30f/0x3f0 [ 18.591916] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 18.591919] ? kthread_affine_node+0x150/0x150 [ 18.591922] ret_from_fork+0x4a2/0x720 [ 18.591925] ? arch_exit_to_user_mode_prepare.isra.0+0xb0/0xb0 [ 18.591929] ? __switch_to+0x538/0xcf0 [ 18.591932] ? kthread_affine_node+0x150/0x150 [ 18.591935] ret_from_fork_asm+0x11/0x20 | [ 18.747879] ================================================================== | [ 18.748875] BUG: KASAN: slab-out-of-bounds in bnxt_backing_store_cfg_v2+0x88b/0xa00 | [ 18.748875] Write of size 2 at addr ff1100011fbb2b86 by task kworker/0:2/243 | [ 18.748875] | [ 18.748875] CPU: 0 UID: 0 PID: 243 Comm: kworker/0:2 Not tainted 7.0.0-rc3-qoaf-g32dca9ae1adf #1 PREEMPT(full) [ 18.748875] Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R30_F44 12/24/2025 [ 18.748875] Workqueue: sync_wq local_pci_probe_callback [ 18.748875] Call Trace: [ 18.748875] [ 18.748875] dump_stack_lvl+0x6f/0xa0 [ 18.748875] print_address_description.constprop.0+0x6e/0x300 [ 18.748875] print_report+0xfc/0x1fb [ 18.748875] ? bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 18.748875] ? __virt_addr_valid+0x1da/0x430 [ 18.748875] ? bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 18.748875] kasan_report+0xe8/0x120 [ 18.748875] ? bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 18.748875] bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 18.748875] bnxt_alloc_ctx_mem+0x610/0x970 [ 18.748875] bnxt_hwrm_func_qcaps.part.0+0x62f/0xb20 [ 18.748875] ? __bnxt_hwrm_func_qcaps+0xe15/0x1c30 [ 18.748875] ? bnxt_hwrm_func_resc_qcaps+0x1040/0x1040 [ 18.748875] bnxt_fw_init_one_p2+0x89/0xda0 [ 18.748875] ? bnxt_hwrm_func_qcaps.part.0+0xb20/0xb20 [ 18.748875] ? trace_kmalloc+0x107/0x130 [ 18.748875] ? __kasan_kmalloc+0x7b/0x90 [ 18.748875] ? __kmalloc_noprof+0x30c/0x7e0 [ 18.748875] bnxt_init_one+0x55b/0x29b0 [ 18.748875] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 18.748875] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 18.748875] ? lockdep_hardirqs_on+0x84/0x130 [ 18.748875] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 18.748875] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 18.748875] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 18.748875] local_pci_probe+0xcc/0x170 [ 18.748875] local_pci_probe_callback+0x35/0x80 [ 18.748875] ? process_one_work+0xd30/0x1390 [ 18.748875] process_one_work+0xd57/0x1390 [ 18.748875] ? pwq_dec_nr_in_flight+0x700/0x700 [ 18.748875] ? lock_acquire.part.0+0xbc/0x260 [ 18.748875] worker_thread+0x4d6/0xd40 [ 18.748875] ? rescuer_thread+0x1330/0x1330 [ 18.748875] ? __kthread_parkme+0xb3/0x200 [ 18.748875] ? rescuer_thread+0x1330/0x1330 [ 18.748875] kthread+0x30f/0x3f0 [ 18.748875] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 18.748875] ? kthread_affine_node+0x150/0x150 [ 18.748875] ret_from_fork+0x4a2/0x720 [ 18.748875] ? arch_exit_to_user_mode_prepare.isra.0+0xb0/0xb0 [ 18.748875] ? __switch_to+0x538/0xcf0 [ 18.748875] ? kthread_affine_node+0x150/0x150 [ 18.748875] ret_from_fork_asm+0x11/0x20 | [ 19.365773] ------------[ cut here ]------------ | [ 19.371747] UBSAN: array-index-out-of-bounds in drivers/net/ethernet/broadcom/bnxt/bnxt.c:9202:27 | [ 19.382498] index 12 is out of range for type 'bnxt_bs_trace_info [11]' | [ 19.390713] CPU: 0 UID: 0 PID: 243 Comm: kworker/0:2 Tainted: G B 7.0.0-rc3-qoaf-g32dca9ae1adf #1 PREEMPT(full) | [ 19.390715] Tainted: [B]=BAD_PAGE [ 19.390716] Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R30_F44 12/24/2025 [ 19.390717] Workqueue: sync_wq local_pci_probe_callback [ 19.390719] Call Trace: [ 19.390720] [ 19.390721] dump_stack_lvl+0x6f/0xa0 [ 19.390723] ubsan_epilogue+0x5/0x2b [ 19.390725] __ubsan_handle_out_of_bounds.cold+0x54/0x59 [ 19.390727] bnxt_hwrm_func_backing_store_cfg_v2+0xad0/0xb80 [ 19.390730] ? bnxt_request_irq+0x8c0/0x8c0 [ 19.390732] bnxt_backing_store_cfg_v2+0x4d7/0xa00 [ 19.390735] bnxt_alloc_ctx_mem+0x610/0x970 [ 19.390737] bnxt_hwrm_func_qcaps.part.0+0x62f/0xb20 [ 19.390739] ? __bnxt_hwrm_func_qcaps+0xe15/0x1c30 [ 19.390742] ? bnxt_hwrm_func_resc_qcaps+0x1040/0x1040 [ 19.390745] bnxt_fw_init_one_p2+0x89/0xda0 [ 19.390747] ? bnxt_hwrm_func_qcaps.part.0+0xb20/0xb20 [ 19.390749] ? trace_kmalloc+0x107/0x130 [ 19.390751] ? __kasan_kmalloc+0x7b/0x90 [ 19.390752] ? __kmalloc_noprof+0x30c/0x7e0 [ 19.390754] bnxt_init_one+0x55b/0x29b0 [ 19.390757] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 19.390760] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 19.390762] ? lockdep_hardirqs_on+0x84/0x130 [ 19.390763] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 19.390765] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 19.390767] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 19.390769] local_pci_probe+0xcc/0x170 [ 19.390771] local_pci_probe_callback+0x35/0x80 [ 19.390772] ? process_one_work+0xd30/0x1390 [ 19.390774] process_one_work+0xd57/0x1390 [ 19.390777] ? pwq_dec_nr_in_flight+0x700/0x700 [ 19.390778] ? lock_acquire.part.0+0xbc/0x260 [ 19.390782] worker_thread+0x4d6/0xd40 [ 19.390784] ? rescuer_thread+0x1330/0x1330 [ 19.390786] ? __kthread_parkme+0xb3/0x200 [ 19.390787] ? rescuer_thread+0x1330/0x1330 [ 19.390789] kthread+0x30f/0x3f0 [ 19.390790] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 19.390792] ? kthread_affine_node+0x150/0x150 [ 19.390793] ret_from_fork+0x4a2/0x720 [ 19.390795] ? arch_exit_to_user_mode_prepare.isra.0+0xb0/0xb0 [ 19.390797] ? __switch_to+0x538/0xcf0 [ 19.390799] ? kthread_affine_node+0x150/0x150 [ 19.390800] ret_from_fork_asm+0x11/0x20 Finger prints: print_report:kasan_report:bnxt_backing_store_cfg_v2:bnxt_alloc_ctx_mem:bnxt_fw_init_one_p2 ubsan_epilogue:bnxt_hwrm_func_backing_store_cfg_v2:bnxt_backing_store_cfg_v2:bnxt_alloc_ctx_mem:bnxt_fw_init_one_p2 ubsan_epilogue:bnxt_backing_store_cfg_v2:bnxt_alloc_ctx_mem:bnxt_fw_init_one_p2:bnxt_init_one