====================================== | [ 19.138955] ata10: SATA link down (SStatus 0 SControl 300) | [ 19.299029] ------------[ cut here ]------------ | [ 19.305016] UBSAN: array-index-out-of-bounds in drivers/net/ethernet/broadcom/bnxt/bnxt.c:2588:26 | [ 19.315773] index 12 is out of range for type 'bnxt_bs_trace_info [11]' | [ 19.324001] CPU: 0 UID: 0 PID: 253 Comm: kworker/0:2 Not tainted 7.0.0-rc3-anxy-gdc41423dc228 #1 PREEMPT(full) [ 19.324005] Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R30_F44 12/24/2025 [ 19.324008] Workqueue: sync_wq local_pci_probe_callback [ 19.324017] Call Trace: [ 19.324018] [ 19.324022] dump_stack_lvl+0x6f/0xa0 [ 19.324028] ubsan_epilogue+0x5/0x2b [ 19.324032] __ubsan_handle_out_of_bounds.cold+0x54/0x59 [ 19.324036] bnxt_backing_store_cfg_v2+0x8d5/0xa00 [ 19.324043] bnxt_alloc_ctx_mem+0x610/0x970 [ 19.324048] bnxt_hwrm_func_qcaps.part.0+0x62f/0xb20 [ 19.324052] ? __bnxt_hwrm_func_qcaps+0xe15/0x1c30 [ 19.324057] ? bnxt_hwrm_func_resc_qcaps+0x1040/0x1040 [ 19.324063] bnxt_fw_init_one_p2+0x89/0xda0 [ 19.324066] ? bnxt_hwrm_func_qcaps.part.0+0xb20/0xb20 [ 19.324068] ? trace_kmalloc+0x107/0x130 [ 19.324072] ? __kasan_kmalloc+0x7b/0x90 [ 19.324075] ? __kmalloc_noprof+0x30c/0x7e0 [ 19.324080] bnxt_init_one+0x55b/0x29b0 [ 19.324085] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 19.324089] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 19.324093] ? lockdep_hardirqs_on+0x84/0x130 [ 19.324096] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 19.324100] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 19.324103] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 19.324106] local_pci_probe+0xcc/0x170 [ 19.324108] local_pci_probe_callback+0x35/0x80 [ 19.324110] ? process_one_work+0xd30/0x1390 [ 19.324113] process_one_work+0xd57/0x1390 [ 19.324119] ? pwq_dec_nr_in_flight+0x700/0x700 [ 19.324121] ? lock_acquire.part.0+0xbc/0x260 [ 19.324129] worker_thread+0x4d6/0xd40 [ 19.324133] ? rescuer_thread+0x1330/0x1330 [ 19.324135] ? __kthread_parkme+0xb3/0x200 [ 19.324139] ? rescuer_thread+0x1330/0x1330 [ 19.324141] kthread+0x30f/0x3f0 [ 19.324143] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 19.324146] ? kthread_affine_node+0x150/0x150 [ 19.324148] ret_from_fork+0x4a2/0x720 [ 19.324152] ? arch_exit_to_user_mode_prepare.isra.0+0xb0/0xb0 [ 19.324156] ? __switch_to+0x538/0xcf0 [ 19.324158] ? kthread_affine_node+0x150/0x150 [ 19.324161] ret_from_fork_asm+0x11/0x20 | [ 19.473164] ================================================================== | [ 19.474145] BUG: KASAN: slab-out-of-bounds in bnxt_backing_store_cfg_v2+0x88b/0xa00 | [ 19.474145] Write of size 2 at addr ff11000121a5ab86 by task kworker/0:2/253 | [ 19.474145] | [ 19.474145] CPU: 0 UID: 0 PID: 253 Comm: kworker/0:2 Not tainted 7.0.0-rc3-anxy-gdc41423dc228 #1 PREEMPT(full) [ 19.474145] Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R30_F44 12/24/2025 [ 19.474145] Workqueue: sync_wq local_pci_probe_callback [ 19.474145] Call Trace: [ 19.474145] [ 19.474145] dump_stack_lvl+0x6f/0xa0 [ 19.474145] print_address_description.constprop.0+0x6e/0x300 [ 19.474145] print_report+0xfc/0x1fb [ 19.474145] ? bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 19.474145] ? __virt_addr_valid+0x1da/0x430 [ 19.474145] ? bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 19.474145] kasan_report+0xe8/0x120 [ 19.474145] ? bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 19.474145] bnxt_backing_store_cfg_v2+0x88b/0xa00 [ 19.474145] bnxt_alloc_ctx_mem+0x610/0x970 [ 19.474145] bnxt_hwrm_func_qcaps.part.0+0x62f/0xb20 [ 19.474145] ? __bnxt_hwrm_func_qcaps+0xe15/0x1c30 [ 19.474145] ? bnxt_hwrm_func_resc_qcaps+0x1040/0x1040 [ 19.474145] bnxt_fw_init_one_p2+0x89/0xda0 [ 19.474145] ? bnxt_hwrm_func_qcaps.part.0+0xb20/0xb20 [ 19.474145] ? trace_kmalloc+0x107/0x130 [ 19.474145] ? __kasan_kmalloc+0x7b/0x90 [ 19.474145] ? __kmalloc_noprof+0x30c/0x7e0 [ 19.474145] bnxt_init_one+0x55b/0x29b0 [ 19.474145] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 19.474145] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 19.474145] ? lockdep_hardirqs_on+0x84/0x130 [ 19.474145] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 19.474145] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 19.474145] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 19.474145] local_pci_probe+0xcc/0x170 [ 19.474145] local_pci_probe_callback+0x35/0x80 [ 19.474145] ? process_one_work+0xd30/0x1390 [ 19.474145] process_one_work+0xd57/0x1390 [ 19.474145] ? pwq_dec_nr_in_flight+0x700/0x700 [ 19.474145] ? lock_acquire.part.0+0xbc/0x260 [ 19.474145] worker_thread+0x4d6/0xd40 [ 19.474145] ? rescuer_thread+0x1330/0x1330 [ 19.474145] ? __kthread_parkme+0xb3/0x200 [ 19.474145] ? rescuer_thread+0x1330/0x1330 [ 19.474145] kthread+0x30f/0x3f0 [ 19.474145] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 19.474145] ? kthread_affine_node+0x150/0x150 [ 19.474145] ret_from_fork+0x4a2/0x720 [ 19.474145] ? arch_exit_to_user_mode_prepare.isra.0+0xb0/0xb0 [ 19.474145] ? __switch_to+0x538/0xcf0 [ 19.474145] ? kthread_affine_node+0x150/0x150 [ 19.474145] ret_from_fork_asm+0x11/0x20 | [ 20.098127] ------------[ cut here ]------------ | [ 20.104376] UBSAN: array-index-out-of-bounds in drivers/net/ethernet/broadcom/bnxt/bnxt.c:9202:27 | [ 20.115128] index 12 is out of range for type 'bnxt_bs_trace_info [11]' | [ 20.123342] CPU: 0 UID: 0 PID: 253 Comm: kworker/0:2 Tainted: G B 7.0.0-rc3-anxy-gdc41423dc228 #1 PREEMPT(full) | [ 20.123345] Tainted: [B]=BAD_PAGE [ 20.123346] Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R30_F44 12/24/2025 [ 20.123347] Workqueue: sync_wq local_pci_probe_callback [ 20.123349] Call Trace: [ 20.123350] [ 20.123351] dump_stack_lvl+0x6f/0xa0 [ 20.123353] ubsan_epilogue+0x5/0x2b [ 20.123355] __ubsan_handle_out_of_bounds.cold+0x54/0x59 [ 20.123357] bnxt_hwrm_func_backing_store_cfg_v2+0xad0/0xb80 [ 20.123360] ? bnxt_request_irq+0x8c0/0x8c0 [ 20.123362] bnxt_backing_store_cfg_v2+0x4d7/0xa00 [ 20.123365] bnxt_alloc_ctx_mem+0x610/0x970 [ 20.123367] bnxt_hwrm_func_qcaps.part.0+0x62f/0xb20 [ 20.123370] ? __bnxt_hwrm_func_qcaps+0xe15/0x1c30 [ 20.123372] ? bnxt_hwrm_func_resc_qcaps+0x1040/0x1040 [ 20.123375] bnxt_fw_init_one_p2+0x89/0xda0 [ 20.123377] ? bnxt_hwrm_func_qcaps.part.0+0xb20/0xb20 [ 20.123379] ? trace_kmalloc+0x107/0x130 [ 20.123381] ? __kasan_kmalloc+0x7b/0x90 [ 20.123383] ? __kmalloc_noprof+0x30c/0x7e0 [ 20.123385] bnxt_init_one+0x55b/0x29b0 [ 20.123387] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 20.123390] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 20.123392] ? lockdep_hardirqs_on+0x84/0x130 [ 20.123394] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 20.123396] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 20.123397] ? bnxt_set_dflt_rings.constprop.0+0xdd0/0xdd0 [ 20.123400] local_pci_probe+0xcc/0x170 [ 20.123401] local_pci_probe_callback+0x35/0x80 [ 20.123403] ? process_one_work+0xd30/0x1390 [ 20.123404] process_one_work+0xd57/0x1390 [ 20.123407] ? pwq_dec_nr_in_flight+0x700/0x700 [ 20.123409] ? lock_acquire.part.0+0xbc/0x260 [ 20.123412] worker_thread+0x4d6/0xd40 [ 20.123414] ? rescuer_thread+0x1330/0x1330 [ 20.123416] ? __kthread_parkme+0xb3/0x200 [ 20.123417] ? rescuer_thread+0x1330/0x1330 [ 20.123419] kthread+0x30f/0x3f0 [ 20.123420] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 20.123422] ? kthread_affine_node+0x150/0x150 [ 20.123424] ret_from_fork+0x4a2/0x720 [ 20.123425] ? arch_exit_to_user_mode_prepare.isra.0+0xb0/0xb0 [ 20.123427] ? __switch_to+0x538/0xcf0 [ 20.123429] ? kthread_affine_node+0x150/0x150 [ 20.123430] ret_from_fork_asm+0x11/0x20 Finger prints: print_report:kasan_report:bnxt_backing_store_cfg_v2:bnxt_alloc_ctx_mem:bnxt_fw_init_one_p2 ubsan_epilogue:bnxt_hwrm_func_backing_store_cfg_v2:bnxt_backing_store_cfg_v2:bnxt_alloc_ctx_mem:bnxt_fw_init_one_p2 ubsan_epilogue:bnxt_backing_store_cfg_v2:bnxt_alloc_ctx_mem:bnxt_fw_init_one_p2:bnxt_init_one