[ 1186.279747][ C0] ------------[ cut here ]------------
[ 1186.280017][ C0] WARNING: ./include/linux/skbuff.h:3250 at erspan_rcv+0xf88/0x1170 [ip_gre], CPU#0: mausezahn/7896
[ 1186.280602][ C0] Modules linked in: cls_matchall ip_gre gre ip_tunnel act_skbedit sch_prio act_gact cls_flower sch_ingress bridge stp llc 8021q vrf veth
[ 1186.281130][ C0] CPU: 0 UID: 0 PID: 7896 Comm: mausezahn Not tainted 7.1.0-virtme #1 PREEMPT(full)
[ 1186.281377][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 1186.281594][ C0] RIP: 0010:erspan_rcv+0xf88/0x1170 [ip_gre]
[ 1186.281770][ C0] Code: 54 24 18 e9 1a fa ff ff 48 8b 7c 24 48 e8 a0 c6 a3 c2 e9 bd f9 ff ff 90 0f 0b 90 e9 3c f4 ff ff 90 0f 0b 90 e9 16 fb ff ff 90 <0f> 0b 90 e9 41 fa ff ff e8 3b c6 a3 c2 e9 19 f1 ff ff 48 8b 3c 24
[ 1186.282270][ C0] RSP: 0018:ffa0000000007820 EFLAGS: 00010246
[ 1186.282446][ C0] RAX: 000000000000ffff RBX: ffa0000000007948 RCX: 000000000000001e
[ 1186.282657][ C0] RDX: ff1100000c834040 RSI: 000000000000001e RDI: ff11000011b262b6
[ 1186.282860][ C0] RBP: 0000000000000008 R08: 0000000000000000 R09: 1fe220000186de99
[ 1186.283068][ C0] R10: ffe21c000186de9a R11: ffe21c000186de9a R12: ff11000002879e40
[ 1186.283278][ C0] R13: ff1100000c36f400 R14: ff1100000c36f4c8 R15: ff11000011b26200
[ 1186.283482][ C0] FS: 00007f662b875c80(0000) GS:ff110000ae59a000(0000) knlGS:0000000000000000
[ 1186.283720][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 1186.283893][ C0] CR2: 000055827769d680 CR3: 0000000008adb003 CR4: 0000000000771ef0
[ 1186.284106][ C0] PKRU: 55555554
[ 1186.284206][ C0] Call Trace:
[ 1186.284310][ C0]
[ 1186.284390][ C0] ? erspan_validate+0x6c0/0x6c0 [ip_gre]
[ 1186.284531][ C0] ? __lock_release.isra.0+0x6b/0x1a0
[ 1186.284667][ C0] ? mark_usage+0x61/0x170
[ 1186.284806][ C0] gre_rcv+0x25a/0x2e0 [ip_gre]
[ 1186.284943][ C0] ? __ipgre_rcv+0xa70/0xa70 [ip_gre]
[ 1186.285088][ C0] ? lock_acquire.part.0+0xbc/0x260
[ 1186.285221][ C0] ? gre_rcv+0x134/0x438 [gre]
[ 1186.285355][ C0] ? rcu_is_watching+0x15/0xd0
[ 1186.285494][ C0] ? raw_rcv+0x2a0/0x2a0
[ 1186.285598][ C0] ? lock_acquire+0x13c/0x160
[ 1186.285735][ C0] gre_rcv+0x1d1/0x438 [gre]
[ 1186.285872][ C0] ip_protocol_deliver_rcu+0x82/0x350
[ 1186.286008][ C0] ? process_backlog+0x561/0x1490
[ 1186.286151][ C0] ip_local_deliver_finish+0x36f/0x610
[ 1186.286290][ C0] ip_local_deliver+0x184/0x4c0
[ 1186.286428][ C0] ? ip_local_deliver_finish+0x610/0x610
[ 1186.286564][ C0] ? ip_rcv_finish_core+0x553/0x14c0
[ 1186.286702][ C0] ? process_backlog+0x561/0x1490
[ 1186.286838][ C0] ip_rcv+0xdc/0x3d0
[ 1186.286942][ C0] ? ip_local_deliver+0x4c0/0x4c0
[ 1186.287078][ C0] ? mark_usage+0x61/0x170
[ 1186.287222][ C0] ? __lock_acquire+0x518/0xc20
[ 1186.287359][ C0] __netif_receive_skb_one_core+0xfc/0x180
[ 1186.287532][ C0] ? lock_acquire.part.0+0xbc/0x260
[ 1186.287668][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 1186.287836][ C0] ? rcu_is_watching+0x15/0xd0
[ 1186.287973][ C0] process_backlog+0x2bc/0x1490
[ 1186.288119][ C0] __napi_poll+0xa7/0x3b0
[ 1186.288219][ C0] net_rx_action+0x513/0xf50
[ 1186.288356][ C0] ? __napi_poll+0x3b0/0x3b0
[ 1186.288496][ C0] ? find_held_lock+0x2b/0x80
[ 1186.288639][ C0] ? rcu_is_watching+0x15/0xd0
[ 1186.288776][ C0] handle_softirqs+0x1d8/0x8f0
[ 1186.288914][ C0] ? _local_bh_enable+0xd0/0xd0
[ 1186.289049][ C0] ? rcu_is_watching+0x15/0xd0
[ 1186.289195][ C0] ? trace_csd_function_exit+0xb3/0x180
[ 1186.289329][ C0] do_softirq+0xa9/0xe0
[ 1186.289431][ C0]
[ 1186.289500][ C0]
[ 1186.289567][ C0] ? __dev_queue_xmit+0x946/0x1b60
[ 1186.289703][ C0] __local_bh_enable_ip+0x113/0x140
[ 1186.289837][ C0] __dev_queue_xmit+0x95b/0x1b60
[ 1186.289974][ C0] ? _copy_from_iter+0x1bb/0x1810
[ 1186.290118][ C0] ? _copy_from_iter_flushcache+0x1970/0x1970
[ 1186.290284][ C0] ? alloc_cpu_rmap+0x70/0x2a0
[ 1186.290423][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 1186.290565][ C0] ? packet_release+0xc70/0xc70
[ 1186.290703][ C0] packet_snd+0xfad/0x1990
[ 1186.290844][ C0] ? tpacket_snd+0x19e0/0x19e0
[ 1186.290979][ C0] ? __might_fault+0x97/0x140
[ 1186.291126][ C0] ? __might_fault+0x97/0x140
[ 1186.291265][ C0] ? __might_fault+0x97/0x140
[ 1186.291404][ C0] __sys_sendto+0x2aa/0x3e0
[ 1186.291535][ C0] ? __ia32_sys_getpeername+0xd0/0xd0
[ 1186.291677][ C0] ? sock_ioctl+0x3cb/0x5f0
[ 1186.291817][ C0] ? exc_page_fault+0x87/0x100
[ 1186.291957][ C0] __x64_sys_sendto+0xe4/0x1f0
[ 1186.292095][ C0] ? trace_irq_enable.constprop.0+0x9b/0x160
[ 1186.292265][ C0] ? lockdep_hardirqs_on+0x8c/0x130
[ 1186.292402][ C0] ? do_syscall_64+0x82/0x590
[ 1186.292542][ C0] do_syscall_64+0x117/0x590
[ 1186.292679][ C0] ? trace_hardirqs_off+0xd/0x30
[ 1186.292815][ C0] ? exc_page_fault+0xee/0x100
[ 1186.292952][ C0] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 1186.293127][ C0] RIP: 0033:0x7f662ba3364e
[ 1186.293267][ C0] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa
[ 1186.293743][ C0] RSP: 002b:00007ffd5fe31c40 EFLAGS: 00000202 ORIG_RAX: 000000000000002c
[ 1186.293948][ C0] RAX: ffffffffffffffda RBX: 00005582b0777b22 RCX: 00007f662ba3364e
[ 1186.294158][ C0] RDX: 0000000000000062 RSI: 00005582b0777b22 RDI: 0000000000000005
[ 1186.294361][ C0] RBP: 00007ffd5fe31c50 R08: 00007ffd5fe31ca0 R09: 0000000000000014
[ 1186.294570][ C0] R10: 0000000000000000 R11: 0000000000000202 R12: 00005582b0777830
[ 1186.294773][ C0] R13: 0000000000000062 R14: 0000000000000005 R15: 00005582b0777830
[ 1186.294983][ C0]
[ 1186.295090][ C0] irq event stamp: 14966
[ 1186.295190][ C0] hardirqs last enabled at (14974): [] __up_console_sem+0x5a/0x70
[ 1186.295425][ C0] hardirqs last disabled at (14981): [] __up_console_sem+0x3f/0x70
[ 1186.295662][ C0] softirqs last enabled at (14040): [] __dev_queue_xmit+0x946/0x1b60
[ 1186.295899][ C0] softirqs last disabled at (14041): [] do_softirq+0xa9/0xe0
[ 1186.296146][ C0] ---[ end trace 0000000000000000 ]---
[ 1186.498864][ C1] ==================================================================
[ 1186.499041][ C1] BUG: KASAN: slab-out-of-bounds in erspan_rcv+0xa32/0x1170 [ip_gre]
[ 1186.499188][ C1] Read of size 8 at addr ff11000008f043cb by task kworker/u16:1/69
[ 1186.499319][ C1]
[ 1186.499375][ C1] CPU: 1 UID: 0 PID: 69 Comm: kworker/u16:1 Tainted: G W 7.1.0-virtme #1 PREEMPT(full)
[ 1186.499379][ C1] Tainted: [W]=WARN
[ 1186.499380][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 1186.499381][ C1] Workqueue: ipv6_addrconf addrconf_dad_work
[ 1186.499389][ C1] Call Trace:
[ 1186.499391][ C1]
[ 1186.499393][ C1] dump_stack_lvl+0x6f/0xa0
[ 1186.499398][ C1] print_address_description.constprop.0+0x56/0x2d0
[ 1186.499404][ C1] print_report+0xfc/0x1fa
[ 1186.499406][ C1] ? __virt_addr_valid+0x102/0x440
[ 1186.499410][ C1] ? __virt_addr_valid+0x1da/0x440
[ 1186.499412][ C1] kasan_report+0x108/0x130
[ 1186.499416][ C1] ? erspan_rcv+0xa32/0x1170 [ip_gre]
[ 1186.499418][ C1] ? erspan_rcv+0xa32/0x1170 [ip_gre]
[ 1186.499420][ C1] kasan_check_range+0x130/0x200
[ 1186.499425][ C1] __asan_memcpy+0x23/0x60
[ 1186.499427][ C1] erspan_rcv+0xa32/0x1170 [ip_gre]
[ 1186.499430][ C1] ? erspan_validate+0x6c0/0x6c0 [ip_gre]
[ 1186.499432][ C1] ? __lock_release.isra.0+0x6b/0x1a0
[ 1186.499435][ C1] ? mark_usage+0x61/0x170
[ 1186.499437][ C1] gre_rcv+0x25a/0x2e0 [ip_gre]
[ 1186.499439][ C1] ? __ipgre_rcv+0xa70/0xa70 [ip_gre]
[ 1186.499441][ C1] ? lock_acquire.part.0+0xbc/0x260
[ 1186.499443][ C1] ? gre_rcv+0x134/0x438 [gre]
[ 1186.499445][ C1] ? rcu_is_watching+0x15/0xd0
[ 1186.499448][ C1] ? raw_rcv+0x2a0/0x2a0
[ 1186.499452][ C1] ? lock_acquire+0x13c/0x160
[ 1186.499454][ C1] gre_rcv+0x1d1/0x438 [gre]
[ 1186.499455][ C1] ip_protocol_deliver_rcu+0x82/0x350
[ 1186.499458][ C1] ? process_backlog+0x561/0x1490
[ 1186.499462][ C1] ip_local_deliver_finish+0x36f/0x610
[ 1186.499464][ C1] ip_local_deliver+0x184/0x4c0
[ 1186.499465][ C1] ? ip_local_deliver_finish+0x610/0x610
[ 1186.499467][ C1] ? ip_rcv_finish_core+0x6ed/0x14c0
[ 1186.499470][ C1] ? process_backlog+0x561/0x1490
[ 1186.499471][ C1] ip_rcv+0xdc/0x3d0
[ 1186.499473][ C1] ? ip_local_deliver+0x4c0/0x4c0
[ 1186.499475][ C1] ? mark_usage+0x61/0x170
[ 1186.499477][ C1] ? __lock_acquire+0x518/0xc20
[ 1186.499479][ C1] __netif_receive_skb_one_core+0xfc/0x180
[ 1186.499481][ C1] ? lock_acquire.part.0+0xbc/0x260
[ 1186.499482][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0
[ 1186.499484][ C1] ? rcu_is_watching+0x15/0xd0
[ 1186.499487][ C1] process_backlog+0x2bc/0x1490
[ 1186.499489][ C1] __napi_poll+0xa7/0x3b0
[ 1186.499491][ C1] net_rx_action+0x513/0xf50
[ 1186.499494][ C1] ? __napi_poll+0x3b0/0x3b0
[ 1186.499495][ C1] ? validate_chain+0x38b/0xc20
[ 1186.499499][ C1] ? __rwlock_init+0x150/0x150
[ 1186.499501][ C1] ? mark_held_locks+0x40/0x70
[ 1186.499503][ C1] handle_softirqs+0x1d8/0x8f0
[ 1186.499506][ C1] ? _local_bh_enable+0xd0/0xd0
[ 1186.499507][ C1] ? do_raw_spin_unlock+0x59/0x250
[ 1186.499509][ C1] ? _raw_spin_unlock+0x2d/0x50
[ 1186.499512][ C1] do_softirq+0xa9/0xe0
[ 1186.499514][ C1]
[ 1186.499514][ C1]
[ 1186.499515][ C1] ? __dev_queue_xmit+0x946/0x1b60
[ 1186.499516][ C1] __local_bh_enable_ip+0x113/0x140
[ 1186.499518][ C1] __dev_queue_xmit+0x95b/0x1b60
[ 1186.499520][ C1] ? __lock_acquire+0x518/0xc20
[ 1186.499522][ C1] ? find_held_lock+0x2b/0x80
[ 1186.499524][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0
[ 1186.499528][ C1] ip6_finish_output2+0x423/0x1300
[ 1186.499530][ C1] ? ip6_xmit+0x2000/0x2000
[ 1186.499531][ C1] ? lock_acquire.part.0+0xbc/0x260
[ 1186.499533][ C1] ? find_held_lock+0x2b/0x80
[ 1186.499534][ C1] ? __lock_release.isra.0+0x6b/0x1a0
[ 1186.499536][ C1] ? ip6_mtu+0x15d/0x310
[ 1186.499538][ C1] ip6_finish_output+0x646/0xda0
[ 1186.499540][ C1] ip6_output+0x23f/0x7f0
[ 1186.499542][ C1] ? ip6_finish_output+0xda0/0xda0
[ 1186.499543][ C1] ? lock_acquire.part.0+0xbc/0x260
[ 1186.499544][ C1] ? find_held_lock+0x2b/0x80
[ 1186.499546][ C1] ? __lock_release.isra.0+0x6b/0x1a0
[ 1186.499547][ C1] ? __local_bh_enable_ip+0xa5/0x140
[ 1186.499550][ C1] ndisc_send_skb+0xba3/0x1520
[ 1186.499553][ C1] ? ndisc_recv_na+0xea0/0xea0
[ 1186.499556][ C1] ? trace_hardirqs_off+0xd/0x30
[ 1186.499558][ C1] ? try_to_grab_pending+0x77/0x840
[ 1186.499561][ C1] ? mark_held_locks+0x40/0x70
[ 1186.499563][ C1] ndisc_send_ns+0xa9/0x120
[ 1186.499565][ C1] ? find_held_lock+0x2b/0x80
[ 1186.499566][ C1] ? ndisc_parse_options+0x30/0x30
[ 1186.499568][ C1] ? __rwlock_init+0x150/0x150
[ 1186.499570][ C1] ? mark_held_locks+0x40/0x70
[ 1186.499571][ C1] ? lockdep_hardirqs_on+0x8c/0x130
[ 1186.499574][ C1] addrconf_dad_work+0x6c2/0x930
[ 1186.499576][ C1] ? addrconf_dad_begin+0x540/0x540
[ 1186.499578][ C1] ? process_one_work+0xdb7/0x1410
[ 1186.499580][ C1] ? rcu_is_watching+0x15/0xd0
[ 1186.499581][ C1] ? rcu_is_watching+0x15/0xd0
[ 1186.499583][ C1] ? lock_acquire+0x13c/0x160
[ 1186.499584][ C1] ? rcu_is_watching+0x15/0xd0
[ 1186.499587][ C1] process_one_work+0xdf8/0x1410
[ 1186.499590][ C1] ? pwq_dec_nr_in_flight+0x710/0x710
[ 1186.499592][ C1] ? lock_acquire.part.0+0xbc/0x260
[ 1186.499595][ C1] worker_thread+0x4f1/0xd60
[ 1186.499597][ C1] ? rescuer_thread+0x1320/0x1320
[ 1186.499599][ C1] ? __kthread_parkme+0xbd/0x210
[ 1186.499601][ C1] ? rescuer_thread+0x1320/0x1320
[ 1186.499603][ C1] kthread+0x367/0x460
[ 1186.499604][ C1] ? trace_irq_enable.constprop.0+0x9b/0x160
[ 1186.499607][ C1] ? kthread_affine_node+0x330/0x330
[ 1186.499609][ C1] ret_from_fork+0x474/0x6b0
[ 1186.499612][ C1] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120
[ 1186.499614][ C1] ? __switch_to+0x5a3/0xe00
[ 1186.499617][ C1] ? kthread_affine_node+0x330/0x330
[ 1186.499619][ C1] ret_from_fork_asm+0x11/0x20
[ 1186.499622][ C1]
[ 1186.499623][ C1]
[ 1186.508546][ C1] Allocated by task 1:
[ 1186.508611][ C1] kasan_save_stack+0x2f/0x50
[ 1186.508699][ C1] kasan_save_track+0x14/0x30
[ 1186.508785][ C1] __kasan_krealloc+0x168/0x180
[ 1186.508866][ C1] krealloc_node_align_noprof+0x194/0x3b0
[ 1186.508950][ C1] add_sysfs_param+0x171/0xa60
[ 1186.509032][ C1] param_sysfs_builtin_init+0x215/0x2c0
[ 1186.509121][ C1] do_one_initcall+0x12b/0x4f0
[ 1186.509208][ C1] kernel_init_freeable+0x596/0x630
[ 1186.509291][ C1] kernel_init+0x1e/0x170
[ 1186.509353][ C1] ret_from_fork+0x474/0x6b0
[ 1186.509442][ C1] ret_from_fork_asm+0x11/0x20
[ 1186.509524][ C1]
[ 1186.509566][ C1] The buggy address belongs to the object at ff11000008f04340
[ 1186.509566][ C1] which belongs to the cache kmalloc-64 of size 64
[ 1186.509771][ C1] The buggy address is located 91 bytes to the right of
[ 1186.509771][ C1] allocated 48-byte region [ff11000008f04340, ff11000008f04370)
[ 1186.509995][ C1]
[ 1186.510037][ C1] The buggy address belongs to the physical page:
[ 1186.510142][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x8f04
[ 1186.510295][ C1] flags: 0x80000000000000(node=0|zone=1)
[ 1186.510388][ C1] page_type: f5(slab)
[ 1186.510454][ C1] raw: 0080000000000000 ff1100000103cac0 ffd4000000082f10 ffd4000000123710
[ 1186.510602][ C1] raw: 0000000000000000 0000000000100010 00000000f5000000 0000000000000000
[ 1186.510748][ C1] page dumped because: kasan: bad access detected
[ 1186.510855][ C1]
[ 1186.510899][ C1] Memory state around the buggy address:
[ 1186.510985][ C1] ff11000008f04280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1186.511110][ C1] ff11000008f04300: fc fc fc fc fc fc fc fc 00 00 00 00 00 00 fc fc
[ 1186.511235][ C1] >ff11000008f04380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1186.511359][ C1] ^
[ 1186.511472][ C1] ff11000008f04400: fc fc fc fc fc fc fc fc 00 00 00 00 00 00 00 00
[ 1186.511592][ C1] ff11000008f04480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 1186.511712][ C1] ==================================================================
[ 1186.511846][ C1] Disabling lock debugging due to kernel taint