[ 708.817591][ T2802] gre: GRE over IPv4 demultiplexer driver [ 708.831409][ T2802] ip_gre: GRE over IPv4 tunneling driver [ 709.330629][ C0] ------------[ cut here ]------------ [ 709.331291][ C0] WARNING: ./include/linux/skbuff.h:3250 at erspan_rcv+0xf88/0x1170 [ip_gre], CPU#0: kworker/u16:0/12 [ 709.331668][ C0] Modules linked in: ip_gre gre ip_tunnel cls_matchall dummy cls_u32 8021q vxlan ip6_udp_tunnel udp_tunnel bridge stp llc act_gact cls_flower sch_ingress vrf veth [ 709.332364][ C0] CPU: 0 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 7.1.0-virtme #1 PREEMPT(full) [ 709.332637][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 709.332886][ C0] Workqueue: ipv6_addrconf addrconf_dad_work [ 709.333082][ C0] RIP: 0010:erspan_rcv+0xf88/0x1170 [ip_gre] [ 709.333276][ C0] Code: 54 24 18 e9 1a fa ff ff 48 8b 7c 24 48 e8 a0 96 1d d3 e9 bd f9 ff ff 90 0f 0b 90 e9 3c f4 ff ff 90 0f 0b 90 e9 16 fb ff ff 90 <0f> 0b 90 e9 41 fa ff ff e8 3b 96 1d d3 e9 19 f1 ff ff 48 8b 3c 24 [ 709.333808][ C0] RSP: 0018:ffa0000000007820 EFLAGS: 00010246 [ 709.334000][ C0] RAX: 000000000000ffff RBX: ffa0000000007948 RCX: 000000000000001a [ 709.334233][ C0] RDX: ff11000014b4a340 RSI: 000000000000001a RDI: ff110000157cf5f6 [ 709.334457][ C0] RBP: 0000000000000008 R08: 0000000000000000 R09: 1fe2200001837b99 [ 709.334673][ C0] R10: ffe21c0001837b9a R11: ffe21c0001837b9a R12: ff11000011e91e40 [ 709.334896][ C0] R13: ff1100000c1bdc00 R14: ff1100000c1bdcc8 R15: ff110000157cf540 [ 709.335115][ C0] FS: 0000000000000000(0000) GS:ff1100009739a000(0000) knlGS:0000000000000000 [ 709.335373][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 709.335564][ C0] CR2: 000055de77d2dd5c CR3: 0000000011c1a004 CR4: 0000000000771ef0 [ 709.335787][ C0] PKRU: 55555554 [ 709.335906][ C0] Call Trace: [ 709.336017][ C0] [ 709.336096][ C0] ? erspan_validate+0x6c0/0x6c0 [ip_gre] [ 709.336245][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.336398][ C0] ? mark_usage+0x61/0x170 [ 709.336546][ C0] gre_rcv+0x25a/0x2e0 [ip_gre] [ 709.336690][ C0] ? __ipgre_rcv+0xa70/0xa70 [ip_gre] [ 709.336848][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.337001][ C0] ? gre_rcv+0x134/0x438 [gre] [ 709.337149][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.337318][ C0] ? raw_rcv+0x2a0/0x2a0 [ 709.337472][ C0] ? lock_acquire+0x13c/0x160 [ 709.337689][ C0] gre_rcv+0x1d1/0x438 [gre] [ 709.337925][ C0] ip_protocol_deliver_rcu+0x82/0x350 [ 709.338151][ C0] ? process_backlog+0x561/0x1490 [ 709.338383][ C0] ip_local_deliver_finish+0x36f/0x610 [ 709.338631][ C0] ip_local_deliver+0x184/0x4c0 [ 709.338876][ C0] ? ip_local_deliver_finish+0x610/0x610 [ 709.339132][ C0] ? ip_rcv_finish_core+0x553/0x14c0 [ 709.339382][ C0] ? process_backlog+0x561/0x1490 [ 709.339629][ C0] ip_rcv+0xdc/0x3d0 [ 709.339812][ C0] ? ip_local_deliver+0x4c0/0x4c0 [ 709.340065][ C0] ? mark_usage+0x61/0x170 [ 709.340294][ C0] ? __lock_acquire+0x518/0xc20 [ 709.340541][ C0] __netif_receive_skb_one_core+0xfc/0x180 [ 709.340833][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.341082][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 709.341375][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.341630][ C0] process_backlog+0x2bc/0x1490 [ 709.341871][ C0] __napi_poll+0xa7/0x3b0 [ 709.342062][ C0] net_rx_action+0x513/0xf50 [ 709.342306][ C0] ? __napi_poll+0x3b0/0x3b0 [ 709.342557][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.342790][ C0] ? __rwlock_init+0x150/0x150 [ 709.343044][ C0] ? clockevents_program_event+0x307/0x7e0 [ 709.343345][ C0] ? __run_timers+0xaa0/0xaa0 [ 709.343591][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.343836][ C0] ? mark_held_locks+0x40/0x70 [ 709.344085][ C0] handle_softirqs+0x1d8/0x8f0 [ 709.344331][ C0] ? _local_bh_enable+0xd0/0xd0 [ 709.344589][ C0] do_softirq+0xa9/0xe0 [ 709.344771][ C0] [ 709.344904][ C0] [ 709.345026][ C0] ? __dev_queue_xmit+0x946/0x1b60 [ 709.345267][ C0] __local_bh_enable_ip+0x113/0x140 [ 709.345509][ C0] __dev_queue_xmit+0x95b/0x1b60 [ 709.345750][ C0] ? __lock_acquire+0x518/0xc20 [ 709.346005][ C0] ? find_held_lock+0x2b/0x80 [ 709.346243][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 709.346505][ C0] ip6_finish_output2+0x423/0x1300 [ 709.346753][ C0] ? ip6_xmit+0x2000/0x2000 [ 709.346998][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.347235][ C0] ? find_held_lock+0x2b/0x80 [ 709.347479][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.347717][ C0] ? ip6_mtu+0x15d/0x310 [ 709.347913][ C0] ip6_finish_output+0x646/0xda0 [ 709.348150][ C0] ip6_output+0x23f/0x7f0 [ 709.348331][ C0] ? ip6_finish_output+0xda0/0xda0 [ 709.348573][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.348815][ C0] ? find_held_lock+0x2b/0x80 [ 709.349075][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.349312][ C0] ? __local_bh_enable_ip+0xa5/0x140 [ 709.349560][ C0] ndisc_send_skb+0xba3/0x1520 [ 709.349807][ C0] ? ndisc_recv_na+0xea0/0xea0 [ 709.350065][ C0] ? trace_hardirqs_off+0xd/0x30 [ 709.350303][ C0] ? try_to_grab_pending+0x77/0x840 [ 709.350547][ C0] ? mark_held_locks+0x40/0x70 [ 709.350795][ C0] ndisc_send_ns+0xa9/0x120 [ 709.351044][ C0] ? find_held_lock+0x2b/0x80 [ 709.351282][ C0] ? ndisc_parse_options+0x30/0x30 [ 709.351531][ C0] ? __rwlock_init+0x150/0x150 [ 709.351773][ C0] ? mark_held_locks+0x40/0x70 [ 709.352020][ C0] ? lockdep_hardirqs_on+0x8c/0x130 [ 709.352263][ C0] addrconf_dad_work+0x6c2/0x930 [ 709.352515][ C0] ? addrconf_dad_begin+0x540/0x540 [ 709.352753][ C0] ? process_one_work+0xdb7/0x1410 [ 709.353006][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.353249][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.353491][ C0] ? lock_acquire+0x13c/0x160 [ 709.353730][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.353990][ C0] process_one_work+0xdf8/0x1410 [ 709.354235][ C0] ? pwq_dec_nr_in_flight+0x710/0x710 [ 709.354477][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.354726][ C0] worker_thread+0x4f1/0xd60 [ 709.354990][ C0] ? rescuer_thread+0x1320/0x1320 [ 709.355227][ C0] kthread+0x367/0x460 [ 709.355409][ C0] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 709.355715][ C0] ? kthread_affine_node+0x330/0x330 [ 709.355966][ C0] ret_from_fork+0x474/0x6b0 [ 709.356214][ C0] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 709.356527][ C0] ? __switch_to+0x5a3/0xe00 [ 709.356772][ C0] ? kthread_affine_node+0x330/0x330 [ 709.357034][ C0] ret_from_fork_asm+0x11/0x20 [ 709.357297][ C0] [ 709.357494][ C0] irq event stamp: 62042 [ 709.357678][ C0] hardirqs last enabled at (62050): [] __up_console_sem+0x5a/0x70 [ 709.358108][ C0] hardirqs last disabled at (62059): [] __up_console_sem+0x3f/0x70 [ 709.358545][ C0] softirqs last enabled at (60900): [] __dev_queue_xmit+0x946/0x1b60 [ 709.358991][ C0] softirqs last disabled at (60901): [] do_softirq+0xa9/0xe0 [ 709.359426][ C0] ---[ end trace 0000000000000000 ]--- [ 709.359677][ C0] ================================================================== [ 709.359901][ C0] BUG: KASAN: use-after-free in erspan_rcv+0xa32/0x1170 [ip_gre] [ 709.360123][ C0] Read of size 8 at addr ff11000014b5a34b by task kworker/u16:0/12 [ 709.360344][ C0] [ 709.360428][ C0] CPU: 0 UID: 0 PID: 12 Comm: kworker/u16:0 Tainted: G W 7.1.0-virtme #1 PREEMPT(full) [ 709.360432][ C0] Tainted: [W]=WARN [ 709.360433][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 709.360435][ C0] Workqueue: ipv6_addrconf addrconf_dad_work [ 709.360440][ C0] Call Trace: [ 709.360441][ C0] [ 709.360443][ C0] dump_stack_lvl+0x6f/0xa0 [ 709.360447][ C0] print_address_description.constprop.0+0x56/0x2d0 [ 709.360454][ C0] print_report+0xfc/0x1fa [ 709.360457][ C0] ? __virt_addr_valid+0x102/0x440 [ 709.360461][ C0] ? __virt_addr_valid+0x1da/0x440 [ 709.360465][ C0] kasan_report+0x108/0x130 [ 709.360469][ C0] ? erspan_rcv+0xa32/0x1170 [ip_gre] [ 709.360473][ C0] ? erspan_rcv+0xa32/0x1170 [ip_gre] [ 709.360478][ C0] kasan_check_range+0x130/0x200 [ 709.360481][ C0] __asan_memcpy+0x23/0x60 [ 709.360485][ C0] erspan_rcv+0xa32/0x1170 [ip_gre] [ 709.360490][ C0] ? erspan_validate+0x6c0/0x6c0 [ip_gre] [ 709.360493][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.360496][ C0] ? mark_usage+0x61/0x170 [ 709.360499][ C0] gre_rcv+0x25a/0x2e0 [ip_gre] [ 709.360503][ C0] ? __ipgre_rcv+0xa70/0xa70 [ip_gre] [ 709.360506][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.360509][ C0] ? gre_rcv+0x134/0x438 [gre] [ 709.360512][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.360514][ C0] ? raw_rcv+0x2a0/0x2a0 [ 709.360518][ C0] ? lock_acquire+0x13c/0x160 [ 709.360522][ C0] gre_rcv+0x1d1/0x438 [gre] [ 709.360525][ C0] ip_protocol_deliver_rcu+0x82/0x350 [ 709.360528][ C0] ? process_backlog+0x561/0x1490 [ 709.360531][ C0] ip_local_deliver_finish+0x36f/0x610 [ 709.360534][ C0] ip_local_deliver+0x184/0x4c0 [ 709.360537][ C0] ? ip_local_deliver_finish+0x610/0x610 [ 709.360540][ C0] ? ip_rcv_finish_core+0x553/0x14c0 [ 709.360545][ C0] ? process_backlog+0x561/0x1490 [ 709.360547][ C0] ip_rcv+0xdc/0x3d0 [ 709.360550][ C0] ? ip_local_deliver+0x4c0/0x4c0 [ 709.360553][ C0] ? mark_usage+0x61/0x170 [ 709.360556][ C0] ? __lock_acquire+0x518/0xc20 [ 709.360560][ C0] __netif_receive_skb_one_core+0xfc/0x180 [ 709.360563][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.360565][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 709.360568][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.360573][ C0] process_backlog+0x2bc/0x1490 [ 709.360577][ C0] __napi_poll+0xa7/0x3b0 [ 709.360580][ C0] net_rx_action+0x513/0xf50 [ 709.360585][ C0] ? __napi_poll+0x3b0/0x3b0 [ 709.360589][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.360591][ C0] ? __rwlock_init+0x150/0x150 [ 709.360596][ C0] ? clockevents_program_event+0x307/0x7e0 [ 709.360599][ C0] ? __run_timers+0xaa0/0xaa0 [ 709.360603][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.360606][ C0] ? mark_held_locks+0x40/0x70 [ 709.360609][ C0] handle_softirqs+0x1d8/0x8f0 [ 709.360613][ C0] ? _local_bh_enable+0xd0/0xd0 [ 709.360617][ C0] do_softirq+0xa9/0xe0 [ 709.360619][ C0] [ 709.360620][ C0] [ 709.360621][ C0] ? __dev_queue_xmit+0x946/0x1b60 [ 709.360623][ C0] __local_bh_enable_ip+0x113/0x140 [ 709.360626][ C0] __dev_queue_xmit+0x95b/0x1b60 [ 709.360629][ C0] ? __lock_acquire+0x518/0xc20 [ 709.360633][ C0] ? find_held_lock+0x2b/0x80 [ 709.360636][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 709.360643][ C0] ip6_finish_output2+0x423/0x1300 [ 709.360647][ C0] ? ip6_xmit+0x2000/0x2000 [ 709.360649][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.360651][ C0] ? find_held_lock+0x2b/0x80 [ 709.360654][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.360657][ C0] ? ip6_mtu+0x15d/0x310 [ 709.360660][ C0] ip6_finish_output+0x646/0xda0 [ 709.360664][ C0] ip6_output+0x23f/0x7f0 [ 709.360666][ C0] ? ip6_finish_output+0xda0/0xda0 [ 709.360669][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.360671][ C0] ? find_held_lock+0x2b/0x80 [ 709.360674][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 709.360677][ C0] ? __local_bh_enable_ip+0xa5/0x140 [ 709.360681][ C0] ndisc_send_skb+0xba3/0x1520 [ 709.360685][ C0] ? ndisc_recv_na+0xea0/0xea0 [ 709.360690][ C0] ? trace_hardirqs_off+0xd/0x30 [ 709.360692][ C0] ? try_to_grab_pending+0x77/0x840 [ 709.360695][ C0] ? mark_held_locks+0x40/0x70 [ 709.360698][ C0] ndisc_send_ns+0xa9/0x120 [ 709.360701][ C0] ? find_held_lock+0x2b/0x80 [ 709.360703][ C0] ? ndisc_parse_options+0x30/0x30 [ 709.360706][ C0] ? __rwlock_init+0x150/0x150 [ 709.360709][ C0] ? mark_held_locks+0x40/0x70 [ 709.360712][ C0] ? lockdep_hardirqs_on+0x8c/0x130 [ 709.360715][ C0] addrconf_dad_work+0x6c2/0x930 [ 709.360719][ C0] ? addrconf_dad_begin+0x540/0x540 [ 709.360721][ C0] ? process_one_work+0xdb7/0x1410 [ 709.360724][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.360727][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.360729][ C0] ? lock_acquire+0x13c/0x160 [ 709.360732][ C0] ? rcu_is_watching+0x15/0xd0 [ 709.360736][ C0] process_one_work+0xdf8/0x1410 [ 709.360741][ C0] ? pwq_dec_nr_in_flight+0x710/0x710 [ 709.360744][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 709.360749][ C0] worker_thread+0x4f1/0xd60 [ 709.360754][ C0] ? rescuer_thread+0x1320/0x1320 [ 709.360757][ C0] kthread+0x367/0x460 [ 709.360760][ C0] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 709.360763][ C0] ? kthread_affine_node+0x330/0x330 [ 709.360766][ C0] ret_from_fork+0x474/0x6b0 [ 709.360770][ C0] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 709.360773][ C0] ? __switch_to+0x5a3/0xe00 [ 709.360776][ C0] ? kthread_affine_node+0x330/0x330 [ 709.360779][ C0] ret_from_fork_asm+0x11/0x20 [ 709.360786][ C0] [ 709.360787][ C0] [ 709.373495][ C0] The buggy address belongs to the physical page: [ 709.373618][ C0] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000000000000 pfn:0x14b5a [ 709.373992][ C0] flags: 0x80000000000000(node=0|zone=1) [ 709.374141][ C0] raw: 0080000000000000 dead000000000100 dead000000000122 0000000000000000 [ 709.374318][ C0] raw: ff11000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 709.374554][ C0] page dumped because: kasan: bad access detected [ 709.374679][ C0] [ 709.374731][ C0] Memory state around the buggy address: [ 709.374880][ C0] ff11000014b5a200: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 709.375022][ C0] ff11000014b5a280: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 709.375164][ C0] >ff11000014b5a300: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 709.375360][ C0] ^ [ 709.375485][ C0] ff11000014b5a380: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 709.375625][ C0] ff11000014b5a400: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 709.375825][ C0] ================================================================== [ 709.375981][ C0] Disabling lock debugging due to kernel taint