====================================== | [ 1236.368267][ T12] vethhv-21: left promiscuous mode | [ 1236.368459][ T12] br2: port 1(vethhv-21) entered disabled state | [ 1236.372926][T14877] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006: 0000 [#1] SMP KASAN | [ 1236.373108][T14877] KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037] [ 1236.373372][T14877] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 1236.373462][T14877] Workqueue: mld mld_ifc_work [ 1236.373543][T14877] RIP: 0010:mroute6_is_socket (net/ipv6/ip6mr.c:1686 (discriminator 4)) [ 1236.373619][T14877] Code: df 48 89 f9 48 c1 e9 03 80 3c 11 00 75 2f 48 8b 80 e8 10 00 00 48 ba 00 00 00 00 00 fc ff df 48 8d 78 30 48 89 f9 48 c1 e9 03 <80> 3c 11 00 75 1c 48 83 78 30 00 0f 95 c0 48 83 c4 08 c3 48 89 04 All code ======== 0: df 48 89 fisttps -0x77(%rax) 3: f9 stc 4: 48 c1 e9 03 shr $0x3,%rcx 8: 80 3c 11 00 cmpb $0x0,(%rcx,%rdx,1) c: 75 2f jne 0x3d e: 48 8b 80 e8 10 00 00 mov 0x10e8(%rax),%rax 15: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx 1c: fc ff df 1f: 48 8d 78 30 lea 0x30(%rax),%rdi 23: 48 89 f9 mov %rdi,%rcx 26: 48 c1 e9 03 shr $0x3,%rcx 2a:* 80 3c 11 00 cmpb $0x0,(%rcx,%rdx,1) <-- trapping instruction 2e: 75 1c jne 0x4c 30: 48 83 78 30 00 cmpq $0x0,0x30(%rax) 35: 0f 95 c0 setne %al 38: 48 83 c4 08 add $0x8,%rsp 3c: c3 ret 3d: 48 rex.W 3e: 89 .byte 0x89 3f: 04 .byte 0x4 Code starting with the faulting instruction =========================================== 0: 80 3c 11 00 cmpb $0x0,(%rcx,%rdx,1) 4: 75 1c jne 0x22 6: 48 83 78 30 00 cmpq $0x0,0x30(%rax) b: 0f 95 c0 setne %al e: 48 83 c4 08 add $0x8,%rsp 12: c3 ret 13: 48 rex.W 14: 89 .byte 0x89 15: 04 .byte 0x4 [ 1236.373884][T14877] RSP: 0018:ffa0000001eaf8b0 EFLAGS: 00010216 [ 1236.373976][T14877] RAX: 0000000000000000 RBX: ff11000025399000 RCX: 0000000000000006 [ 1236.374084][T14877] RDX: dffffc0000000000 RSI: ff11000025399000 RDI: 0000000000000030 [ 1236.374195][T14877] RBP: ff110000164c43c0 R08: ffffffffa95b8550 R09: 1fe22000025e73e5 [ 1236.374303][T14877] R10: ff1100001c37a028 R11: ff11000014e240b0 R12: 1ff40000003d5f20 [ 1236.374415][T14877] R13: ff11000014e24000 R14: ff110000247ee800 R15: ff1100001c37a010 [ 1236.374528][T14877] FS: 0000000000000000(0000) GS:ff110000bfae4000(0000) knlGS:0000000000000000 [ 1236.374658][T14877] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1236.374754][T14877] CR2: 00007fdfec072888 CR3: 0000000020b4f004 CR4: 0000000000771ef0 [ 1236.374863][T14877] PKRU: 55555554 [ 1236.374923][T14877] Call Trace: [ 1236.375015][T14877] [ 1236.375054][T14877] ip6_finish_output2 (net/ipv6/ip6_output.c:84 (discriminator 3)) [ 1236.375129][T14877] ? ip6_xmit (net/ipv6/ip6_output.c:61) [ 1236.375200][T14877] ? find_held_lock (kernel/locking/lockdep.c:5350 (discriminator 1)) [ 1236.375272][T14877] ? __lock_release.isra.0 (kernel/locking/lockdep.c:5536) [ 1236.375381][T14877] ? ip6_mtu (./include/linux/rcupdate.h:322 (discriminator 2) ./include/linux/rcupdate.h:881 (discriminator 2) ./include/net/ip6_route.h:382 (discriminator 2) net/ipv6/route.c:3281 (discriminator 2)) [ 1236.375435][T14877] ip6_finish_output (net/ipv6/ip6_output.c:208 net/ipv6/ip6_output.c:219) [ 1236.375511][T14877] ip6_output (./include/linux/netfilter.h:307 net/ipv6/ip6_output.c:246) [ 1236.375564][T14877] ? ip6_finish_output (net/ipv6/ip6_output.c:227) [ 1236.375666][T14877] ? __lock_release.isra.0 (kernel/locking/lockdep.c:5536) [ 1236.375744][T14877] ? xfrm_bundle_lookup.constprop.0 (net/xfrm/xfrm_policy.c:3177) [ 1236.375834][T14877] ? mark_held_locks (kernel/locking/lockdep.c:4325 (discriminator 1)) [ 1236.375904][T14877] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/softirq.c:455) [ 1236.376009][T14877] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/softirq.c:455) [ 1236.376079][T14877] ? icmp6_dst_alloc (net/ipv6/route.c:3357 (discriminator 1)) [ 1236.376150][T14877] mld_sendpack (./include/linux/netfilter.h:319 ./include/linux/netfilter.h:312 net/ipv6/mcast.c:1855) [ 1236.376221][T14877] ? nf_hook.constprop.0 (net/ipv4/ip_forward.c:66) [ 1236.376326][T14877] ? mld_send_cr (net/ipv6/mcast.c:2131 (discriminator 14)) [ 1236.376403][T14877] mld_ifc_work (net/ipv6/mcast.c:2695) [ 1236.376474][T14877] ? process_one_work (kernel/workqueue.c:3252 (discriminator 2)) [ 1236.376546][T14877] process_one_work (kernel/workqueue.c:3281) [ 1236.376652][T14877] ? pwq_dec_nr_in_flight (kernel/workqueue.c:3177) [ 1236.376728][T14877] ? lock_acquire.part.0 (kernel/locking/lockdep.c:470 (discriminator 2) kernel/locking/lockdep.c:5870 (discriminator 2)) [ 1236.376800][T14877] worker_thread (kernel/workqueue.c:3353 (discriminator 5) kernel/workqueue.c:3440 (discriminator 5)) [ 1236.376873][T14877] ? rescuer_thread (kernel/workqueue.c:3386) [ 1236.376980][T14877] ? __kthread_parkme (./arch/x86/include/asm/bitops.h:202 (discriminator 1) ./arch/x86/include/asm/bitops.h:232 (discriminator 1) ./include/asm-generic/bitops/instrumented-non-atomic.h:142 (discriminator 1) kernel/kthread.c:272 (discriminator 1)) [ 1236.377052][T14877] ? rescuer_thread (kernel/workqueue.c:3386) [ 1236.377123][T14877] kthread (kernel/kthread.c:436) [ 1236.377178][T14877] ? trace_irq_enable.constprop.0 (./include/trace/events/preemptirq.h:40 (discriminator 24)) [ 1236.377300][T14877] ? kthread_affine_node (kernel/kthread.c:381) [ 1236.377377][T14877] ret_from_fork (arch/x86/kernel/process.c:164) [ 1236.377451][T14877] ? arch_exit_to_user_mode_prepare.isra.0 (arch/x86/entry/syscall_64.c:37) [ 1236.377542][T14877] ? __switch_to (./arch/x86/include/asm/cpufeature.h:101 (discriminator 1) arch/x86/kernel/process_64.c:377 (discriminator 1) arch/x86/kernel/process_64.c:665 (discriminator 1)) [ 1236.377646][T14877] ? kthread_affine_node (kernel/kthread.c:381) Finger prints: mroute6_is_socket:ip6_finish_output2:ip6_finish_output:ip6_output:mld_sendpack