[ 8.657053][ T196] gre: GRE over IPv4 demultiplexer driver [ 9.097352][ T219] ip_gre: GRE over IPv4 tunneling driver [ 13.798586][ T456] ip (456) used greatest stack depth: 23680 bytes left [ 24.538545][ T798] ip6_gre: GRE over IPv6 tunneling driver [ 34.628492][ C0] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 36.549454][ C3] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 38.341456][ C3] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 40.324469][ C0] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 70.621605][ C3] ------------[ cut here ]------------ [ 70.621849][ C3] WARNING: ./include/linux/skbuff.h:3094 at geneve_udp_encap_recv+0x933/0xc68 [geneve], CPU#3: kworker/3:2/473 [ 70.622173][ C3] Modules linked in: geneve vxlan ip6_gre ip_gre gre [ 70.622591][ C3] CPU: 3 UID: 0 PID: 473 Comm: kworker/3:2 Not tainted 7.1.0-virtme #1 PREEMPT(full) [ 70.622841][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 70.623023][ C3] Workqueue: mld mld_ifc_work [ 70.623173][ C3] RIP: 0010:geneve_udp_encap_recv+0x933/0xc68 [geneve] [ 70.623356][ C3] Code: df 48 c1 ee 03 0f b6 34 06 48 89 f8 83 e0 07 83 c0 03 40 38 f0 7c 09 40 84 f6 0f 85 f9 02 00 00 41 8b 76 0c e9 13 fd ff ff 90 <0f> 0b 90 e9 1b fc ff ff 90 0f 0b 90 e9 66 fe ff ff 48 8d b9 a0 00 [ 70.623963][ C3] RSP: 0018:ffa0000000280790 EFLAGS: 00010246 [ 70.624145][ C3] RAX: 0000000000000007 RBX: ff11000011fbc000 RCX: 0000000000000001 [ 70.624353][ C3] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ff1100000c89de81 [ 70.624567][ C3] RBP: ffa0000000280860 R08: ff1100000c89ded0 R09: ff110000099aa032 [ 70.624774][ C3] R10: 1fe2200001913bd0 R11: 000000000000006a R12: 0000000000000000 [ 70.624981][ C3] R13: 000000000000ffff R14: ff1100000f5d1e80 R15: ff1100000c89de00 [ 70.625195][ C3] FS: 0000000000000000(0000) GS:ff110000afe30000(0000) knlGS:0000000000000000 [ 70.625445][ C3] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 70.625622][ C3] CR2: 00007f0939be7574 CR3: 0000000046b4d004 CR4: 0000000000771ef0 [ 70.625842][ C3] PKRU: 55555554 [ 70.625952][ C3] Call Trace: [ 70.626064][ C3] [ 70.626137][ C3] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 70.626283][ C3] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 70.626462][ C3] ? __udp4_lib_lookup+0x5f1/0x820 [ 70.626601][ C3] ? __xfrm_policy_check2.constprop.0+0x36/0x5f0 [ 70.626775][ C3] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 70.626950][ C3] udp_queue_rcv_one_skb+0x645/0xb00 [ 70.627094][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.627234][ C3] ? alloc_chain_hlocks+0x527/0x5d0 [ 70.627373][ C3] udp_unicast_rcv_skb+0x366/0x450 [ 70.627516][ C3] ? udp_rcv+0xce3/0x1e30 [ 70.627621][ C3] udp_rcv+0xd01/0x1e30 [ 70.627729][ C3] ? udp_sk_rx_dst_set+0x90/0x90 [ 70.627871][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.628012][ C3] ? ip_local_deliver_finish+0x2ba/0x610 [ 70.628154][ C3] ip_protocol_deliver_rcu+0x82/0x350 [ 70.628294][ C3] ? process_backlog+0x561/0x1490 [ 70.628439][ C3] ip_local_deliver_finish+0x36f/0x610 [ 70.628577][ C3] ? __lock_release.isra.0+0x6b/0x1a0 [ 70.628717][ C3] ip_local_deliver+0x184/0x4c0 [ 70.628860][ C3] ? ip_local_deliver_finish+0x610/0x610 [ 70.629003][ C3] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 70.629146][ C3] ? process_backlog+0x561/0x1490 [ 70.629283][ C3] ip_rcv+0xdc/0x3d0 [ 70.629388][ C3] ? ip_local_deliver+0x4c0/0x4c0 [ 70.629532][ C3] ? validate_chain+0x38b/0xc20 [ 70.629672][ C3] ? mark_usage+0x61/0x170 [ 70.629813][ C3] ? __lock_acquire+0x518/0xc20 [ 70.629955][ C3] __netif_receive_skb_one_core+0xfc/0x180 [ 70.630130][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.630267][ C3] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 70.630445][ C3] ? rcu_is_watching+0x15/0xd0 [ 70.630588][ C3] process_backlog+0x2bc/0x1490 [ 70.630729][ C3] __napi_poll+0xa7/0x3b0 [ 70.630836][ C3] net_rx_action+0x513/0xf50 [ 70.630985][ C3] ? __napi_poll+0x3b0/0x3b0 [ 70.631129][ C3] ? rcu_is_watching+0x15/0xd0 [ 70.631272][ C3] ? clockevents_program_event+0x307/0x7e0 [ 70.631453][ C3] ? __run_timers+0xaa0/0xaa0 [ 70.631592][ C3] ? rcu_is_watching+0x15/0xd0 [ 70.631731][ C3] ? mark_held_locks+0x40/0x70 [ 70.631871][ C3] handle_softirqs+0x1d8/0x8f0 [ 70.632016][ C3] ? _local_bh_enable+0xd0/0xd0 [ 70.632159][ C3] do_softirq+0xa9/0xe0 [ 70.632263][ C3] [ 70.632335][ C3] [ 70.632409][ C3] ? __dev_queue_xmit+0x956/0x1b70 [ 70.632547][ C3] __local_bh_enable_ip+0x113/0x140 [ 70.632690][ C3] __dev_queue_xmit+0x96b/0x1b70 [ 70.632829][ C3] ? __lock_acquire+0x518/0xc20 [ 70.632969][ C3] ? find_held_lock+0x2b/0x80 [ 70.633111][ C3] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 70.633249][ C3] ? __asan_memcpy+0x3c/0x60 [ 70.633389][ C3] ? eth_header+0x14c/0x180 [ 70.633537][ C3] ? neigh_resolve_output.part.0+0x344/0x740 [ 70.633714][ C3] ip6_finish_output2+0x488/0x1310 [ 70.633856][ C3] ? ip6_xmit+0x2000/0x2000 [ 70.633993][ C3] ? find_held_lock+0x2b/0x80 [ 70.634136][ C3] ? __lock_release.isra.0+0x6b/0x1a0 [ 70.634277][ C3] ? ip6_mtu+0x174/0x410 [ 70.634383][ C3] ip6_finish_output+0x701/0xe80 [ 70.634529][ C3] ip6_output+0x23f/0x7f0 [ 70.634639][ C3] ? ip6_finish_output+0xe80/0xe80 [ 70.634781][ C3] ? __lock_release.isra.0+0x6b/0x1a0 [ 70.634919][ C3] ? xfrm_bundle_lookup.constprop.0+0xba0/0xba0 [ 70.635097][ C3] ? mark_held_locks+0x40/0x70 [ 70.635238][ C3] ? __local_bh_enable_ip+0xa5/0x140 [ 70.635376][ C3] ? __local_bh_enable_ip+0xa5/0x140 [ 70.635519][ C3] ? icmp6_dst_alloc+0x317/0x4d0 [ 70.635661][ C3] mld_sendpack+0x9d6/0xec0 [ 70.635802][ C3] ? nf_hook.constprop.0+0x340/0x340 [ 70.635944][ C3] ? mld_send_cr+0x50f/0x820 [ 70.636088][ C3] mld_ifc_work+0x36/0x190 [ 70.636228][ C3] ? process_one_work+0xdb7/0x1410 [ 70.636367][ C3] process_one_work+0xdf8/0x1410 [ 70.636514][ C3] ? pwq_dec_nr_in_flight+0x710/0x710 [ 70.636654][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.636796][ C3] worker_thread+0x4f1/0xd60 [ 70.636937][ C3] ? rescuer_thread+0x1320/0x1320 [ 70.637080][ C3] ? __kthread_parkme+0xbd/0x210 [ 70.637222][ C3] ? rescuer_thread+0x1320/0x1320 [ 70.637364][ C3] kthread+0x367/0x460 [ 70.637475][ C3] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 70.637651][ C3] ? kthread_affine_node+0x330/0x330 [ 70.637792][ C3] ret_from_fork+0x474/0x6b0 [ 70.637934][ C3] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 70.638112][ C3] ? __switch_to+0x5a3/0xe00 [ 70.638254][ C3] ? kthread_affine_node+0x330/0x330 [ 70.638400][ C3] ret_from_fork_asm+0x11/0x20 [ 70.638548][ C3] [ 70.638652][ C3] irq event stamp: 164500 [ 70.638757][ C3] hardirqs last enabled at (164508): [] __up_console_sem+0x5a/0x70 [ 70.639002][ C3] hardirqs last disabled at (164515): [] __up_console_sem+0x3f/0x70 [ 70.639245][ C3] softirqs last enabled at (163540): [] __dev_queue_xmit+0x956/0x1b70 [ 70.639493][ C3] softirqs last disabled at (163541): [] do_softirq+0xa9/0xe0 [ 70.639733][ C3] ---[ end trace 0000000000000000 ]--- [ 70.639873][ C3] ================================================================== [ 70.640013][ C3] BUG: KASAN: slab-use-after-free in geneve_rx+0x160e/0x1f80 [geneve] [ 70.640149][ C3] Read of size 1 at addr ff110000099ba008 by task kworker/3:2/473 [ 70.640283][ C3] [ 70.640331][ C3] CPU: 3 UID: 0 PID: 473 Comm: kworker/3:2 Tainted: G W 7.1.0-virtme #1 PREEMPT(full) [ 70.640334][ C3] Tainted: [W]=WARN [ 70.640335][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 70.640336][ C3] Workqueue: mld mld_ifc_work [ 70.640339][ C3] Call Trace: [ 70.640339][ C3] [ 70.640340][ C3] dump_stack_lvl+0x6f/0xa0 [ 70.640343][ C3] print_address_description.constprop.0+0x56/0x2d0 [ 70.640347][ C3] print_report+0xfc/0x1fa [ 70.640349][ C3] ? __virt_addr_valid+0x102/0x440 [ 70.640351][ C3] ? __virt_addr_valid+0x1da/0x440 [ 70.640353][ C3] kasan_report+0x108/0x130 [ 70.640356][ C3] ? geneve_rx+0x160e/0x1f80 [geneve] [ 70.640358][ C3] ? geneve_rx+0x160e/0x1f80 [geneve] [ 70.640360][ C3] geneve_rx+0x160e/0x1f80 [geneve] [ 70.640362][ C3] ? geneve_udp_encap_recv+0x933/0xc68 [geneve] [ 70.640364][ C3] ? exc_invalid_op+0x1d/0x60 [ 70.640367][ C3] ? geneve_gro_receive+0x1630/0x1630 [geneve] [ 70.640370][ C3] ? INET_ECN_decapsulate+0x9a0/0x9a0 [geneve] [ 70.640372][ C3] geneve_udp_encap_recv+0x5b1/0xc68 [geneve] [ 70.640374][ C3] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 70.640377][ C3] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 70.640379][ C3] ? __udp4_lib_lookup+0x5f1/0x820 [ 70.640381][ C3] ? __xfrm_policy_check2.constprop.0+0x36/0x5f0 [ 70.640382][ C3] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 70.640384][ C3] udp_queue_rcv_one_skb+0x645/0xb00 [ 70.640386][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.640388][ C3] ? alloc_chain_hlocks+0x527/0x5d0 [ 70.640389][ C3] udp_unicast_rcv_skb+0x366/0x450 [ 70.640391][ C3] ? udp_rcv+0xce3/0x1e30 [ 70.640393][ C3] udp_rcv+0xd01/0x1e30 [ 70.640397][ C3] ? udp_sk_rx_dst_set+0x90/0x90 [ 70.640399][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.640400][ C3] ? ip_local_deliver_finish+0x2ba/0x610 [ 70.640403][ C3] ip_protocol_deliver_rcu+0x82/0x350 [ 70.640405][ C3] ? process_backlog+0x561/0x1490 [ 70.640406][ C3] ip_local_deliver_finish+0x36f/0x610 [ 70.640408][ C3] ? __lock_release.isra.0+0x6b/0x1a0 [ 70.640410][ C3] ip_local_deliver+0x184/0x4c0 [ 70.640411][ C3] ? ip_local_deliver_finish+0x610/0x610 [ 70.640413][ C3] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 70.640416][ C3] ? process_backlog+0x561/0x1490 [ 70.640417][ C3] ip_rcv+0xdc/0x3d0 [ 70.640419][ C3] ? ip_local_deliver+0x4c0/0x4c0 [ 70.640420][ C3] ? validate_chain+0x38b/0xc20 [ 70.640422][ C3] ? mark_usage+0x61/0x170 [ 70.640424][ C3] ? __lock_acquire+0x518/0xc20 [ 70.640426][ C3] __netif_receive_skb_one_core+0xfc/0x180 [ 70.640428][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.640430][ C3] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 70.640431][ C3] ? rcu_is_watching+0x15/0xd0 [ 70.640434][ C3] process_backlog+0x2bc/0x1490 [ 70.640436][ C3] __napi_poll+0xa7/0x3b0 [ 70.640438][ C3] net_rx_action+0x513/0xf50 [ 70.640440][ C3] ? __napi_poll+0x3b0/0x3b0 [ 70.640442][ C3] ? rcu_is_watching+0x15/0xd0 [ 70.640445][ C3] ? clockevents_program_event+0x307/0x7e0 [ 70.640447][ C3] ? __run_timers+0xaa0/0xaa0 [ 70.640449][ C3] ? rcu_is_watching+0x15/0xd0 [ 70.640450][ C3] ? mark_held_locks+0x40/0x70 [ 70.640452][ C3] handle_softirqs+0x1d8/0x8f0 [ 70.640455][ C3] ? _local_bh_enable+0xd0/0xd0 [ 70.640457][ C3] do_softirq+0xa9/0xe0 [ 70.640459][ C3] [ 70.640459][ C3] [ 70.640460][ C3] ? __dev_queue_xmit+0x956/0x1b70 [ 70.640461][ C3] __local_bh_enable_ip+0x113/0x140 [ 70.640463][ C3] __dev_queue_xmit+0x96b/0x1b70 [ 70.640465][ C3] ? __lock_acquire+0x518/0xc20 [ 70.640467][ C3] ? find_held_lock+0x2b/0x80 [ 70.640468][ C3] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 70.640470][ C3] ? __asan_memcpy+0x3c/0x60 [ 70.640472][ C3] ? eth_header+0x14c/0x180 [ 70.640474][ C3] ? neigh_resolve_output.part.0+0x344/0x740 [ 70.640476][ C3] ip6_finish_output2+0x488/0x1310 [ 70.640479][ C3] ? ip6_xmit+0x2000/0x2000 [ 70.640480][ C3] ? find_held_lock+0x2b/0x80 [ 70.640482][ C3] ? __lock_release.isra.0+0x6b/0x1a0 [ 70.640484][ C3] ? ip6_mtu+0x174/0x410 [ 70.640486][ C3] ip6_finish_output+0x701/0xe80 [ 70.640487][ C3] ip6_output+0x23f/0x7f0 [ 70.640489][ C3] ? ip6_finish_output+0xe80/0xe80 [ 70.640490][ C3] ? __lock_release.isra.0+0x6b/0x1a0 [ 70.640492][ C3] ? xfrm_bundle_lookup.constprop.0+0xba0/0xba0 [ 70.640494][ C3] ? mark_held_locks+0x40/0x70 [ 70.640496][ C3] ? __local_bh_enable_ip+0xa5/0x140 [ 70.640497][ C3] ? __local_bh_enable_ip+0xa5/0x140 [ 70.640499][ C3] ? icmp6_dst_alloc+0x317/0x4d0 [ 70.640501][ C3] mld_sendpack+0x9d6/0xec0 [ 70.640503][ C3] ? nf_hook.constprop.0+0x340/0x340 [ 70.640506][ C3] ? mld_send_cr+0x50f/0x820 [ 70.640508][ C3] mld_ifc_work+0x36/0x190 [ 70.640510][ C3] ? process_one_work+0xdb7/0x1410 [ 70.640511][ C3] process_one_work+0xdf8/0x1410 [ 70.640514][ C3] ? pwq_dec_nr_in_flight+0x710/0x710 [ 70.640516][ C3] ? lock_acquire.part.0+0xbc/0x260 [ 70.640519][ C3] worker_thread+0x4f1/0xd60 [ 70.640522][ C3] ? rescuer_thread+0x1320/0x1320 [ 70.640524][ C3] ? __kthread_parkme+0xbd/0x210 [ 70.640526][ C3] ? rescuer_thread+0x1320/0x1320 [ 70.640528][ C3] kthread+0x367/0x460 [ 70.640529][ C3] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 70.640531][ C3] ? kthread_affine_node+0x330/0x330 [ 70.640533][ C3] ret_from_fork+0x474/0x6b0 [ 70.640535][ C3] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 70.640537][ C3] ? __switch_to+0x5a3/0xe00 [ 70.640538][ C3] ? kthread_affine_node+0x330/0x330 [ 70.640540][ C3] ret_from_fork_asm+0x11/0x20 [ 70.640544][ C3] [ 70.640544][ C3] [ 70.650683][ C3] Allocated by task 2454: [ 70.650755][ C3] kasan_save_stack+0x2f/0x50 [ 70.650848][ C3] kasan_save_track+0x14/0x30 [ 70.650938][ C3] __kasan_kmalloc+0x7b/0x90 [ 70.651082][ C3] __kmalloc_node_track_caller_noprof+0x2d8/0x7a0 [ 70.651197][ C3] kstrdup+0x44/0xb0 [ 70.651268][ C3] alloc_vfsmnt+0xd4/0x6f0 [ 70.651359][ C3] clone_mnt+0x54/0x970 [ 70.651427][ C3] copy_tree+0x271/0xd10 [ 70.651496][ C3] copy_mnt_ns+0x291/0xf20 [ 70.651586][ C3] create_new_namespaces+0xe6/0xa10 [ 70.651676][ C3] unshare_nsproxy_namespaces+0xa5/0x1d0 [ 70.651818][ C3] ksys_unshare+0x353/0x880 [ 70.651908][ C3] __x64_sys_unshare+0x34/0x50 [ 70.652000][ C3] do_syscall_64+0x117/0x590 [ 70.652092][ C3] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 70.652257][ C3] [ 70.652303][ C3] Freed by task 0: [ 70.652372][ C3] kasan_save_stack+0x2f/0x50 [ 70.652464][ C3] kasan_save_track+0x14/0x30 [ 70.652555][ C3] kasan_save_free_info+0x3b/0x60 [ 70.652695][ C3] __kasan_slab_free+0x43/0x70 [ 70.652785][ C3] kfree+0x123/0x5a0 [ 70.652852][ C3] delayed_free_vfsmnt+0x5a/0xb0 [ 70.652941][ C3] rcu_do_batch+0x2b6/0x1000 [ 70.653034][ C3] rcu_core+0x2bf/0x640 [ 70.653102][ C3] handle_softirqs+0x1d8/0x8f0 [ 70.653193][ C3] __irq_exit_rcu+0x103/0x1c0 [ 70.653283][ C3] irq_exit_rcu+0xe/0x30 [ 70.653352][ C3] sysvec_apic_timer_interrupt+0x9d/0xe0 [ 70.653444][ C3] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 70.653557][ C3] [ 70.653603][ C3] The buggy address belongs to the object at ff110000099ba008 [ 70.653603][ C3] which belongs to the cache kmalloc-8 of size 8 [ 70.653826][ C3] The buggy address is located 0 bytes inside of [ 70.653826][ C3] freed 8-byte region [ff110000099ba008, ff110000099ba010) [ 70.654048][ C3] [ 70.654095][ C3] The buggy address belongs to the physical page: [ 70.654207][ C3] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x99ba [ 70.654368][ C3] flags: 0x80000000000000(node=0|zone=1) [ 70.654464][ C3] page_type: f5(slab) [ 70.654536][ C3] raw: 0080000000000000 ff1100000103c640 ffd4000000127310 ffd4000000491710 [ 70.654697][ C3] raw: 0000000000000000 00000000001c001c 00000000f5000000 0000000000000000 [ 70.654856][ C3] page dumped because: kasan: bad access detected [ 70.654976][ C3] [ 70.655027][ C3] Memory state around the buggy address: [ 70.655118][ C3] ff110000099b9f00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 70.655253][ C3] ff110000099b9f80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 70.655386][ C3] >ff110000099ba000: fc fa fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 70.655520][ C3] ^ [ 70.655588][ C3] ff110000099ba080: fc fc fc fa fc fc fc fc fc fc fc fc fc fc fc fc [ 70.655719][ C3] ff110000099ba100: fc fc fc fc fc fa fc fc fc fc fc fc fc fc fc fc [ 70.655852][ C3] ================================================================== [ 70.655991][ C3] Disabling lock debugging due to kernel taint WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr