[ 136.629347][ T897] gre: GRE over IPv4 demultiplexer driver [ 137.069662][ T920] ip_gre: GRE over IPv4 tunneling driver [ 152.290252][ T1493] ip6_gre: GRE over IPv6 tunneling driver [ 162.241841][ C2] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 164.162801][ C3] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 165.953810][ C0] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 167.937819][ C0] ip6_tunnel: tep0 xmit: Local address not yet configured! [ 197.875937][ C0] ------------[ cut here ]------------ [ 197.876172][ C0] WARNING: ./include/linux/skbuff.h:3094 at geneve_udp_encap_recv+0x933/0xc68 [geneve], CPU#0: kworker/0:2/1075 [ 197.876488][ C0] Modules linked in: geneve vxlan ip6_gre ip_gre gre act_gact cls_matchall sch_ingress [ 197.876980][ C0] CPU: 0 UID: 0 PID: 1075 Comm: kworker/0:2 Not tainted 7.1.0-virtme #1 PREEMPT(full) [ 197.877235][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 197.877455][ C0] Workqueue: mld mld_ifc_work [ 197.877606][ C0] RIP: 0010:geneve_udp_encap_recv+0x933/0xc68 [geneve] [ 197.877834][ C0] Code: df 48 c1 ee 03 0f b6 34 06 48 89 f8 83 e0 07 83 c0 03 40 38 f0 7c 09 40 84 f6 0f 85 f9 02 00 00 41 8b 76 0c e9 13 fd ff ff 90 <0f> 0b 90 e9 1b fc ff ff 90 0f 0b 90 e9 66 fe ff ff 48 8d b9 a0 00 [ 197.878348][ C0] RSP: 0018:ffa0000000007790 EFLAGS: 00010246 [ 197.878527][ C0] RAX: 0000000000000007 RBX: ff11000009a5c000 RCX: 0000000000000001 [ 197.878740][ C0] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ff1100000bee1941 [ 197.878963][ C0] RBP: ffa0000000007860 R08: ff1100000bee1990 R09: ff1100000de9d032 [ 197.879175][ C0] R10: 1fe22000017dc328 R11: 000000000000006a R12: 0000000000000000 [ 197.879394][ C0] R13: 000000000000ffff R14: ff1100001a901e80 R15: ff1100000bee18c0 [ 197.879603][ C0] FS: 0000000000000000(0000) GS:ff110000c4cb0000(0000) knlGS:0000000000000000 [ 197.879855][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 197.880034][ C0] CR2: 0000559b0dd4ad5c CR3: 000000001674d005 CR4: 0000000000771ef0 [ 197.880246][ C0] PKRU: 55555554 [ 197.880353][ C0] Call Trace: [ 197.880459][ C0] [ 197.880532][ C0] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 197.880678][ C0] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 197.880860][ C0] ? __udp4_lib_lookup+0x5f1/0x820 [ 197.881006][ C0] ? __xfrm_policy_check2.constprop.0+0x36/0x5f0 [ 197.881180][ C0] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 197.881354][ C0] udp_queue_rcv_one_skb+0x645/0xb00 [ 197.881494][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.881635][ C0] ? alloc_chain_hlocks+0x527/0x5d0 [ 197.881782][ C0] udp_unicast_rcv_skb+0x366/0x450 [ 197.881922][ C0] ? udp_rcv+0xce3/0x1e30 [ 197.882034][ C0] udp_rcv+0xd01/0x1e30 [ 197.882141][ C0] ? udp_sk_rx_dst_set+0x90/0x90 [ 197.882283][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.882422][ C0] ? ip_local_deliver_finish+0x2ba/0x610 [ 197.882565][ C0] ip_protocol_deliver_rcu+0x82/0x350 [ 197.882705][ C0] ? process_backlog+0x561/0x1490 [ 197.882852][ C0] ip_local_deliver_finish+0x36f/0x610 [ 197.882998][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.883137][ C0] ip_local_deliver+0x184/0x4c0 [ 197.883279][ C0] ? ip_local_deliver_finish+0x610/0x610 [ 197.883418][ C0] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 197.883561][ C0] ? process_backlog+0x561/0x1490 [ 197.883700][ C0] ip_rcv+0xdc/0x3d0 [ 197.883811][ C0] ? ip_local_deliver+0x4c0/0x4c0 [ 197.883955][ C0] ? validate_chain+0x38b/0xc20 [ 197.884097][ C0] ? mark_usage+0x61/0x170 [ 197.884236][ C0] ? __lock_acquire+0x518/0xc20 [ 197.884377][ C0] __netif_receive_skb_one_core+0xfc/0x180 [ 197.884550][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.884690][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 197.884866][ C0] ? rcu_is_watching+0x15/0xd0 [ 197.885011][ C0] process_backlog+0x2bc/0x1490 [ 197.885156][ C0] __napi_poll+0xa7/0x3b0 [ 197.885262][ C0] net_rx_action+0x513/0xf50 [ 197.885405][ C0] ? __napi_poll+0x3b0/0x3b0 [ 197.885547][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.885690][ C0] ? note_gp_changes+0x158/0x1f0 [ 197.885833][ C0] ? rcu_is_watching+0x15/0xd0 [ 197.885975][ C0] ? mark_held_locks+0x40/0x70 [ 197.886114][ C0] handle_softirqs+0x1d8/0x8f0 [ 197.886258][ C0] ? _local_bh_enable+0xd0/0xd0 [ 197.886399][ C0] do_softirq+0xa9/0xe0 [ 197.886504][ C0] [ 197.886576][ C0] [ 197.886646][ C0] ? __dev_queue_xmit+0x956/0x1b70 [ 197.886790][ C0] __local_bh_enable_ip+0x113/0x140 [ 197.886932][ C0] __dev_queue_xmit+0x96b/0x1b70 [ 197.887073][ C0] ? __lock_acquire+0x518/0xc20 [ 197.887215][ C0] ? find_held_lock+0x2b/0x80 [ 197.887355][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 197.887494][ C0] ? __asan_memcpy+0x3c/0x60 [ 197.887634][ C0] ? eth_header+0x14c/0x180 [ 197.887782][ C0] ? neigh_resolve_output.part.0+0x344/0x740 [ 197.887964][ C0] ip6_finish_output2+0x488/0x1310 [ 197.888105][ C0] ? ip6_xmit+0x2000/0x2000 [ 197.888244][ C0] ? find_held_lock+0x2b/0x80 [ 197.888386][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.888526][ C0] ? ip6_mtu+0x174/0x410 [ 197.888634][ C0] ip6_finish_output+0x701/0xe80 [ 197.888781][ C0] ip6_output+0x23f/0x7f0 [ 197.888886][ C0] ? ip6_finish_output+0xe80/0xe80 [ 197.889027][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.889168][ C0] ? xfrm_bundle_lookup.constprop.0+0xba0/0xba0 [ 197.889343][ C0] ? mark_held_locks+0x40/0x70 [ 197.889483][ C0] ? __local_bh_enable_ip+0xa5/0x140 [ 197.889622][ C0] ? __local_bh_enable_ip+0xa5/0x140 [ 197.889765][ C0] ? icmp6_dst_alloc+0x317/0x4d0 [ 197.889906][ C0] mld_sendpack+0x9d6/0xec0 [ 197.890053][ C0] ? nf_hook.constprop.0+0x340/0x340 [ 197.890196][ C0] ? mld_send_cr+0x50f/0x820 [ 197.890339][ C0] mld_ifc_work+0x36/0x190 [ 197.890480][ C0] ? process_one_work+0xdb7/0x1410 [ 197.890620][ C0] process_one_work+0xdf8/0x1410 [ 197.890767][ C0] ? pwq_dec_nr_in_flight+0x710/0x710 [ 197.890908][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.891056][ C0] worker_thread+0x4f1/0xd60 [ 197.891197][ C0] ? rescuer_thread+0x1320/0x1320 [ 197.891338][ C0] ? __kthread_parkme+0xbd/0x210 [ 197.891480][ C0] ? rescuer_thread+0x1320/0x1320 [ 197.891619][ C0] kthread+0x367/0x460 [ 197.891724][ C0] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 197.891901][ C0] ? kthread_affine_node+0x330/0x330 [ 197.892042][ C0] ret_from_fork+0x474/0x6b0 [ 197.892184][ C0] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 197.892359][ C0] ? __switch_to+0x5a3/0xe00 [ 197.892501][ C0] ? kthread_affine_node+0x330/0x330 [ 197.892641][ C0] ret_from_fork_asm+0x11/0x20 [ 197.892793][ C0] [ 197.892897][ C0] irq event stamp: 172564 [ 197.893006][ C0] hardirqs last enabled at (172572): [] __up_console_sem+0x5a/0x70 [ 197.893250][ C0] hardirqs last disabled at (172579): [] __up_console_sem+0x3f/0x70 [ 197.893491][ C0] softirqs last enabled at (171592): [] __dev_queue_xmit+0x956/0x1b70 [ 197.893733][ C0] softirqs last disabled at (171593): [] do_softirq+0xa9/0xe0 [ 197.893988][ C0] ---[ end trace 0000000000000000 ]--- [ 197.894131][ C0] ================================================================== [ 197.894269][ C0] BUG: KASAN: use-after-free in geneve_rx+0x160e/0x1f80 [geneve] [ 197.894405][ C0] Read of size 1 at addr ff1100000dead008 by task kworker/0:2/1075 [ 197.894539][ C0] [ 197.894587][ C0] CPU: 0 UID: 0 PID: 1075 Comm: kworker/0:2 Tainted: G W 7.1.0-virtme #1 PREEMPT(full) [ 197.894590][ C0] Tainted: [W]=WARN [ 197.894591][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 197.894592][ C0] Workqueue: mld mld_ifc_work [ 197.894595][ C0] Call Trace: [ 197.894595][ C0] [ 197.894596][ C0] dump_stack_lvl+0x6f/0xa0 [ 197.894599][ C0] print_address_description.constprop.0+0x56/0x2d0 [ 197.894603][ C0] print_report+0xfc/0x1fa [ 197.894605][ C0] ? __virt_addr_valid+0x102/0x440 [ 197.894607][ C0] ? __virt_addr_valid+0x1da/0x440 [ 197.894609][ C0] kasan_report+0x108/0x130 [ 197.894612][ C0] ? geneve_rx+0x160e/0x1f80 [geneve] [ 197.894614][ C0] ? geneve_rx+0x160e/0x1f80 [geneve] [ 197.894617][ C0] geneve_rx+0x160e/0x1f80 [geneve] [ 197.894618][ C0] ? geneve_udp_encap_recv+0x933/0xc68 [geneve] [ 197.894620][ C0] ? exc_invalid_op+0x1d/0x60 [ 197.894623][ C0] ? geneve_gro_receive+0x1630/0x1630 [geneve] [ 197.894625][ C0] ? INET_ECN_decapsulate+0x9a0/0x9a0 [geneve] [ 197.894628][ C0] geneve_udp_encap_recv+0x5b1/0xc68 [geneve] [ 197.894630][ C0] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 197.894632][ C0] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 197.894634][ C0] ? __udp4_lib_lookup+0x5f1/0x820 [ 197.894636][ C0] ? __xfrm_policy_check2.constprop.0+0x36/0x5f0 [ 197.894638][ C0] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 197.894640][ C0] udp_queue_rcv_one_skb+0x645/0xb00 [ 197.894641][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.894643][ C0] ? alloc_chain_hlocks+0x527/0x5d0 [ 197.894645][ C0] udp_unicast_rcv_skb+0x366/0x450 [ 197.894647][ C0] ? udp_rcv+0xce3/0x1e30 [ 197.894648][ C0] udp_rcv+0xd01/0x1e30 [ 197.894651][ C0] ? udp_sk_rx_dst_set+0x90/0x90 [ 197.894653][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.894654][ C0] ? ip_local_deliver_finish+0x2ba/0x610 [ 197.894656][ C0] ip_protocol_deliver_rcu+0x82/0x350 [ 197.894658][ C0] ? process_backlog+0x561/0x1490 [ 197.894660][ C0] ip_local_deliver_finish+0x36f/0x610 [ 197.894662][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.894663][ C0] ip_local_deliver+0x184/0x4c0 [ 197.894665][ C0] ? ip_local_deliver_finish+0x610/0x610 [ 197.894667][ C0] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 197.894670][ C0] ? process_backlog+0x561/0x1490 [ 197.894671][ C0] ip_rcv+0xdc/0x3d0 [ 197.894673][ C0] ? ip_local_deliver+0x4c0/0x4c0 [ 197.894674][ C0] ? validate_chain+0x38b/0xc20 [ 197.894676][ C0] ? mark_usage+0x61/0x170 [ 197.894678][ C0] ? __lock_acquire+0x518/0xc20 [ 197.894680][ C0] __netif_receive_skb_one_core+0xfc/0x180 [ 197.894682][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.894683][ C0] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 197.894685][ C0] ? rcu_is_watching+0x15/0xd0 [ 197.894687][ C0] process_backlog+0x2bc/0x1490 [ 197.894690][ C0] __napi_poll+0xa7/0x3b0 [ 197.894691][ C0] net_rx_action+0x513/0xf50 [ 197.894694][ C0] ? __napi_poll+0x3b0/0x3b0 [ 197.894696][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.894699][ C0] ? note_gp_changes+0x158/0x1f0 [ 197.894700][ C0] ? rcu_is_watching+0x15/0xd0 [ 197.894701][ C0] ? mark_held_locks+0x40/0x70 [ 197.894703][ C0] handle_softirqs+0x1d8/0x8f0 [ 197.894706][ C0] ? _local_bh_enable+0xd0/0xd0 [ 197.894708][ C0] do_softirq+0xa9/0xe0 [ 197.894710][ C0] [ 197.894710][ C0] [ 197.894711][ C0] ? __dev_queue_xmit+0x956/0x1b70 [ 197.894712][ C0] __local_bh_enable_ip+0x113/0x140 [ 197.894714][ C0] __dev_queue_xmit+0x96b/0x1b70 [ 197.894716][ C0] ? __lock_acquire+0x518/0xc20 [ 197.894718][ C0] ? find_held_lock+0x2b/0x80 [ 197.894719][ C0] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 197.894721][ C0] ? __asan_memcpy+0x3c/0x60 [ 197.894722][ C0] ? eth_header+0x14c/0x180 [ 197.894724][ C0] ? neigh_resolve_output.part.0+0x344/0x740 [ 197.894727][ C0] ip6_finish_output2+0x488/0x1310 [ 197.894729][ C0] ? ip6_xmit+0x2000/0x2000 [ 197.894730][ C0] ? find_held_lock+0x2b/0x80 [ 197.894732][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.894734][ C0] ? ip6_mtu+0x174/0x410 [ 197.894736][ C0] ip6_finish_output+0x701/0xe80 [ 197.894738][ C0] ip6_output+0x23f/0x7f0 [ 197.894740][ C0] ? ip6_finish_output+0xe80/0xe80 [ 197.894741][ C0] ? __lock_release.isra.0+0x6b/0x1a0 [ 197.894742][ C0] ? xfrm_bundle_lookup.constprop.0+0xba0/0xba0 [ 197.894744][ C0] ? mark_held_locks+0x40/0x70 [ 197.894748][ C0] ? __local_bh_enable_ip+0xa5/0x140 [ 197.894750][ C0] ? __local_bh_enable_ip+0xa5/0x140 [ 197.894751][ C0] ? icmp6_dst_alloc+0x317/0x4d0 [ 197.894753][ C0] mld_sendpack+0x9d6/0xec0 [ 197.894755][ C0] ? nf_hook.constprop.0+0x340/0x340 [ 197.894758][ C0] ? mld_send_cr+0x50f/0x820 [ 197.894760][ C0] mld_ifc_work+0x36/0x190 [ 197.894762][ C0] ? process_one_work+0xdb7/0x1410 [ 197.894764][ C0] process_one_work+0xdf8/0x1410 [ 197.894767][ C0] ? pwq_dec_nr_in_flight+0x710/0x710 [ 197.894768][ C0] ? lock_acquire.part.0+0xbc/0x260 [ 197.894771][ C0] worker_thread+0x4f1/0xd60 [ 197.894774][ C0] ? rescuer_thread+0x1320/0x1320 [ 197.894775][ C0] ? __kthread_parkme+0xbd/0x210 [ 197.894778][ C0] ? rescuer_thread+0x1320/0x1320 [ 197.894779][ C0] kthread+0x367/0x460 [ 197.894781][ C0] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 197.894782][ C0] ? kthread_affine_node+0x330/0x330 [ 197.894784][ C0] ret_from_fork+0x474/0x6b0 [ 197.894786][ C0] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 197.894788][ C0] ? __switch_to+0x5a3/0xe00 [ 197.894790][ C0] ? kthread_affine_node+0x330/0x330 [ 197.894792][ C0] ret_from_fork_asm+0x11/0x20 [ 197.894795][ C0] [ 197.894796][ C0] [ 197.904485][ C0] The buggy address belongs to the physical page: [ 197.904600][ C0] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff11000000000000 pfn:0xdead [ 197.904790][ C0] flags: 0x80000000000000(node=0|zone=1) [ 197.904887][ C0] raw: 0080000000000000 dead000000000100 dead000000000122 0000000000000000 [ 197.905110][ C0] raw: ff11000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 197.905270][ C0] page dumped because: kasan: bad access detected [ 197.905390][ C0] [ 197.905437][ C0] Memory state around the buggy address: [ 197.905576][ C0] ff1100000deacf00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 197.905710][ C0] ff1100000deacf80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 197.905844][ C0] >ff1100000dead000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 197.906033][ C0] ^ [ 197.906102][ C0] ff1100000dead080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 197.906235][ C0] ff1100000dead100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 197.906417][ C0] ================================================================== [ 197.906554][ C0] Disabling lock debugging due to kernel taint WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr