[ 269.499288][T17170] udpgso_bench_tx (17170) used greatest stack depth: 22592 bytes left [ 273.753078][ C1] ------------[ cut here ]------------ [ 273.753744][ C1] WARNING: ./include/linux/skbuff.h:3094 at geneve_udp_encap_recv+0x933/0xc68 [geneve], CPU#1: kworker/1:2/515 [ 273.754063][ C1] Modules linked in: geneve xt_bpf xt_length nft_compat vxlan ipvtap ipvlan xfrm_user nf_tables unix_diag [ 273.754452][ C1] CPU: 1 UID: 0 PID: 515 Comm: kworker/1:2 Not tainted 7.1.0-virtme #1 PREEMPT(full) [ 273.754710][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 273.754884][ C1] Workqueue: mld mld_ifc_work [ 273.755032][ C1] RIP: 0010:geneve_udp_encap_recv+0x933/0xc68 [geneve] [ 273.755211][ C1] Code: df 48 c1 ee 03 0f b6 34 06 48 89 f8 83 e0 07 83 c0 03 40 38 f0 7c 09 40 84 f6 0f 85 f9 02 00 00 41 8b 76 0c e9 13 fd ff ff 90 <0f> 0b 90 e9 1b fc ff ff 90 0f 0b 90 e9 66 fe ff ff 48 8d b9 a0 00 [ 273.755720][ C1] RSP: 0018:ffa00000001d0790 EFLAGS: 00010246 [ 273.755894][ C1] RAX: 0000000000000007 RBX: ff11000022cd4000 RCX: 0000000000000001 [ 273.756099][ C1] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ff110000197355c1 [ 273.756304][ C1] RBP: ffa00000001d0860 R08: ffffffff84cf86bb R09: 1fe2200000aca100 [ 273.756515][ C1] R10: ffe21c0000aca101 R11: ffe21c0000aca101 R12: 0000000000000000 [ 273.756841][ C1] R13: 000000000000ffff R14: ff110000117e4e80 R15: ff11000019735540 [ 273.757048][ C1] FS: 0000000000000000(0000) GS:ff110000e4330000(0000) knlGS:0000000000000000 [ 273.757290][ C1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 273.757471][ C1] CR2: 00007f0cb7a24460 CR3: 000000000e14d004 CR4: 0000000000771ef0 [ 273.757680][ C1] PKRU: 55555554 [ 273.757785][ C1] Call Trace: [ 273.757888][ C1] [ 273.757960][ C1] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 273.758106][ C1] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 273.758277][ C1] ? __udp4_lib_lookup+0x5f1/0x820 [ 273.758421][ C1] ? __xfrm_policy_check2.constprop.0+0x36/0x5f0 [ 273.758593][ C1] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 273.758767][ C1] udp_queue_rcv_one_skb+0x645/0xb00 [ 273.758904][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.759044][ C1] ? alloc_chain_hlocks+0x527/0x5d0 [ 273.759182][ C1] udp_unicast_rcv_skb+0x366/0x450 [ 273.759321][ C1] ? udp_rcv+0xce3/0x1e30 [ 273.759434][ C1] udp_rcv+0xd01/0x1e30 [ 273.759541][ C1] ? udp_sk_rx_dst_set+0x90/0x90 [ 273.759682][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.759821][ C1] ? ip_local_deliver_finish+0x2ba/0x610 [ 273.759961][ C1] ip_protocol_deliver_rcu+0x82/0x350 [ 273.760099][ C1] ? process_backlog+0x561/0x1490 [ 273.760237][ C1] ip_local_deliver_finish+0x36f/0x610 [ 273.760381][ C1] ip_local_deliver+0x184/0x4c0 [ 273.760519][ C1] ? ip_local_deliver_finish+0x610/0x610 [ 273.760665][ C1] ? ip_rcv_finish_core+0x553/0x14c0 [ 273.760803][ C1] ? __asan_memset+0x27/0x50 [ 273.760944][ C1] ? process_backlog+0x561/0x1490 [ 273.761081][ C1] ip_rcv+0xdc/0x3d0 [ 273.761186][ C1] ? ip_local_deliver+0x4c0/0x4c0 [ 273.761325][ C1] ? validate_chain+0x38b/0xc20 [ 273.761473][ C1] ? mark_usage+0x61/0x170 [ 273.761611][ C1] ? __lock_acquire+0x518/0xc20 [ 273.761751][ C1] ? __dev_queue_xmit+0x1077/0x1b70 [ 273.761890][ C1] __netif_receive_skb_one_core+0xfc/0x180 [ 273.762060][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.762198][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 273.762375][ C1] ? rcu_is_watching+0x15/0xd0 [ 273.762517][ C1] process_backlog+0x2bc/0x1490 [ 273.762661][ C1] __napi_poll+0xa7/0x3b0 [ 273.762766][ C1] net_rx_action+0x513/0xf50 [ 273.762906][ C1] ? __napi_poll+0x3b0/0x3b0 [ 273.763042][ C1] ? validate_chain+0x38b/0xc20 [ 273.763185][ C1] ? __rwlock_init+0x150/0x150 [ 273.763322][ C1] ? mark_held_locks+0x40/0x70 [ 273.763473][ C1] handle_softirqs+0x1d8/0x8f0 [ 273.763614][ C1] ? _local_bh_enable+0xd0/0xd0 [ 273.763754][ C1] ? do_raw_spin_unlock+0x59/0x250 [ 273.763891][ C1] ? _raw_spin_unlock+0x2d/0x50 [ 273.764032][ C1] do_softirq+0xa9/0xe0 [ 273.764135][ C1] [ 273.764206][ C1] [ 273.764274][ C1] ? __dev_queue_xmit+0x956/0x1b70 [ 273.764413][ C1] __local_bh_enable_ip+0x113/0x140 [ 273.764551][ C1] __dev_queue_xmit+0x96b/0x1b70 [ 273.764692][ C1] ? __lock_acquire+0x518/0xc20 [ 273.764831][ C1] ? find_held_lock+0x2b/0x80 [ 273.764968][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 273.765107][ C1] ? __asan_memcpy+0x3c/0x60 [ 273.765243][ C1] ? eth_header+0x14c/0x180 [ 273.765385][ C1] ? neigh_resolve_output.part.0+0x344/0x740 [ 273.765560][ C1] ip6_finish_output2+0x488/0x1310 [ 273.765713][ C1] ? ip6_xmit+0x2000/0x2000 [ 273.765851][ C1] ? find_held_lock+0x2b/0x80 [ 273.765989][ C1] ? __lock_release.isra.0+0x6b/0x1a0 [ 273.766128][ C1] ? ip6_mtu+0x174/0x410 [ 273.766233][ C1] ip6_finish_output+0x701/0xe80 [ 273.766376][ C1] ip6_output+0x23f/0x7f0 [ 273.766480][ C1] ? ip6_finish_output+0xe80/0xe80 [ 273.766618][ C1] ? __lock_release.isra.0+0x6b/0x1a0 [ 273.766759][ C1] ? xfrm_bundle_lookup.constprop.0+0xba0/0xba0 [ 273.766930][ C1] ? mark_held_locks+0x40/0x70 [ 273.767067][ C1] ? __local_bh_enable_ip+0xa5/0x140 [ 273.767205][ C1] ? __local_bh_enable_ip+0xa5/0x140 [ 273.767341][ C1] ? icmp6_dst_alloc+0x317/0x4d0 [ 273.767483][ C1] mld_sendpack+0x9d6/0xec0 [ 273.767625][ C1] ? nf_hook.constprop.0+0x340/0x340 [ 273.767769][ C1] ? mld_send_cr+0x50f/0x820 [ 273.767908][ C1] mld_ifc_work+0x36/0x190 [ 273.768046][ C1] ? process_one_work+0xdb7/0x1410 [ 273.768185][ C1] process_one_work+0xdf8/0x1410 [ 273.768326][ C1] ? pwq_dec_nr_in_flight+0x710/0x710 [ 273.768469][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.768613][ C1] worker_thread+0x4f1/0xd60 [ 273.768754][ C1] ? rescuer_thread+0x1320/0x1320 [ 273.768891][ C1] ? __kthread_parkme+0xbd/0x210 [ 273.769031][ C1] ? rescuer_thread+0x1320/0x1320 [ 273.769168][ C1] kthread+0x367/0x460 [ 273.769272][ C1] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 273.769448][ C1] ? kthread_affine_node+0x330/0x330 [ 273.769586][ C1] ret_from_fork+0x474/0x6b0 [ 273.769731][ C1] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 273.769903][ C1] ? __switch_to+0x5a3/0xe00 [ 273.770040][ C1] ? kthread_affine_node+0x330/0x330 [ 273.770178][ C1] ret_from_fork_asm+0x11/0x20 [ 273.770323][ C1] [ 273.770430][ C1] irq event stamp: 23616700 [ 273.770567][ C1] hardirqs last enabled at (23616708): [] __up_console_sem+0x5a/0x70 [ 273.770815][ C1] hardirqs last disabled at (23616715): [] __up_console_sem+0x3f/0x70 [ 273.771053][ C1] softirqs last enabled at (23615528): [] __dev_queue_xmit+0x956/0x1b70 [ 273.771324][ C1] softirqs last disabled at (23615529): [] do_softirq+0xa9/0xe0 [ 273.771568][ C1] ---[ end trace 0000000000000000 ]--- [ 273.771710][ C1] ================================================================== [ 273.771844][ C1] BUG: KASAN: slab-use-after-free in geneve_rx+0x160e/0x1f80 [geneve] [ 273.771979][ C1] Read of size 1 at addr ff11000015c326c8 by task kworker/1:2/515 [ 273.772116][ C1] [ 273.772164][ C1] CPU: 1 UID: 0 PID: 515 Comm: kworker/1:2 Tainted: G W 7.1.0-virtme #1 PREEMPT(full) [ 273.772167][ C1] Tainted: [W]=WARN [ 273.772168][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 273.772169][ C1] Workqueue: mld mld_ifc_work [ 273.772171][ C1] Call Trace: [ 273.772172][ C1] [ 273.772173][ C1] dump_stack_lvl+0x6f/0xa0 [ 273.772176][ C1] print_address_description.constprop.0+0x56/0x2d0 [ 273.772180][ C1] print_report+0xfc/0x1fa [ 273.772182][ C1] ? __virt_addr_valid+0x102/0x440 [ 273.772184][ C1] ? __virt_addr_valid+0x1da/0x440 [ 273.772186][ C1] kasan_report+0x108/0x130 [ 273.772189][ C1] ? geneve_rx+0x160e/0x1f80 [geneve] [ 273.772191][ C1] ? geneve_rx+0x160e/0x1f80 [geneve] [ 273.772194][ C1] geneve_rx+0x160e/0x1f80 [geneve] [ 273.772195][ C1] ? geneve_udp_encap_recv+0x933/0xc68 [geneve] [ 273.772197][ C1] ? exc_invalid_op+0x1d/0x60 [ 273.772201][ C1] ? geneve_gro_receive+0x1630/0x1630 [geneve] [ 273.772203][ C1] ? INET_ECN_decapsulate+0x9a0/0x9a0 [geneve] [ 273.772205][ C1] ? dst_release+0x3b/0x250 [ 273.772208][ C1] geneve_udp_encap_recv+0x5b1/0xc68 [geneve] [ 273.772210][ C1] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 273.772212][ C1] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 273.772214][ C1] ? __udp4_lib_lookup+0x5f1/0x820 [ 273.772215][ C1] ? __xfrm_policy_check2.constprop.0+0x36/0x5f0 [ 273.772217][ C1] ? geneve_udp_encap_err_lookup+0x920/0x920 [geneve] [ 273.772219][ C1] udp_queue_rcv_one_skb+0x645/0xb00 [ 273.772221][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.772222][ C1] ? alloc_chain_hlocks+0x527/0x5d0 [ 273.772224][ C1] udp_unicast_rcv_skb+0x366/0x450 [ 273.772226][ C1] ? udp_rcv+0xce3/0x1e30 [ 273.772228][ C1] udp_rcv+0xd01/0x1e30 [ 273.772230][ C1] ? udp_sk_rx_dst_set+0x90/0x90 [ 273.772232][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.772234][ C1] ? ip_local_deliver_finish+0x2ba/0x610 [ 273.772236][ C1] ip_protocol_deliver_rcu+0x82/0x350 [ 273.772238][ C1] ? process_backlog+0x561/0x1490 [ 273.772239][ C1] ip_local_deliver_finish+0x36f/0x610 [ 273.772241][ C1] ip_local_deliver+0x184/0x4c0 [ 273.772243][ C1] ? ip_local_deliver_finish+0x610/0x610 [ 273.772245][ C1] ? ip_rcv_finish_core+0x553/0x14c0 [ 273.772246][ C1] ? __asan_memset+0x27/0x50 [ 273.772248][ C1] ? process_backlog+0x561/0x1490 [ 273.772250][ C1] ip_rcv+0xdc/0x3d0 [ 273.772251][ C1] ? ip_local_deliver+0x4c0/0x4c0 [ 273.772253][ C1] ? validate_chain+0x38b/0xc20 [ 273.772255][ C1] ? mark_usage+0x61/0x170 [ 273.772257][ C1] ? __lock_acquire+0x518/0xc20 [ 273.772258][ C1] ? __dev_queue_xmit+0x1077/0x1b70 [ 273.772260][ C1] __netif_receive_skb_one_core+0xfc/0x180 [ 273.772262][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.772263][ C1] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 273.772265][ C1] ? rcu_is_watching+0x15/0xd0 [ 273.772267][ C1] process_backlog+0x2bc/0x1490 [ 273.772269][ C1] __napi_poll+0xa7/0x3b0 [ 273.772271][ C1] net_rx_action+0x513/0xf50 [ 273.772274][ C1] ? __napi_poll+0x3b0/0x3b0 [ 273.772275][ C1] ? validate_chain+0x38b/0xc20 [ 273.772279][ C1] ? __rwlock_init+0x150/0x150 [ 273.772280][ C1] ? mark_held_locks+0x40/0x70 [ 273.772283][ C1] handle_softirqs+0x1d8/0x8f0 [ 273.772285][ C1] ? _local_bh_enable+0xd0/0xd0 [ 273.772286][ C1] ? do_raw_spin_unlock+0x59/0x250 [ 273.772288][ C1] ? _raw_spin_unlock+0x2d/0x50 [ 273.772290][ C1] do_softirq+0xa9/0xe0 [ 273.772292][ C1] [ 273.772292][ C1] [ 273.772293][ C1] ? __dev_queue_xmit+0x956/0x1b70 [ 273.772294][ C1] __local_bh_enable_ip+0x113/0x140 [ 273.772296][ C1] __dev_queue_xmit+0x96b/0x1b70 [ 273.772298][ C1] ? __lock_acquire+0x518/0xc20 [ 273.772300][ C1] ? find_held_lock+0x2b/0x80 [ 273.772301][ C1] ? netdev_core_pick_tx+0x2c0/0x2c0 [ 273.772303][ C1] ? __asan_memcpy+0x3c/0x60 [ 273.772304][ C1] ? eth_header+0x14c/0x180 [ 273.772307][ C1] ? neigh_resolve_output.part.0+0x344/0x740 [ 273.772310][ C1] ip6_finish_output2+0x488/0x1310 [ 273.772312][ C1] ? ip6_xmit+0x2000/0x2000 [ 273.772313][ C1] ? find_held_lock+0x2b/0x80 [ 273.772314][ C1] ? __lock_release.isra.0+0x6b/0x1a0 [ 273.772316][ C1] ? ip6_mtu+0x174/0x410 [ 273.772318][ C1] ip6_finish_output+0x701/0xe80 [ 273.772320][ C1] ip6_output+0x23f/0x7f0 [ 273.772322][ C1] ? ip6_finish_output+0xe80/0xe80 [ 273.772323][ C1] ? __lock_release.isra.0+0x6b/0x1a0 [ 273.772325][ C1] ? xfrm_bundle_lookup.constprop.0+0xba0/0xba0 [ 273.772327][ C1] ? mark_held_locks+0x40/0x70 [ 273.772329][ C1] ? __local_bh_enable_ip+0xa5/0x140 [ 273.772330][ C1] ? __local_bh_enable_ip+0xa5/0x140 [ 273.772332][ C1] ? icmp6_dst_alloc+0x317/0x4d0 [ 273.772334][ C1] mld_sendpack+0x9d6/0xec0 [ 273.772336][ C1] ? nf_hook.constprop.0+0x340/0x340 [ 273.772338][ C1] ? mld_send_cr+0x50f/0x820 [ 273.772340][ C1] mld_ifc_work+0x36/0x190 [ 273.772342][ C1] ? process_one_work+0xdb7/0x1410 [ 273.772344][ C1] process_one_work+0xdf8/0x1410 [ 273.772347][ C1] ? pwq_dec_nr_in_flight+0x710/0x710 [ 273.772349][ C1] ? lock_acquire.part.0+0xbc/0x260 [ 273.772352][ C1] worker_thread+0x4f1/0xd60 [ 273.772354][ C1] ? rescuer_thread+0x1320/0x1320 [ 273.772356][ C1] ? __kthread_parkme+0xbd/0x210 [ 273.772358][ C1] ? rescuer_thread+0x1320/0x1320 [ 273.772360][ C1] kthread+0x367/0x460 [ 273.772362][ C1] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 273.772363][ C1] ? kthread_affine_node+0x330/0x330 [ 273.772366][ C1] ret_from_fork+0x474/0x6b0 [ 273.772368][ C1] ? arch_exit_to_user_mode_prepare.isra.0+0x120/0x120 [ 273.772370][ C1] ? __switch_to+0x5a3/0xe00 [ 273.772372][ C1] ? kthread_affine_node+0x330/0x330 [ 273.772374][ C1] ret_from_fork_asm+0x11/0x20 [ 273.772378][ C1] [ 273.772378][ C1] [ 273.783226][ C1] Allocated by task 17288: [ 273.783370][ C1] kasan_save_stack+0x2f/0x50 [ 273.783464][ C1] kasan_save_track+0x14/0x30 [ 273.783552][ C1] __kasan_slab_alloc+0x60/0x70 [ 273.783644][ C1] kmem_cache_alloc_noprof+0x221/0x5f0 [ 273.783788][ C1] alloc_empty_file+0x3f/0x120 [ 273.783877][ C1] path_openat+0xcb/0x3b0 [ 273.783945][ C1] do_file_open+0x209/0x480 [ 273.784035][ C1] do_sys_openat2+0xe0/0x170 [ 273.784176][ C1] __x64_sys_openat+0x10e/0x210 [ 273.784265][ C1] do_syscall_64+0x117/0x590 [ 273.784353][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 273.784466][ C1] [ 273.784562][ C1] Freed by task 14: [ 273.784632][ C1] kasan_save_stack+0x2f/0x50 [ 273.784723][ C1] kasan_save_track+0x14/0x30 [ 273.784813][ C1] kasan_save_free_info+0x3b/0x60 [ 273.784957][ C1] __kasan_slab_free+0x43/0x70 [ 273.785046][ C1] slab_free_after_rcu_debug+0xa6/0x100 [ 273.785135][ C1] rcu_do_batch+0x2b6/0x1000 [ 273.785224][ C1] rcu_core+0x2bf/0x640 [ 273.785293][ C1] handle_softirqs+0x1d8/0x8f0 [ 273.785434][ C1] run_ksoftirqd+0x39/0x60 [ 273.785523][ C1] smpboot_thread_fn+0x2fb/0x9b0 [ 273.785612][ C1] kthread+0x367/0x460 [ 273.785682][ C1] ret_from_fork+0x474/0x6b0 [ 273.785821][ C1] ret_from_fork_asm+0x11/0x20 [ 273.785912][ C1] [ 273.785958][ C1] Last potentially related work creation: [ 273.786051][ C1] kasan_save_stack+0x2f/0x50 [ 273.786195][ C1] kasan_record_aux_stack+0x9b/0xc0 [ 273.786284][ C1] kmem_cache_free+0x37d/0x560 [ 273.786374][ C1] fput_close_sync+0xde/0x1b0 [ 273.786467][ C1] __x64_sys_close+0x8b/0xf0 [ 273.786607][ C1] do_syscall_64+0x117/0x590 [ 273.786700][ C1] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 273.786812][ C1] [ 273.786861][ C1] The buggy address belongs to the object at ff11000015c32680 [ 273.786861][ C1] which belongs to the cache filp of size 344 [ 273.787131][ C1] The buggy address is located 72 bytes inside of [ 273.787131][ C1] freed 344-byte region [ff11000015c32680, ff11000015c327d8) [ 273.787349][ C1] [ 273.787395][ C1] The buggy address belongs to the physical page: [ 273.787508][ C1] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x15c30 [ 273.787672][ C1] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 273.787862][ C1] flags: 0x80000000000040(head|node=0|zone=1) [ 273.787978][ C1] page_type: f5(slab) [ 273.788050][ C1] raw: 0080000000000040 ff11000001973840 ffd4000000091710 ffd40000005fa510 [ 273.788266][ C1] raw: 0000000000000000 00000000001c001c 00000000f5000000 0000000000000000 [ 273.788423][ C1] head: 0080000000000040 ff11000001973840 ffd4000000091710 ffd40000005fa510 [ 273.788637][ C1] head: 0000000000000000 00000000001c001c 00000000f5000000 0000000000000000 [ 273.788792][ C1] head: 0080000000000002 ffffffffffffff01 00000000ffffffff 00000000ffffffff [ 273.788951][ C1] head: ff11000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 273.789160][ C1] page dumped because: kasan: bad access detected [ 273.789271][ C1] [ 273.789317][ C1] Memory state around the buggy address: [ 273.789457][ C1] ff11000015c32580: fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc fc [ 273.789589][ C1] ff11000015c32600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 273.789724][ C1] >ff11000015c32680: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 273.789906][ C1] ^ [ 273.790014][ C1] ff11000015c32700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 273.790144][ C1] ff11000015c32780: fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc fc [ 273.790327][ C1] ================================================================== [ 273.790462][ C1] Disabling lock debugging due to kernel taint [ 458.376508][T18062] udpgso_bench_tx (18062) used greatest stack depth: 22288 bytes left [ 459.409245][T18132] udpgso_bench_tx (18132) used greatest stack depth: 21656 bytes left