[ 8.801668][ T205] ip (205) used greatest stack depth: 23872 bytes left [ 10.411802][ T262] mpls_gso: MPLS GSO support [ 10.765882][ T275] Mirror/redirect action on [ 10.849458][ C2] ------------[ cut here ]------------ [ 10.849729][ C2] WARNING: ./include/linux/skbuff.h:3094 at udp_tun_rx_dst+0xa92/0x1060, CPU#2: ping/277 [ 10.850033][ C2] Modules linked in: act_mirred act_tunnel_key cls_flower bareudp mpls_gso mpls_iptunnel mpls_router sch_ingress [ 10.850549][ C2] CPU: 2 UID: 0 PID: 277 Comm: ping Not tainted 7.1.0-virtme #1 PREEMPT(full) [ 10.850864][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 10.851135][ C2] RIP: 0010:udp_tun_rx_dst+0xa92/0x1060 [ 10.851333][ C2] Code: 24 18 4c 89 44 24 20 e8 4c 6b 74 fe 4c 8b 44 24 20 49 0f ba 28 08 4c 8b 4c 24 18 e9 c0 f9 ff ff 90 0f 0b 90 e9 7d fb ff ff 90 <0f> 0b 90 e9 f1 f9 ff ff 90 0f 0b 90 e9 a7 fa ff ff 44 89 44 24 18 [ 10.851941][ C2] RSP: 0018:ffa0000000228718 EFLAGS: 00010246 [ 10.852172][ C2] RAX: 0000000000000007 RBX: 000000000000ffff RCX: 0000000000000000 [ 10.852431][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ff110000103c703a [ 10.852709][ C2] RBP: ffa0000000228770 R08: ff1100000b82c1c8 R09: ff11000005826200 [ 10.852983][ C2] R10: ffe21c000170583c R11: ffe21c000170583c R12: ff1100000b82c1dc [ 10.853242][ C2] R13: ff1100000b82c1da R14: ff110000058262b6 R15: ff1100000b82c100 [ 10.853517][ C2] FS: 00007fa0f843d4c0(0000) GS:ff110000b8bb0000(0000) knlGS:0000000000000000 [ 10.853818][ C2] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 10.854046][ C2] CR2: 0000561e542e20a8 CR3: 00000000126bc002 CR4: 0000000000771ef0 [ 10.854310][ C2] PKRU: 55555554 [ 10.854477][ C2] Call Trace: [ 10.854677][ C2] [ 10.854801][ C2] bareudp_udp_encap_recv+0x243/0x1847 [bareudp] [ 10.855029][ C2] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 10.855219][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.855444][ C2] ? __udp4_lib_lookup+0x5f1/0x820 [ 10.855652][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.855885][ C2] udp_queue_rcv_one_skb+0x645/0xb00 [ 10.856075][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.856266][ C2] ? print_irq_inversion_bug.part.0+0x59/0xc0 [ 10.856504][ C2] udp_unicast_rcv_skb+0x366/0x450 [ 10.856702][ C2] ? udp_rcv+0xce3/0x1e30 [ 10.856860][ C2] udp_rcv+0xd01/0x1e30 [ 10.857018][ C2] ? udp_sk_rx_dst_set+0x90/0x90 [ 10.857208][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.857396][ C2] ? ip_local_deliver_finish+0x2ba/0x610 [ 10.857600][ C2] ip_protocol_deliver_rcu+0x82/0x350 [ 10.857797][ C2] ? process_backlog+0x561/0x1490 [ 10.857989][ C2] ip_local_deliver_finish+0x36f/0x610 [ 10.858180][ C2] ? __lock_release.isra.0+0x6b/0x1a0 [ 10.858368][ C2] ip_local_deliver+0x184/0x4c0 [ 10.858571][ C2] ? ip_local_deliver_finish+0x610/0x610 [ 10.858769][ C2] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 10.858961][ C2] ? process_backlog+0x561/0x1490 [ 10.859149][ C2] ip_rcv+0xdc/0x3d0 [ 10.859304][ C2] ? ip_local_deliver+0x4c0/0x4c0 [ 10.859507][ C2] ? mark_usage+0x61/0x170 [ 10.859705][ C2] ? __lock_acquire+0x518/0xc20 [ 10.859895][ C2] ? __dev_queue_xmit+0x1077/0x1b70 [ 10.860084][ C2] __netif_receive_skb_one_core+0xfc/0x180 [ 10.860308][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.860507][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 10.860737][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.860929][ C2] process_backlog+0x2bc/0x1490 [ 10.861125][ C2] __napi_poll+0xa7/0x3b0 [ 10.861279][ C2] net_rx_action+0x513/0xf50 [ 10.861482][ C2] ? __napi_poll+0x3b0/0x3b0 [ 10.861675][ C2] ? trace_rcu_this_gp.isra.0+0x1b6/0x3c0 [ 10.861866][ C2] ? trace_rcu_quiescent_state_report+0xf2/0x330 [ 10.862089][ C2] ? find_held_lock+0x2b/0x80 [ 10.862281][ C2] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 10.862520][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.862717][ C2] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 10.862943][ C2] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 10.863167][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.863356][ C2] ? mark_held_locks+0x40/0x70 [ 10.863559][ C2] handle_softirqs+0x1d8/0x8f0 [ 10.863761][ C2] ? _local_bh_enable+0xd0/0xd0 [ 10.863956][ C2] do_softirq+0xa9/0xe0 [ 10.864110][ C2] [ 10.864228][ C2] [ 10.864346][ C2] __local_bh_enable_ip+0x113/0x140 [ 10.864548][ C2] __neigh_event_send+0x30a/0x1070 [ 10.864744][ C2] ? lockdep_hardirqs_on+0x21/0x130 [ 10.864934][ C2] ? sync_exp_reset_tree_hotplug+0x3f0/0x3f0 [ 10.865159][ C2] neigh_resolve_output+0xbe/0x140 [ 10.865349][ C2] ip_finish_output2+0x684/0x1c60 [ 10.865550][ C2] ? ip_dst_mtu_maybe_forward+0x2c7/0x720 [ 10.865745][ C2] ? ip4_dst_hoplimit+0x320/0x320 [ 10.865935][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.866125][ C2] ip_output+0x1ca/0x660 [ 10.866280][ C2] ? ip_finish_output+0x460/0x460 [ 10.866481][ C2] ? __ip_make_skb+0x106a/0x2300 [ 10.866682][ C2] ip_push_pending_frames+0xf6/0x250 [ 10.866872][ C2] raw_sendmsg+0x11f3/0x1b00 [ 10.867061][ C2] ? mark_lock+0x980/0xa00 [ 10.867251][ C2] ? raw_send_hdrinc+0x1740/0x1740 [ 10.867438][ C2] ? folio_add_lru_vma+0x1a1/0x250 [ 10.867642][ C2] ? rcu_lockdep_current_cpu_online+0x39/0x1b0 [ 10.867877][ C2] ? rcu_read_unlock+0x1b/0x70 [ 10.868072][ C2] ? wp_page_copy+0x741/0x10d0 [ 10.868263][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.868451][ C2] ? __might_fault+0x97/0x140 [ 10.868657][ C2] ? __might_fault+0x97/0x140 [ 10.868855][ C2] ? __might_fault+0x97/0x140 [ 10.869044][ C2] __sys_sendto+0x2aa/0x3e0 [ 10.869235][ C2] ? __ia32_sys_getpeername+0xd0/0xd0 [ 10.869421][ C2] ? __lock_release.isra.0+0xb3/0x1a0 [ 10.869633][ C2] ? exc_page_fault+0x87/0x100 [ 10.869831][ C2] __x64_sys_sendto+0xe4/0x1f0 [ 10.870020][ C2] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 10.870245][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.870432][ C2] ? do_syscall_64+0x82/0x590 [ 10.870634][ C2] do_syscall_64+0x117/0x590 [ 10.870832][ C2] ? trace_hardirqs_off+0xd/0x30 [ 10.871022][ C2] ? exc_page_fault+0xee/0x100 [ 10.871213][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 10.871437][ C2] RIP: 0033:0x7fa0f865b64e [ 10.871646][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 10.872204][ C2] RSP: 002b:00007ffdd4501190 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 10.872481][ C2] RAX: ffffffffffffffda RBX: 0000000000000040 RCX: 00007fa0f865b64e [ 10.872745][ C2] RDX: 0000000000000040 RSI: 0000561e542d20a4 RDI: 0000000000000005 [ 10.873005][ C2] RBP: 00007ffdd45011a0 R08: 0000561e542e4320 R09: 0000000000000010 [ 10.873266][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 431bde82d7b634db [ 10.873543][ C2] R13: 0000000000000000 R14: 0000561e542e53e0 R15: 0000561e542d20a0 [ 10.873815][ C2] [ 10.873967][ C2] irq event stamp: 39514 [ 10.874122][ C2] hardirqs last enabled at (39524): [] __up_console_sem+0x5a/0x70 [ 10.874418][ C2] hardirqs last disabled at (39533): [] __up_console_sem+0x3f/0x70 [ 10.874735][ C2] softirqs last enabled at (37490): [] __neigh_event_send+0x305/0x1070 [ 10.875031][ C2] softirqs last disabled at (37491): [] do_softirq+0xa9/0xe0 [ 10.875326][ C2] ---[ end trace 0000000000000000 ]--- [ 10.875530][ C2] ================================================================== [ 10.875687][ C2] BUG: KASAN: slab-out-of-bounds in udp_tun_rx_dst+0xb91/0x1060 [ 10.875821][ C2] Read of size 2 at addr ff110000103d6fff by task ping/277 [ 10.875952][ C2] [ 10.875998][ C2] CPU: 2 UID: 0 PID: 277 Comm: ping Tainted: G W 7.1.0-virtme #1 PREEMPT(full) [ 10.876002][ C2] Tainted: [W]=WARN [ 10.876002][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 10.876003][ C2] Call Trace: [ 10.876004][ C2] [ 10.876005][ C2] dump_stack_lvl+0x6f/0xa0 [ 10.876009][ C2] print_address_description.constprop.0+0x56/0x2d0 [ 10.876014][ C2] print_report+0xfc/0x1fa [ 10.876016][ C2] ? __virt_addr_valid+0x102/0x440 [ 10.876018][ C2] ? __virt_addr_valid+0x1da/0x440 [ 10.876020][ C2] kasan_report+0x108/0x130 [ 10.876023][ C2] ? udp_tun_rx_dst+0xb91/0x1060 [ 10.876025][ C2] ? udp_tun_rx_dst+0xb91/0x1060 [ 10.876028][ C2] udp_tun_rx_dst+0xb91/0x1060 [ 10.876030][ C2] bareudp_udp_encap_recv+0x243/0x1847 [bareudp] [ 10.876033][ C2] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 10.876035][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.876037][ C2] ? __udp4_lib_lookup+0x5f1/0x820 [ 10.876039][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.876041][ C2] udp_queue_rcv_one_skb+0x645/0xb00 [ 10.876042][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.876044][ C2] ? print_irq_inversion_bug.part.0+0x59/0xc0 [ 10.876046][ C2] udp_unicast_rcv_skb+0x366/0x450 [ 10.876048][ C2] ? udp_rcv+0xce3/0x1e30 [ 10.876049][ C2] udp_rcv+0xd01/0x1e30 [ 10.876052][ C2] ? udp_sk_rx_dst_set+0x90/0x90 [ 10.876054][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.876055][ C2] ? ip_local_deliver_finish+0x2ba/0x610 [ 10.876058][ C2] ip_protocol_deliver_rcu+0x82/0x350 [ 10.876060][ C2] ? process_backlog+0x561/0x1490 [ 10.876061][ C2] ip_local_deliver_finish+0x36f/0x610 [ 10.876063][ C2] ? __lock_release.isra.0+0x6b/0x1a0 [ 10.876065][ C2] ip_local_deliver+0x184/0x4c0 [ 10.876067][ C2] ? ip_local_deliver_finish+0x610/0x610 [ 10.876068][ C2] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 10.876071][ C2] ? process_backlog+0x561/0x1490 [ 10.876072][ C2] ip_rcv+0xdc/0x3d0 [ 10.876074][ C2] ? ip_local_deliver+0x4c0/0x4c0 [ 10.876076][ C2] ? mark_usage+0x61/0x170 [ 10.876078][ C2] ? __lock_acquire+0x518/0xc20 [ 10.876079][ C2] ? __dev_queue_xmit+0x1077/0x1b70 [ 10.876081][ C2] __netif_receive_skb_one_core+0xfc/0x180 [ 10.876083][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.876084][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 10.876086][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.876088][ C2] process_backlog+0x2bc/0x1490 [ 10.876090][ C2] __napi_poll+0xa7/0x3b0 [ 10.876092][ C2] net_rx_action+0x513/0xf50 [ 10.876095][ C2] ? __napi_poll+0x3b0/0x3b0 [ 10.876096][ C2] ? trace_rcu_this_gp.isra.0+0x1b6/0x3c0 [ 10.876098][ C2] ? trace_rcu_quiescent_state_report+0xf2/0x330 [ 10.876100][ C2] ? find_held_lock+0x2b/0x80 [ 10.876102][ C2] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 10.876104][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.876106][ C2] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 10.876108][ C2] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 10.876109][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.876111][ C2] ? mark_held_locks+0x40/0x70 [ 10.876113][ C2] handle_softirqs+0x1d8/0x8f0 [ 10.876115][ C2] ? _local_bh_enable+0xd0/0xd0 [ 10.876117][ C2] do_softirq+0xa9/0xe0 [ 10.876119][ C2] [ 10.876119][ C2] [ 10.876120][ C2] __local_bh_enable_ip+0x113/0x140 [ 10.876122][ C2] __neigh_event_send+0x30a/0x1070 [ 10.876123][ C2] ? lockdep_hardirqs_on+0x21/0x130 [ 10.876125][ C2] ? sync_exp_reset_tree_hotplug+0x3f0/0x3f0 [ 10.876127][ C2] neigh_resolve_output+0xbe/0x140 [ 10.876129][ C2] ip_finish_output2+0x684/0x1c60 [ 10.876131][ C2] ? ip_dst_mtu_maybe_forward+0x2c7/0x720 [ 10.876133][ C2] ? ip4_dst_hoplimit+0x320/0x320 [ 10.876134][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.876136][ C2] ip_output+0x1ca/0x660 [ 10.876138][ C2] ? ip_finish_output+0x460/0x460 [ 10.876140][ C2] ? __ip_make_skb+0x106a/0x2300 [ 10.876143][ C2] ip_push_pending_frames+0xf6/0x250 [ 10.876145][ C2] raw_sendmsg+0x11f3/0x1b00 [ 10.876147][ C2] ? mark_lock+0x980/0xa00 [ 10.876149][ C2] ? raw_send_hdrinc+0x1740/0x1740 [ 10.876150][ C2] ? folio_add_lru_vma+0x1a1/0x250 [ 10.876152][ C2] ? rcu_lockdep_current_cpu_online+0x39/0x1b0 [ 10.876154][ C2] ? rcu_read_unlock+0x1b/0x70 [ 10.876156][ C2] ? wp_page_copy+0x741/0x10d0 [ 10.876158][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.876159][ C2] ? __might_fault+0x97/0x140 [ 10.876162][ C2] ? __might_fault+0x97/0x140 [ 10.876163][ C2] ? __might_fault+0x97/0x140 [ 10.876166][ C2] __sys_sendto+0x2aa/0x3e0 [ 10.876167][ C2] ? __ia32_sys_getpeername+0xd0/0xd0 [ 10.876169][ C2] ? __lock_release.isra.0+0xb3/0x1a0 [ 10.876172][ C2] ? exc_page_fault+0x87/0x100 [ 10.876175][ C2] __x64_sys_sendto+0xe4/0x1f0 [ 10.876176][ C2] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 10.876178][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.876180][ C2] ? do_syscall_64+0x82/0x590 [ 10.876181][ C2] do_syscall_64+0x117/0x590 [ 10.876183][ C2] ? trace_hardirqs_off+0xd/0x30 [ 10.876184][ C2] ? exc_page_fault+0xee/0x100 [ 10.876186][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 10.876187][ C2] RIP: 0033:0x7fa0f865b64e [ 10.876190][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 10.876191][ C2] RSP: 002b:00007ffdd4501190 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 10.876193][ C2] RAX: ffffffffffffffda RBX: 0000000000000040 RCX: 00007fa0f865b64e [ 10.876195][ C2] RDX: 0000000000000040 RSI: 0000561e542d20a4 RDI: 0000000000000005 [ 10.876195][ C2] RBP: 00007ffdd45011a0 R08: 0000561e542e4320 R09: 0000000000000010 [ 10.876196][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 431bde82d7b634db [ 10.876197][ C2] R13: 0000000000000000 R14: 0000561e542e53e0 R15: 0000561e542d20a0 [ 10.876199][ C2] [ 10.876200][ C2] [ 10.886125][ C2] Allocated by task 220: [ 10.886194][ C2] kasan_save_stack+0x2f/0x50 [ 10.886285][ C2] kasan_save_track+0x14/0x30 [ 10.886375][ C2] __kasan_kmalloc+0x7b/0x90 [ 10.886463][ C2] ipv6_add_dev.part.0+0x476/0x1020 [ 10.886552][ C2] addrconf_notify+0x429/0xf30 [ 10.886640][ C2] notifier_call_chain+0xae/0x300 [ 10.886733][ C2] register_netdevice+0x120b/0x1c80 [ 10.886822][ C2] veth_newlink+0x3a9/0x8d0 [ 10.886911][ C2] rtnl_newlink_create+0x2da/0x8c0 [ 10.887002][ C2] __rtnl_newlink+0x22b/0xa50 [ 10.887089][ C2] rtnl_newlink+0x8d1/0xee0 [ 10.887177][ C2] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 10.887264][ C2] netlink_rcv_skb+0x14e/0x3a0 [ 10.887352][ C2] netlink_unicast+0x486/0x750 [ 10.887440][ C2] netlink_sendmsg+0x735/0xc60 [ 10.887526][ C2] ____sys_sendmsg+0x419/0x850 [ 10.887614][ C2] ___sys_sendmsg+0x14e/0x1d0 [ 10.887706][ C2] __sys_sendmsg+0x12c/0x1d0 [ 10.887794][ C2] do_syscall_64+0x117/0x590 [ 10.887882][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 10.887990][ C2] [ 10.888037][ C2] The buggy address belongs to the object at ff110000103d4000 [ 10.888037][ C2] which belongs to the cache kmalloc-4k of size 4096 [ 10.888253][ C2] The buggy address is located 8191 bytes to the right of [ 10.888253][ C2] allocated 4096-byte region [ff110000103d4000, ff110000103d5000) [ 10.888491][ C2] [ 10.888535][ C2] The buggy address belongs to the physical page: [ 10.888645][ C2] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xff110000103d1000 pfn:0x103d0 [ 10.888826][ C2] head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 10.888961][ C2] flags: 0x80000000000240(workingset|head|node=0|zone=1) [ 10.889077][ C2] page_type: f5(slab) [ 10.889148][ C2] raw: 0080000000000240 ff1100000103d3c0 ffd4000000258810 ffd4000000410e10 [ 10.889308][ C2] raw: ff110000103d1000 0000000000020001 00000000f5000000 0000000000000000 [ 10.889464][ C2] head: 0080000000000240 ff1100000103d3c0 ffd4000000258810 ffd4000000410e10 [ 10.889624][ C2] head: ff110000103d1000 0000000000020001 00000000f5000000 0000000000000000 [ 10.889784][ C2] head: 0080000000000003 fffffffffffffe01 00000000ffffffff 00000000ffffffff [ 10.889938][ C2] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 10.890094][ C2] page dumped because: kasan: bad access detected [ 10.890204][ C2] [ 10.890251][ C2] Memory state around the buggy address: [ 10.890339][ C2] ff110000103d6e80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 10.890472][ C2] ff110000103d6f00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 10.890602][ C2] >ff110000103d6f80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 10.890735][ C2] ^ [ 10.890865][ C2] ff110000103d7000: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 10.890995][ C2] ff110000103d7080: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 10.891124][ C2] ================================================================== [ 10.891292][ C2] Disabling lock debugging due to kernel taint [ 10.891472][ C2] ------------[ cut here ]------------ [ 10.891602][ C2] WARNING: ./include/linux/skbuff.h:3094 at udp_tun_rx_dst+0xa9b/0x1060, CPU#2: ping/277 [ 10.891803][ C2] Modules linked in: act_mirred act_tunnel_key cls_flower bareudp mpls_gso mpls_iptunnel mpls_router sch_ingress [ 10.892047][ C2] CPU: 2 UID: 0 PID: 277 Comm: ping Tainted: G B W 7.1.0-virtme #1 PREEMPT(full) [ 10.892269][ C2] Tainted: [B]=BAD_PAGE, [W]=WARN [ 10.892400][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 10.892562][ C2] RIP: 0010:udp_tun_rx_dst+0xa9b/0x1060 [ 10.892702][ C2] Code: 6b 74 fe 4c 8b 44 24 20 49 0f ba 28 08 4c 8b 4c 24 18 e9 c0 f9 ff ff 90 0f 0b 90 e9 7d fb ff ff 90 0f 0b 90 e9 f1 f9 ff ff 90 <0f> 0b 90 e9 a7 fa ff ff 44 89 44 24 18 89 74 24 20 4c 89 4c 24 28 [ 10.893056][ C2] RSP: 0018:ffa0000000228718 EFLAGS: 00010246 [ 10.893212][ C2] RAX: 0000000000000007 RBX: 000000000000ffff RCX: 0000000000000001 [ 10.893387][ C2] RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffffb35bc6a0 [ 10.893569][ C2] RBP: ffa0000000228770 R08: ff1100000b82c1c8 R09: ff11000005826200 [ 10.893747][ C2] R10: fffffbfff66b78d5 R11: fffffbfff66b78d5 R12: ff1100000b82c1dc [ 10.893922][ C2] R13: ff1100000b82c1da R14: ff110000058262b6 R15: ff1100000b82c100 [ 10.894097][ C2] FS: 00007fa0f843d4c0(0000) GS:ff110000b8bb0000(0000) knlGS:0000000000000000 [ 10.894293][ C2] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 10.894446][ C2] CR2: 0000561e542e20a8 CR3: 00000000126bc002 CR4: 0000000000771ef0 [ 10.894635][ C2] PKRU: 55555554 [ 10.894749][ C2] Call Trace: [ 10.894857][ C2] [ 10.894945][ C2] bareudp_udp_encap_recv+0x243/0x1847 [bareudp] [ 10.895098][ C2] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 10.895229][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.895401][ C2] ? __udp4_lib_lookup+0x5f1/0x820 [ 10.895552][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.895711][ C2] udp_queue_rcv_one_skb+0x645/0xb00 [ 10.895844][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.895975][ C2] ? print_irq_inversion_bug.part.0+0x59/0xc0 [ 10.896131][ C2] udp_unicast_rcv_skb+0x366/0x450 [ 10.896263][ C2] ? udp_rcv+0xce3/0x1e30 [ 10.896373][ C2] udp_rcv+0xd01/0x1e30 [ 10.896496][ C2] ? udp_sk_rx_dst_set+0x90/0x90 [ 10.896627][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.896767][ C2] ? ip_local_deliver_finish+0x2ba/0x610 [ 10.896899][ C2] ip_protocol_deliver_rcu+0x82/0x350 [ 10.897030][ C2] ? process_backlog+0x561/0x1490 [ 10.897161][ C2] ip_local_deliver_finish+0x36f/0x610 [ 10.897295][ C2] ? __lock_release.isra.0+0x6b/0x1a0 [ 10.897427][ C2] ip_local_deliver+0x184/0x4c0 [ 10.897570][ C2] ? ip_local_deliver_finish+0x610/0x610 [ 10.897704][ C2] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 10.897836][ C2] ? process_backlog+0x561/0x1490 [ 10.897966][ C2] ip_rcv+0xdc/0x3d0 [ 10.898077][ C2] ? ip_local_deliver+0x4c0/0x4c0 [ 10.898208][ C2] ? mark_usage+0x61/0x170 [ 10.898342][ C2] ? __lock_acquire+0x518/0xc20 [ 10.898485][ C2] ? __dev_queue_xmit+0x1077/0x1b70 [ 10.898616][ C2] __netif_receive_skb_one_core+0xfc/0x180 [ 10.898776][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.898907][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 10.899060][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.899191][ C2] process_backlog+0x2bc/0x1490 [ 10.899327][ C2] __napi_poll+0xa7/0x3b0 [ 10.899437][ C2] net_rx_action+0x513/0xf50 [ 10.899579][ C2] ? __napi_poll+0x3b0/0x3b0 [ 10.899718][ C2] ? trace_rcu_this_gp.isra.0+0x1b6/0x3c0 [ 10.899850][ C2] ? trace_rcu_quiescent_state_report+0xf2/0x330 [ 10.900002][ C2] ? find_held_lock+0x2b/0x80 [ 10.900133][ C2] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 10.900287][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.900418][ C2] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 10.900580][ C2] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 10.900741][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.900871][ C2] ? mark_held_locks+0x40/0x70 [ 10.901003][ C2] handle_softirqs+0x1d8/0x8f0 [ 10.901134][ C2] ? _local_bh_enable+0xd0/0xd0 [ 10.901269][ C2] do_softirq+0xa9/0xe0 [ 10.901378][ C2] [ 10.901474][ C2] [ 10.901561][ C2] __local_bh_enable_ip+0x113/0x140 [ 10.901701][ C2] __neigh_event_send+0x30a/0x1070 [ 10.901833][ C2] ? lockdep_hardirqs_on+0x21/0x130 [ 10.901966][ C2] ? sync_exp_reset_tree_hotplug+0x3f0/0x3f0 [ 10.902117][ C2] neigh_resolve_output+0xbe/0x140 [ 10.902252][ C2] ip_finish_output2+0x684/0x1c60 [ 10.902384][ C2] ? ip_dst_mtu_maybe_forward+0x2c7/0x720 [ 10.902527][ C2] ? ip4_dst_hoplimit+0x320/0x320 [ 10.902657][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.902797][ C2] ip_output+0x1ca/0x660 [ 10.902908][ C2] ? ip_finish_output+0x460/0x460 [ 10.903038][ C2] ? __ip_make_skb+0x106a/0x2300 [ 10.903171][ C2] ip_push_pending_frames+0xf6/0x250 [ 10.903306][ C2] raw_sendmsg+0x11f3/0x1b00 [ 10.903437][ C2] ? mark_lock+0x980/0xa00 [ 10.903577][ C2] ? raw_send_hdrinc+0x1740/0x1740 [ 10.903716][ C2] ? folio_add_lru_vma+0x1a1/0x250 [ 10.903847][ C2] ? rcu_lockdep_current_cpu_online+0x39/0x1b0 [ 10.904000][ C2] ? rcu_read_unlock+0x1b/0x70 [ 10.904131][ C2] ? wp_page_copy+0x741/0x10d0 [ 10.904264][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.904396][ C2] ? __might_fault+0x97/0x140 [ 10.904540][ C2] ? __might_fault+0x97/0x140 [ 10.904678][ C2] ? __might_fault+0x97/0x140 [ 10.904810][ C2] __sys_sendto+0x2aa/0x3e0 [ 10.904942][ C2] ? __ia32_sys_getpeername+0xd0/0xd0 [ 10.905073][ C2] ? __lock_release.isra.0+0xb3/0x1a0 [ 10.905208][ C2] ? exc_page_fault+0x87/0x100 [ 10.905339][ C2] __x64_sys_sendto+0xe4/0x1f0 [ 10.905481][ C2] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 10.905634][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.905770][ C2] ? do_syscall_64+0x82/0x590 [ 10.905901][ C2] do_syscall_64+0x117/0x590 [ 10.906032][ C2] ? trace_hardirqs_off+0xd/0x30 [ 10.906163][ C2] ? exc_page_fault+0xee/0x100 [ 10.906297][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 10.906449][ C2] RIP: 0033:0x7fa0f865b64e [ 10.906594][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 10.906949][ C2] RSP: 002b:00007ffdd4501190 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 10.907125][ C2] RAX: ffffffffffffffda RBX: 0000000000000040 RCX: 00007fa0f865b64e [ 10.907298][ C2] RDX: 0000000000000040 RSI: 0000561e542d20a4 RDI: 0000000000000005 [ 10.907481][ C2] RBP: 00007ffdd45011a0 R08: 0000561e542e4320 R09: 0000000000000010 [ 10.907655][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 431bde82d7b634db [ 10.907837][ C2] R13: 0000000000000000 R14: 0000561e542e53e0 R15: 0000561e542d20a0 [ 10.908014][ C2] [ 10.908122][ C2] irq event stamp: 39584 [ 10.908230][ C2] hardirqs last enabled at (39584): [] irqentry_exit+0x21c/0x790 [ 10.908426][ C2] hardirqs last disabled at (39583): [] common_interrupt+0x17/0xf0 [ 10.908634][ C2] softirqs last enabled at (37490): [] __neigh_event_send+0x305/0x1070 [ 10.908834][ C2] softirqs last disabled at (37491): [] do_softirq+0xa9/0xe0 [ 10.909028][ C2] ---[ end trace 0000000000000000 ]--- [ 10.909173][ C2] ------------[ cut here ]------------ [ 10.909301][ C2] WARNING: ./include/linux/skbuff.h:3094 at udp_tun_rx_dst+0xa89/0x1060, CPU#2: ping/277 [ 10.909505][ C2] Modules linked in: act_mirred act_tunnel_key cls_flower bareudp mpls_gso mpls_iptunnel mpls_router sch_ingress [ 10.909755][ C2] CPU: 2 UID: 0 PID: 277 Comm: ping Tainted: G B W 7.1.0-virtme #1 PREEMPT(full) [ 10.909974][ C2] Tainted: [B]=BAD_PAGE, [W]=WARN [ 10.910104][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 10.910257][ C2] RIP: 0010:udp_tun_rx_dst+0xa89/0x1060 [ 10.910391][ C2] Code: c7 be 08 00 00 00 4c 89 4c 24 18 4c 89 44 24 20 e8 4c 6b 74 fe 4c 8b 44 24 20 49 0f ba 28 08 4c 8b 4c 24 18 e9 c0 f9 ff ff 90 <0f> 0b 90 e9 7d fb ff ff 90 0f 0b 90 e9 f1 f9 ff ff 90 0f 0b 90 e9 [ 10.910754][ C2] RSP: 0018:ffa0000000228718 EFLAGS: 00010246 [ 10.910911][ C2] RAX: 0000000000000007 RBX: 000000000000ffff RCX: ffffffffb0a31c3e [ 10.911083][ C2] RDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000000 [ 10.911257][ C2] RBP: ffa0000000228770 R08: ff1100000b82c1c8 R09: ff11000005826200 [ 10.911429][ C2] R10: fffffbfff66b78d5 R11: fffffbfff66b78d5 R12: ff1100000b82c1dc [ 10.911616][ C2] R13: ff1100000b82c1da R14: ff110000058262b6 R15: ff1100000b82c100 [ 10.911799][ C2] FS: 00007fa0f843d4c0(0000) GS:ff110000b8bb0000(0000) knlGS:0000000000000000 [ 10.911996][ C2] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 10.912149][ C2] CR2: 0000561e542e20a8 CR3: 00000000126bc002 CR4: 0000000000771ef0 [ 10.912324][ C2] PKRU: 55555554 [ 10.912435][ C2] Call Trace: [ 10.912551][ C2] [ 10.912639][ C2] bareudp_udp_encap_recv+0x243/0x1847 [bareudp] [ 10.912795][ C2] ? udp_lib_lport_inuse2+0x3d0/0x3d0 [ 10.912927][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.913080][ C2] ? __udp4_lib_lookup+0x5f1/0x820 [ 10.913213][ C2] ? bareudp_newlink+0xb70/0xb70 [bareudp] [ 10.913366][ C2] udp_queue_rcv_one_skb+0x645/0xb00 [ 10.913512][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.913644][ C2] ? print_irq_inversion_bug.part.0+0x59/0xc0 [ 10.913805][ C2] udp_unicast_rcv_skb+0x366/0x450 [ 10.913938][ C2] ? udp_rcv+0xce3/0x1e30 [ 10.914048][ C2] udp_rcv+0xd01/0x1e30 [ 10.914159][ C2] ? udp_sk_rx_dst_set+0x90/0x90 [ 10.914290][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.914423][ C2] ? ip_local_deliver_finish+0x2ba/0x610 [ 10.914566][ C2] ip_protocol_deliver_rcu+0x82/0x350 [ 10.914704][ C2] ? process_backlog+0x561/0x1490 [ 10.914836][ C2] ip_local_deliver_finish+0x36f/0x610 [ 10.914967][ C2] ? __lock_release.isra.0+0x6b/0x1a0 [ 10.915097][ C2] ip_local_deliver+0x184/0x4c0 [ 10.915230][ C2] ? ip_local_deliver_finish+0x610/0x610 [ 10.915361][ C2] ? ip_rcv_finish_core+0x6ed/0x14c0 [ 10.915504][ C2] ? process_backlog+0x561/0x1490 [ 10.915636][ C2] ip_rcv+0xdc/0x3d0 [ 10.915750][ C2] ? ip_local_deliver+0x4c0/0x4c0 [ 10.915881][ C2] ? mark_usage+0x61/0x170 [ 10.916012][ C2] ? __lock_acquire+0x518/0xc20 [ 10.916142][ C2] ? __dev_queue_xmit+0x1077/0x1b70 [ 10.916276][ C2] __netif_receive_skb_one_core+0xfc/0x180 [ 10.916427][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.916571][ C2] ? __netif_receive_skb_list_core+0x9e0/0x9e0 [ 10.916726][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.916857][ C2] process_backlog+0x2bc/0x1490 [ 10.916988][ C2] __napi_poll+0xa7/0x3b0 [ 10.917098][ C2] net_rx_action+0x513/0xf50 [ 10.917232][ C2] ? __napi_poll+0x3b0/0x3b0 [ 10.917365][ C2] ? trace_rcu_this_gp.isra.0+0x1b6/0x3c0 [ 10.917505][ C2] ? trace_rcu_quiescent_state_report+0xf2/0x330 [ 10.917657][ C2] ? find_held_lock+0x2b/0x80 [ 10.917795][ C2] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 10.917946][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.918076][ C2] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 10.918232][ C2] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 10.918383][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.918526][ C2] ? mark_held_locks+0x40/0x70 [ 10.918659][ C2] handle_softirqs+0x1d8/0x8f0 [ 10.918798][ C2] ? _local_bh_enable+0xd0/0xd0 [ 10.918929][ C2] do_softirq+0xa9/0xe0 [ 10.919041][ C2] [ 10.919127][ C2] [ 10.919215][ C2] __local_bh_enable_ip+0x113/0x140 [ 10.919346][ C2] __neigh_event_send+0x30a/0x1070 [ 10.919486][ C2] ? lockdep_hardirqs_on+0x21/0x130 [ 10.919618][ C2] ? sync_exp_reset_tree_hotplug+0x3f0/0x3f0 [ 10.919777][ C2] neigh_resolve_output+0xbe/0x140 [ 10.919909][ C2] ip_finish_output2+0x684/0x1c60 [ 10.920042][ C2] ? ip_dst_mtu_maybe_forward+0x2c7/0x720 [ 10.920175][ C2] ? ip4_dst_hoplimit+0x320/0x320 [ 10.920306][ C2] ? rcu_is_watching+0x15/0xd0 [ 10.920437][ C2] ip_output+0x1ca/0x660 [ 10.920555][ C2] ? ip_finish_output+0x460/0x460 [ 10.920692][ C2] ? __ip_make_skb+0x106a/0x2300 [ 10.920827][ C2] ip_push_pending_frames+0xf6/0x250 [ 10.920958][ C2] raw_sendmsg+0x11f3/0x1b00 [ 10.921090][ C2] ? mark_lock+0x980/0xa00 [ 10.921221][ C2] ? raw_send_hdrinc+0x1740/0x1740 [ 10.921352][ C2] ? folio_add_lru_vma+0x1a1/0x250 [ 10.921491][ C2] ? rcu_lockdep_current_cpu_online+0x39/0x1b0 [ 10.921643][ C2] ? rcu_read_unlock+0x1b/0x70 [ 10.921785][ C2] ? wp_page_copy+0x741/0x10d0 [ 10.921918][ C2] ? lock_acquire.part.0+0xbc/0x260 [ 10.922052][ C2] ? __might_fault+0x97/0x140 [ 10.922183][ C2] ? __might_fault+0x97/0x140 [ 10.922314][ C2] ? __might_fault+0x97/0x140 [ 10.922445][ C2] __sys_sendto+0x2aa/0x3e0 [ 10.922589][ C2] ? __ia32_sys_getpeername+0xd0/0xd0 [ 10.922724][ C2] ? __lock_release.isra.0+0xb3/0x1a0 [ 10.922856][ C2] ? exc_page_fault+0x87/0x100 [ 10.922987][ C2] __x64_sys_sendto+0xe4/0x1f0 [ 10.923121][ C2] ? trace_irq_enable.constprop.0+0x9b/0x160 [ 10.923272][ C2] ? lockdep_hardirqs_on+0x8c/0x130 [ 10.923406][ C2] ? do_syscall_64+0x82/0x590 [ 10.923547][ C2] do_syscall_64+0x117/0x590 [ 10.923683][ C2] ? trace_hardirqs_off+0xd/0x30 [ 10.923813][ C2] ? exc_page_fault+0xee/0x100 [ 10.923945][ C2] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 10.924100][ C2] RIP: 0033:0x7fa0f865b64e [ 10.924233][ C2] Code: 4d 89 d8 e8 b4 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 10.924591][ C2] RSP: 002b:00007ffdd4501190 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 10.924767][ C2] RAX: ffffffffffffffda RBX: 0000000000000040 RCX: 00007fa0f865b64e [ 10.924942][ C2] RDX: 0000000000000040 RSI: 0000561e542d20a4 RDI: 0000000000000005 [ 10.925117][ C2] RBP: 00007ffdd45011a0 R08: 0000561e542e4320 R09: 0000000000000010 [ 10.925289][ C2] R10: 0000000000000000 R11: 0000000000000202 R12: 431bde82d7b634db [ 10.925472][ C2] R13: 0000000000000000 R14: 0000561e542e53e0 R15: 0000561e542d20a0 [ 10.925648][ C2] [ 10.925766][ C2] irq event stamp: 39584 [ 10.925874][ C2] hardirqs last enabled at (39584): [] irqentry_exit+0x21c/0x790 [ 10.926067][ C2] hardirqs last disabled at (39583): [] common_interrupt+0x17/0xf0 [ 10.926261][ C2] softirqs last enabled at (37490): [] __neigh_event_send+0x305/0x1070 [ 10.926457][ C2] softirqs last disabled at (37491): [] do_softirq+0xa9/0xe0 [ 10.926672][ C2] ---[ end trace 0000000000000000 ]---