[ 217.594661][ T3498] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 217.600949][ T3496] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 217.605170][ T3494] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 217.607695][ T3492] devlink (3492) used greatest stack depth: 22512 bytes left [ 217.611068][ T3500] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 220.815036][ T3581] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 220.823811][ T3582] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 220.831517][ T3583] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 220.879414][ T3580] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 221.154213][ T3563] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 221.161544][ T3582] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 221.162945][ T3570] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 221.167181][ T3573] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 221.554873][ T3570] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 221.556629][ T3582] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 221.568356][ T3573] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 221.569539][ T3577] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 221.925010][ T3582] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 221.928390][ T3571] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 221.936386][ T3570] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 221.941624][ T3577] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 222.417418][ T3573] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 222.425001][ T3571] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 222.432036][ T3577] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 222.490362][ T3582] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 222.861696][ T3570] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 222.872629][ T3577] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 222.875493][ T3571] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 222.880609][ T3582] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 223.314512][ T3571] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 223.322401][ T3582] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 223.330483][ T3573] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 223.426405][ T3577] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 223.849134][ T3762] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 223.858277][ T3764] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 224.014105][ T3754] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 224.030126][ T3766] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 224.862490][ T3764] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 224.869894][ T3756] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 224.878562][ T3766] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 224.889248][ T3754] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 225.151911][ T3766] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 225.154416][ T3756] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 225.377095][ T3764] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 225.414292][ T3756] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 225.479178][ T3754] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 225.485780][ T3766] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 225.878263][ T3901] ================================================================== [ 225.878443][ T3901] BUG: KASAN: slab-out-of-bounds in devlink_nl_dumpit+0x370/0x390 [ 225.878584][ T3901] Read of size 8 at addr ff11000005135d40 by task devlink/3901 [ 225.878719][ T3901] [ 225.878768][ T3901] CPU: 3 UID: 0 PID: 3901 Comm: devlink Not tainted 7.0.0-rc2-virtme #1 PREEMPT(full) [ 225.878771][ T3901] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 225.878772][ T3901] Call Trace: [ 225.878774][ T3901] [ 225.878775][ T3901] dump_stack_lvl+0x6f/0xa0 [ 225.878780][ T3901] print_address_description.constprop.0+0x6e/0x300 [ 225.878786][ T3901] print_report+0xfc/0x1fb [ 225.878787][ T3901] ? devlink_nl_dumpit+0x370/0x390 [ 225.878789][ T3901] ? __virt_addr_valid+0x1da/0x430 [ 225.878793][ T3901] ? devlink_nl_dumpit+0x370/0x390 [ 225.878795][ T3901] kasan_report+0xe8/0x120 [ 225.878799][ T3901] ? devlink_nl_dumpit+0x370/0x390 [ 225.878801][ T3901] devlink_nl_dumpit+0x370/0x390 [ 225.878803][ T3901] ? devlink_nl_fill+0x600/0x600 [ 225.878805][ T3901] genl_dumpit+0x101/0x270 [ 225.878809][ T3901] netlink_dump+0x4a1/0x13a0 [ 225.878812][ T3901] ? netlink_lookup+0x1a0/0x1a0 [ 225.878815][ T3901] ? __asan_memset+0x27/0x50 [ 225.878818][ T3901] ? genl_start+0x4ed/0x940 [ 225.878820][ T3901] __netlink_dump_start+0x60d/0x890 [ 225.878823][ T3901] genl_family_rcv_msg_dumpit+0x1aa/0x320 [ 225.878825][ T3901] ? genl_dumpit+0x270/0x270 [ 225.878827][ T3901] ? lock_acquire.part.0+0xbc/0x260 [ 225.878830][ T3901] ? find_held_lock+0x2b/0x80 [ 225.878833][ T3901] ? genl_cmd_full_to_split+0x9a0/0x9a0 [ 225.878835][ T3901] ? genl_family_rcv_msg_doit+0x2c0/0x2c0 [ 225.878837][ T3901] ? genl_release+0x180/0x180 [ 225.878838][ T3901] ? genl_rcv_msg+0x130/0x130 [ 225.878840][ T3901] ? is_bpf_text_address+0x72/0x110 [ 225.878846][ T3901] ? kernel_text_address+0x142/0x160 [ 225.878848][ T3901] genl_family_rcv_msg+0x2de/0x5b0 [ 225.878851][ T3901] ? genl_family_rcv_msg_dumpit+0x320/0x320 [ 225.878853][ T3901] ? rcu_lockdep_current_cpu_online+0x39/0x1b0 [ 225.878856][ T3901] ? devlink_nl_get_doit+0x1d0/0x1d0 [ 225.878858][ T3901] ? __lock_acquire+0x577/0xc10 [ 225.878860][ T3901] genl_rcv_msg+0xa3/0x130 [ 225.878862][ T3901] netlink_rcv_skb+0x123/0x380 [ 225.878864][ T3901] ? genl_family_rcv_msg+0x5b0/0x5b0 [ 225.878866][ T3901] ? netlink_ack+0xcc0/0xcc0 [ 225.878869][ T3901] ? netlink_deliver_tap+0xc5/0x330 [ 225.878871][ T3901] ? netlink_deliver_tap+0x13f/0x330 [ 225.878873][ T3901] genl_rcv+0x28/0x40 [ 225.878875][ T3901] netlink_unicast+0x4a3/0x770 [ 225.878877][ T3901] ? netlink_attachskb+0x810/0x810 [ 225.878879][ T3901] ? __alloc_skb+0x4c7/0x5f0 [ 225.878881][ T3901] ? napi_skb_cache_get+0x7a0/0x7a0 [ 225.878883][ T3901] ? __lock_acquire+0x577/0xc10 [ 225.878885][ T3901] netlink_sendmsg+0x735/0xc60 [ 225.878887][ T3901] ? netlink_unicast+0x770/0x770 [ 225.878889][ T3901] ? __might_fault+0x97/0x140 [ 225.878892][ T3901] ? __might_fault+0x97/0x140 [ 225.878895][ T3901] __sys_sendto+0x265/0x390 [ 225.878899][ T3901] ? __ia32_sys_getpeername+0xd0/0xd0 [ 225.878904][ T3901] ? exc_page_fault+0x6f/0xd0 [ 225.878909][ T3901] __x64_sys_sendto+0xe4/0x1f0 [ 225.878911][ T3901] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 225.878914][ T3901] ? lockdep_hardirqs_on+0x84/0x130 [ 225.878916][ T3901] ? do_syscall_64+0x87/0xfc0 [ 225.878917][ T3901] do_syscall_64+0x117/0xfc0 [ 225.878918][ T3901] ? exc_page_fault+0xaf/0xd0 [ 225.878920][ T3901] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 225.878922][ T3901] RIP: 0033:0x7f5c5eeecc5e [ 225.878925][ T3901] Code: 4d 89 d8 e8 34 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 13 ff ff ff 0f 1f 00 f3 0f 1e fa [ 225.878927][ T3901] RSP: 002b:00007ffc0f512540 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 225.878931][ T3901] RAX: ffffffffffffffda RBX: 0000000018412310 RCX: 00007f5c5eeecc5e [ 225.878933][ T3901] RDX: 0000000000000014 RSI: 0000000018412530 RDI: 0000000000000005 [ 225.878933][ T3901] RBP: 00007ffc0f512550 R08: 00007f5c5f177980 R09: 000000000000000c [ 225.878934][ T3901] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000407ef0 [ 225.878935][ T3901] R13: 0000000018412310 R14: 0000000000000000 R15: 0000000000000001 [ 225.878938][ T3901] [ 225.878939][ T3901] [ 225.885937][ T3901] Allocated by task 3901: [ 225.886020][ T3901] kasan_save_stack+0x30/0x50 [ 225.886114][ T3901] kasan_save_track+0x14/0x30 [ 225.886208][ T3901] __kasan_kmalloc+0x7b/0x90 [ 225.886303][ T3901] __kmalloc_noprof+0x2a8/0x730 [ 225.886405][ T3901] genl_family_rcv_msg_attrs_parse.isra.0+0xa0/0x2c0 [ 225.886522][ T3901] genl_start+0x14a/0x940 [ 225.886594][ T3901] __netlink_dump_start+0x562/0x890 [ 225.886687][ T3901] genl_family_rcv_msg_dumpit+0x1aa/0x320 [ 225.886778][ T3901] genl_family_rcv_msg+0x2de/0x5b0 [ 225.886867][ T3901] genl_rcv_msg+0xa3/0x130 [ 225.886965][ T3901] netlink_rcv_skb+0x123/0x380 [ 225.887061][ T3901] genl_rcv+0x28/0x40 [ 225.887131][ T3901] netlink_unicast+0x4a3/0x770 [ 225.887222][ T3901] netlink_sendmsg+0x735/0xc60 [ 225.887315][ T3901] __sys_sendto+0x265/0x390 [ 225.887416][ T3901] __x64_sys_sendto+0xe4/0x1f0 [ 225.887507][ T3901] do_syscall_64+0x117/0xfc0 [ 225.887598][ T3901] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 225.887710][ T3901] [ 225.887758][ T3901] The buggy address belongs to the object at ff11000005135d30 [ 225.887758][ T3901] which belongs to the cache kmalloc-16 of size 16 [ 225.887993][ T3901] The buggy address is located 0 bytes to the right of [ 225.887993][ T3901] allocated 16-byte region [ff11000005135d30, ff11000005135d40) [ 225.888238][ T3901] [ 225.888286][ T3901] The buggy address belongs to the physical page: [ 225.888407][ T3901] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x5135 [ 225.888572][ T3901] flags: 0x80000000000000(node=0|zone=1) [ 225.888670][ T3901] page_type: f5(slab) [ 225.888746][ T3901] raw: 0080000000000000 ff1100000103c7c0 ffd4000000143b50 ffd4000000143d10 [ 225.888913][ T3901] raw: 0000000000000000 0000000000190019 00000000f5000000 0000000000000000 [ 225.889075][ T3901] page dumped because: kasan: bad access detected [ 225.889191][ T3901] [ 225.889237][ T3901] Memory state around the buggy address: [ 225.889329][ T3901] ff11000005135c00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 225.889469][ T3901] ff11000005135c80: fc fc fa fb fc fc fc fc fc fc fc fc fc fc fc fc [ 225.889602][ T3901] >ff11000005135d00: fc fc fc fc fc fc 00 00 fc fc fc fc fc fc fc fc [ 225.889734][ T3901] ^ [ 225.889845][ T3901] ff11000005135d80: fc fc fc fc fc fc fc fc fc fc fa fb fc fc fc fc [ 225.889980][ T3901] ff11000005135e00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fa fb [ 225.890110][ T3901] ================================================================== [ 225.890250][ T3901] Disabling lock debugging due to kernel taint [ 225.926831][ T3764] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 225.935201][ T3756] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 225.943182][ T3754] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 225.944339][ T3766] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 228.599678][ T4174] Failed to register fib notifier [ 228.677832][ T4149] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 228.687238][ T4141] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 228.689285][ T4146] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 228.697318][ T4150] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 232.643358][ T4642] netdevsim netdevsim10 eni10npf0vf0: renamed from eth0 [ 232.665709][ T4647] netdevsim netdevsim10 eni10npf0vf2: renamed from eth2 [ 232.669939][ T4645] netdevsim netdevsim10 eni10npf0vf1: renamed from eth1 [ 232.680518][ T4648] netdevsim netdevsim10 eni10npf0vf3: renamed from eth3