[ 645.802042][T11020] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 645.802471][T11014] devlink (11014) used greatest stack depth: 22544 bytes left [ 645.807894][T11022] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 645.813075][T11018] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 645.816847][T11016] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 649.115416][T11104] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 649.158342][T11105] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 649.164556][T11107] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 649.171131][T11098] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 649.388713][T11104] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 649.394946][T11099] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 649.446217][T11101] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 649.493070][T11094] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 649.821616][T11098] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 649.824802][T11101] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 649.886670][T11102] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 649.896059][T11104] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 650.234757][T11099] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 650.249760][T11098] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 650.253325][T11104] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 650.260005][T11101] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 650.687377][T11094] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 650.690790][T11098] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 650.695233][T11101] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 650.708628][T11104] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 651.075132][T11101] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 651.078844][T11099] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 651.083621][T11098] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 651.088785][T11102] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 651.533980][T11101] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 651.538403][T11098] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 651.540808][T11099] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 651.545930][T11102] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 652.132787][T11299] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 652.154206][T11300] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 652.162713][T11306] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 652.168756][T11304] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 653.038079][T11299] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 653.040388][T11291] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 653.042611][T11295] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 653.268081][T11291] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 653.287731][T11300] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 653.298602][T11299] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 653.306140][T11304] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 653.528731][T11299] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 653.550339][T11306] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 653.580183][T11291] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 653.599289][T11292] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 654.125308][T11420] ================================================================== [ 654.125514][T11420] BUG: KASAN: slab-out-of-bounds in devlink_nl_dumpit+0x370/0x390 [ 654.125668][T11420] Read of size 8 at addr ff11000004a9cb60 by task devlink/11420 [ 654.125827][T11420] [ 654.125880][T11420] CPU: 2 UID: 0 PID: 11420 Comm: devlink Not tainted 7.0.0-rc2-virtme #1 PREEMPT(full) [ 654.125883][T11420] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 654.125885][T11420] Call Trace: [ 654.125886][T11420] [ 654.125888][T11420] dump_stack_lvl+0x6f/0xa0 [ 654.125893][T11420] print_address_description.constprop.0+0x6e/0x300 [ 654.125898][T11420] print_report+0xfc/0x1fb [ 654.125900][T11420] ? devlink_nl_dumpit+0x370/0x390 [ 654.125902][T11420] ? __virt_addr_valid+0x1da/0x430 [ 654.125906][T11420] ? devlink_nl_dumpit+0x370/0x390 [ 654.125908][T11420] kasan_report+0xe8/0x120 [ 654.125912][T11420] ? devlink_nl_dumpit+0x370/0x390 [ 654.125914][T11420] devlink_nl_dumpit+0x370/0x390 [ 654.125916][T11420] ? devlink_nl_fill+0x600/0x600 [ 654.125918][T11420] genl_dumpit+0x101/0x270 [ 654.125922][T11420] netlink_dump+0x4a1/0x13a0 [ 654.125925][T11420] ? netlink_lookup+0x1a0/0x1a0 [ 654.125929][T11420] ? __asan_memset+0x27/0x50 [ 654.125932][T11420] ? genl_start+0x4ed/0x940 [ 654.125934][T11420] __netlink_dump_start+0x60d/0x890 [ 654.125937][T11420] genl_family_rcv_msg_dumpit+0x1aa/0x320 [ 654.125939][T11420] ? genl_dumpit+0x270/0x270 [ 654.125941][T11420] ? lock_acquire.part.0+0xbc/0x260 [ 654.125944][T11420] ? find_held_lock+0x2b/0x80 [ 654.125947][T11420] ? genl_cmd_full_to_split+0x9a0/0x9a0 [ 654.125949][T11420] ? genl_family_rcv_msg_doit+0x2c0/0x2c0 [ 654.125951][T11420] ? genl_release+0x180/0x180 [ 654.125953][T11420] ? genl_rcv_msg+0x130/0x130 [ 654.125955][T11420] ? is_bpf_text_address+0x72/0x110 [ 654.125958][T11420] ? kernel_text_address+0x142/0x160 [ 654.125961][T11420] genl_family_rcv_msg+0x2de/0x5b0 [ 654.125963][T11420] ? genl_family_rcv_msg_dumpit+0x320/0x320 [ 654.125965][T11420] ? rcu_lockdep_current_cpu_online+0x39/0x1b0 [ 654.125969][T11420] ? devlink_nl_get_doit+0x1d0/0x1d0 [ 654.125971][T11420] ? __lock_acquire+0x577/0xc10 [ 654.125973][T11420] genl_rcv_msg+0xa3/0x130 [ 654.125975][T11420] netlink_rcv_skb+0x123/0x380 [ 654.125977][T11420] ? genl_family_rcv_msg+0x5b0/0x5b0 [ 654.125979][T11420] ? netlink_ack+0xcc0/0xcc0 [ 654.125983][T11420] ? netlink_deliver_tap+0xc5/0x330 [ 654.125984][T11420] ? netlink_deliver_tap+0x13f/0x330 [ 654.125987][T11420] genl_rcv+0x28/0x40 [ 654.125988][T11420] netlink_unicast+0x4a3/0x770 [ 654.125991][T11420] ? netlink_attachskb+0x810/0x810 [ 654.125993][T11420] ? __alloc_skb+0x4c7/0x5f0 [ 654.125995][T11420] ? napi_skb_cache_get+0x7a0/0x7a0 [ 654.125997][T11420] ? __lock_acquire+0x577/0xc10 [ 654.125999][T11420] netlink_sendmsg+0x735/0xc60 [ 654.126001][T11420] ? netlink_unicast+0x770/0x770 [ 654.126003][T11420] ? __might_fault+0x97/0x140 [ 654.126007][T11420] ? __might_fault+0x97/0x140 [ 654.126009][T11420] __sys_sendto+0x265/0x390 [ 654.126012][T11420] ? __ia32_sys_getpeername+0xd0/0xd0 [ 654.126018][T11420] ? exc_page_fault+0x6f/0xd0 [ 654.126022][T11420] __x64_sys_sendto+0xe4/0x1f0 [ 654.126025][T11420] ? trace_irq_enable.constprop.0+0x13c/0x190 [ 654.126028][T11420] ? lockdep_hardirqs_on+0x84/0x130 [ 654.126029][T11420] ? do_syscall_64+0x87/0xfc0 [ 654.126031][T11420] do_syscall_64+0x117/0xfc0 [ 654.126032][T11420] ? exc_page_fault+0xaf/0xd0 [ 654.126034][T11420] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 654.126036][T11420] RIP: 0033:0x7f4418339c5e [ 654.126039][T11420] Code: 4d 89 d8 e8 34 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 13 ff ff ff 0f 1f 00 f3 0f 1e fa [ 654.126041][T11420] RSP: 002b:00007ffedae185e0 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 654.126045][T11420] RAX: ffffffffffffffda RBX: 0000000028476310 RCX: 00007f4418339c5e [ 654.126047][T11420] RDX: 0000000000000014 RSI: 0000000028476530 RDI: 0000000000000005 [ 654.126047][T11420] RBP: 00007ffedae185f0 R08: 00007f44185c4980 R09: 000000000000000c [ 654.126048][T11420] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000407ef0 [ 654.126049][T11420] R13: 0000000028476310 R14: 0000000000000000 R15: 0000000000000001 [ 654.126052][T11420] [ 654.126053][T11420] [ 654.133473][T11420] Allocated by task 11420: [ 654.133569][T11420] kasan_save_stack+0x30/0x50 [ 654.133669][T11420] kasan_save_track+0x14/0x30 [ 654.133764][T11420] __kasan_kmalloc+0x7b/0x90 [ 654.133858][T11420] __kmalloc_noprof+0x2a8/0x730 [ 654.133954][T11420] genl_family_rcv_msg_attrs_parse.isra.0+0xa0/0x2c0 [ 654.134073][T11420] genl_start+0x14a/0x940 [ 654.134145][T11420] __netlink_dump_start+0x562/0x890 [ 654.134240][T11420] genl_family_rcv_msg_dumpit+0x1aa/0x320 [ 654.134335][T11420] genl_family_rcv_msg+0x2de/0x5b0 [ 654.134434][T11420] genl_rcv_msg+0xa3/0x130 [ 654.134531][T11420] netlink_rcv_skb+0x123/0x380 [ 654.134626][T11420] genl_rcv+0x28/0x40 [ 654.134697][T11420] netlink_unicast+0x4a3/0x770 [ 654.134796][T11420] netlink_sendmsg+0x735/0xc60 [ 654.134891][T11420] __sys_sendto+0x265/0x390 [ 654.134985][T11420] __x64_sys_sendto+0xe4/0x1f0 [ 654.135079][T11420] do_syscall_64+0x117/0xfc0 [ 654.135175][T11420] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 654.135306][T11420] [ 654.135358][T11420] The buggy address belongs to the object at ff11000004a9cb50 [ 654.135358][T11420] which belongs to the cache kmalloc-16 of size 16 [ 654.135599][T11420] The buggy address is located 0 bytes to the right of [ 654.135599][T11420] allocated 16-byte region [ff11000004a9cb50, ff11000004a9cb60) [ 654.135867][T11420] [ 654.135929][T11420] The buggy address belongs to the physical page: [ 654.136055][T11420] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x4a9c [ 654.136237][T11420] flags: 0x80000000000000(node=0|zone=1) [ 654.136338][T11420] page_type: f5(slab) [ 654.136420][T11420] raw: 0080000000000000 ff1100000103c7c0 ffd400000012a090 ffd4000000073ed0 [ 654.136602][T11420] raw: 0000000000000000 0000000000190019 00000000f5000000 0000000000000000 [ 654.136783][T11420] page dumped because: kasan: bad access detected [ 654.136913][T11420] [ 654.136966][T11420] Memory state around the buggy address: [ 654.137064][T11420] ff11000004a9ca00: fc fc fa fb fc fc fc fc fc fc fc fc fc fc fc fc [ 654.137212][T11420] ff11000004a9ca80: fc fc fc fc fc fc fa fb fc fc fc fc fc fc fc fc [ 654.137385][T11420] >ff11000004a9cb00: fc fc fc fc fc fc fc fc fc fc 00 00 fc fc fc fc [ 654.137526][T11420] ^ [ 654.137671][T11420] ff11000004a9cb80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc 00 00 [ 654.137808][T11420] ff11000004a9cc00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 654.137946][T11420] ================================================================== [ 654.138571][T11420] Disabling lock debugging due to kernel taint [ 654.166927][T11306] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 654.173259][T11295] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 654.176174][T11299] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 654.183926][T11304] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 656.873146][T11681] Failed to register fib notifier [ 656.967110][T11655] netdevsim netdevsim10 eni10np4: renamed from eth3 [ 656.970234][T11654] netdevsim netdevsim10 eni10np3: renamed from eth2 [ 656.973317][T11652] netdevsim netdevsim10 eni10np2: renamed from eth1 [ 656.978056][T11653] netdevsim netdevsim10 eni10np1: renamed from eth0 [ 660.913842][T12140] netdevsim netdevsim10 eni10npf0vf0: renamed from eth0 [ 660.915895][T12141] netdevsim netdevsim10 eni10npf0vf1: renamed from eth1 [ 660.923817][T12143] netdevsim netdevsim10 eni10npf0vf3: renamed from eth3 [ 660.938098][T12142] netdevsim netdevsim10 eni10npf0vf2: renamed from eth2