Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp580739imu; Thu, 8 Nov 2018 12:27:39 -0800 (PST) X-Google-Smtp-Source: AJdET5fiGvnRCuAzU0X6s3AU40mBSqRlNwD1LaJ5tzXbLojz/U3IH98M89geSOSTxwA3r4oujWER X-Received: by 2002:a17:902:bf0c:: with SMTP id bi12-v6mr6147691plb.330.1541708859012; Thu, 08 Nov 2018 12:27:39 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1541708858; cv=none; d=google.com; s=arc-20160816; b=lZXgDsvrBkPEKX6DSM0Z81MALMgBK6j5rgSEeIOQ6MLvkPI1pqRaV2g41/YNAIwv9g CT3QqiZFxn6wbrwHS5FkGCQ5Y34RbIOu3I0egyeImOMnaivQu/pkQTjOEVxWsD6HxV+v 1+9VqVQSMAplI71Sz034nZmr7t35c88PaFi8eCyCECWBF0DOLX/yx+6m7DTY3NKkzslC YSY7uqFtSGHsDY79KZGIBtYGMEjd0Dv1kluw4oVN9kDU1+tV6h8TvBt5wBvWkrTeE6xK nm17lJjJObRM9PBAiMubTwkvFpeGC2ySEV2t/ik1rir+bJ0TMhaXlLCqCVx4qmEIhVYy pCuQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :date:cc:to:from:subject:message-id; bh=texLus8Y4PEUH7OnW+vukYiyZE8QkvxE9A/V967sF9c=; b=K4fO7pBNeioDmJ47FOkgtI0X8NKRmj91zTSD5LrTmt/ez+ubsbneoOTJHAZ9RNC5ea +P1aQ4GpqQy4vBzgSnbKEWYmT/jje0mgyrb7SEhNI7U0VyJdXuFM5tW3BsyD+NPzFAQz n3T3vfRLVZchE73Uodh5DTxjY44+p5fMO706ewJO6gNaqHLx++l6NTty96G4d6m041xg afI6f/csmADUbYrCtPNpbl7bp205gar5a7SV7RA2vve4Io8PNHmQhEJrem5sOCtQX16O 9iZmOlf+vNEuU1nqeiNRJBjk7+Fsens4yAs0sIUQoAxcnrUKmSzF1XIdFt+uhOXpXdPB hnlw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id 70-v6si5687563pfz.20.2018.11.08.12.27.23; Thu, 08 Nov 2018 12:27:38 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727251AbeKIGD0 (ORCPT + 99 others); Fri, 9 Nov 2018 01:03:26 -0500 Received: from mout.gmx.net ([212.227.15.15]:50305 "EHLO mout.gmx.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725723AbeKIGD0 (ORCPT ); Fri, 9 Nov 2018 01:03:26 -0500 Received: from dhcp-41-57.bos.redhat.com ([66.187.233.206]) by mail.gmx.com (mrgmx001 [212.227.17.184]) with ESMTPSA (Nemesis) id 0MQiVh-1fvvTW0Kfl-00U0zw; Thu, 08 Nov 2018 21:26:07 +0100 Message-ID: <1541708719.12945.2.camel@gmx.us> Subject: BUG: KASAN: slab-out-of-bounds in cts_cbc_encrypt+0xec/0x3c0 From: Qian Cai To: linux-kernel@vger.kernel.org Cc: Herbert Xu , "David S. Miller" , linux-crypto@vger.kernel.org Date: Thu, 08 Nov 2018 15:25:19 -0500 Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.22.6 (3.22.6-10.el7) Mime-Version: 1.0 Content-Transfer-Encoding: 8bit X-Provags-ID: V03:K1:EhR9gZcI7kOZSGMKgX86ZXq7/hCTgrDp9HCM/rpzwabldd8kSDo 9GVI8b/cqjqTJXpPzjN8OO3ggXdhmMq7rpQVsVhJPQkZN4xULhFLU1Lo0Zk9ve4f+3UBQ9f 1FGsWftafHHjSJXXuQVVPXNvXD6xVeFjlB//R0AFP79vhEzCJ1Q5cS2UfoXRkH0I+mHfALO 823i9jnWNk9XPmuv4yVIA== X-Spam-Flag: NO X-UI-Out-Filterresults: notjunk:1;V01:K0:aHDBJnjCduw=:PzeRA/dpieOlCcg+sSS0uJ tGUiHJamwObQsZAEf8VNFrl1JO50ESvW1Fbw0RB/NPsnh3LhN8gQa0CCS62PGS2EbEXF2h8MD 7HyXo8McR2lAuzQ9ei/K79mRAWZaWSCnFaDIiQmCtxDi34nFZ0MukkYAfDlw8BCo5WdEuNNR+ 6AcLjRZmzBdPvqMVp3WlkiF+kmHvUq07pJI2Fx45YJRTwJrKaHjubIFPz0zz0vwBaXh0Cg7IC IqScwxAbX7BtQDKPt9q8KSbSdMco7DSewgIEFbazyKZuHiKgO6qcwX4T+eIBpatXuPxYRN21U s+rMqdNTeVScFEHk1Zt1F3/bmNq+48aqOri0oTWiLahEMjr1BV0GTFkG41l6CJaEUpjT6Z1QL weKLMa8zYB966XbSoMpNQgeN2C52igeLPzykTfSBYmr3lbV/QCPJvOw8haLEiuP7Bdk1nu6JW AiAUsjCO9DK49S1Ld4308JLa/+Jo5q+U2pruWYvfE/L/2olI+DCjchoqV9WudJt6ob67RNFTe aLXB7tT3tlTNeOAq4/ow7n7KX4SBCWARh6tFx8NgVdEuh39rcvyAP0Nyu22tGmRFIX0bnu7/U NxC0+Qf/42A95de+HIlEsZDH5dygBxm04O0H9JEclc7xLA8uvF+aNC+jCJ3PXNmVEJsBtR7bF OirlvBJM3k4txPIpXYa1KtabsZlZebN6ahmEZmbceFkRhE8FWTbCBblF1iSYBZhfonj8v7j5Z BBpNdlueZjisjC9qkoYpIPugDhIfGgN5Ai+2+55zBDXPjezTPUcoT4S0MmaBJ/BHz7+nYRcGW kfwDOCgQCySnceKEhVCGvM9AGlliKsfO+HeMupvIS89shd4eLTdqeqokzOP+TBr204671j7pl 709jG2F78KMw5SYG1+GvxhR2E0crheBVlnicn8j7BecBzN6skz1s6Msm9CcXoF Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Just booting up the latest git master (b00d209) on an aarch64 server and saw this. [   42.448373] BUG: KASAN: slab-out-of-bounds in cts_cbc_encrypt+0xec/0x3c0 [   42.455157] Write of size 8 at addr ffff801dd06aaa40 by task cryptomgr_test/409 [   42.464065] CPU: 3 PID: 409 Comm: cryptomgr_test Tainted: G        W       T 4.20.0-rc1+ #6 [   42.472517] Hardware name: Huawei TaiShan 2280 /BC11SPCD, BIOS 1.50 06/01/2018 [   42.479826] Call trace: [   42.482306]  dump_backtrace+0x0/0x248 [   42.486014]  show_stack+0x24/0x30 [   42.489372]  dump_stack+0xb8/0xf4 [   42.492730]  print_address_description+0x68/0x2b8 [   42.497492]  kasan_report+0x22c/0x340 [   42.501199]  __asan_store8+0x90/0xa0 [   42.504818]  cts_cbc_encrypt+0xec/0x3c0 [   42.508703]  simd_skcipher_encrypt+0xc4/0x198 [   42.513115]  __test_skcipher+0x6d4/0x1030 [   42.517173]  test_skcipher+0x48/0xf0 [   42.520793]  alg_test_skcipher+0x78/0x110 [   42.524852]  alg_test.part.6+0x238/0x4e8 [   42.528823]  alg_test+0x60/0xa8 [   42.532002]  cryptomgr_test+0x5c/0x68 [   42.535710]  kthread+0x18c/0x1d0 [   42.538977]  ret_from_fork+0x10/0x18 [   42.544102] Allocated by task 409: [   42.547547]  kasan_kmalloc+0xd8/0x188 [   42.551254]  __kmalloc+0x1f8/0x470 [   42.554698]  __test_skcipher+0x18c/0x1030 [   42.558757]  test_skcipher+0x48/0xf0 [   42.562376]  alg_test_skcipher+0x78/0x110 [   42.566435]  alg_test.part.6+0x238/0x4e8 [   42.570406]  alg_test+0x60/0xa8 [   42.573586]  cryptomgr_test+0x5c/0x68 [   42.577293]  kthread+0x18c/0x1d0 [   42.580560]  ret_from_fork+0x10/0x18 [   42.585684] Freed by task 0: [   42.588597] (stack is not available) [   42.593722] The buggy address belongs to the object at ffff801dd06aa880  which belongs to the cache kmalloc-512 of size 512 [   42.606397] The buggy address is located 448 bytes inside of  512-byte region [ffff801dd06aa880, ffff801dd06aaa80) [   42.618277] The buggy address belongs to the page: [   42.623127] page:ffff7fe007741a80 count:1 mapcount:0 mapping:ffff801dc0010880 index:0xffff801dd06a5880 [   42.632548] flags: 0x1fffff0000000200(slab) [   42.636785] raw: 1fffff0000000200 ffff801dc000fac0 ffff801dc000fac0 ffff801dc0010880 [   42.644625] raw: ffff801dd06a5880 000000000040002c 00000001ffffffff 0000000000000000 [   42.652461] page dumped because: kasan: bad access detected [   42.659606] Memory state around the buggy address: [   42.664455]  ffff801dd06aa900: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [   42.671765]  ffff801dd06aa980: 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [   42.679075] >ffff801dd06aaa00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [   42.686383]                                            ^ [   42.691759]  ffff801dd06aaa80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [   42.699069]  ffff801dd06aab00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [   42.706377] ================================================================== Any idea?