==================================================================
BUG: KASAN: slab-out-of-bounds in decrypt_internal+0x15df/0x1eb0
Read of size 16 at addr ffff888149150540 by task syz-executor.1/3690

CPU: 1 PID: 3690 Comm: syz-executor.1 Tainted: G        W         5.17.0-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
Call Trace:
 <TASK>
 dump_stack_lvl+0xfc/0x174
 print_report.cold+0x2a8/0x73d
 kasan_report+0xbf/0xf0
 kasan_check_range+0x13f/0x190
 memcpy+0x1f/0x60
 decrypt_internal+0x15df/0x1eb0
 decrypt_skb_update+0x14b/0xc10
 tls_sw_recvmsg+0x69b/0x1710
 inet6_recvmsg+0x11b/0x5e0
 ____sys_recvmsg+0x2c6/0x630
 ___sys_recvmsg+0x137/0x210
 do_recvmmsg+0x259/0x6d0
 __x64_sys_recvmmsg+0x213/0x270
 do_syscall_64+0x34/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x55891be2df69
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f306367c0c8 EFLAGS: 00000246 ORIG_RAX: 000000000000012b
RAX: ffffffffffffffda RBX: 000055891bf5bf80 RCX: 000055891be2df69
RDX: 0000000000000001 RSI: 0000000020002900 RDI: 0000000000000003
RBP: 000055891be7a4a4 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 000000000000000b R14: 000055891bf5bf80 R15: 00007ffc25e30028
 </TASK>

Allocated by task 3690:
 kasan_save_stack+0x1c/0x40
 __kasan_kmalloc+0xa7/0xd0
 tls_set_sw_offload+0x817/0x13c0
 tls_setsockopt+0xaf8/0xe20
 __sys_setsockopt+0x24a/0x5e0
 __x64_sys_setsockopt+0xb9/0x150
 do_syscall_64+0x34/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae

The buggy address belongs to the object at ffff888149150540
 which belongs to the cache kmalloc-16 of size 16
The buggy address is located 0 bytes inside of
 16-byte region [ffff888149150540, ffff888149150550)

The buggy address belongs to the physical page:
page:ffffea0005245400 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x149150
flags: 0x57ff00000000200(slab|node=1|zone=2|lastcpupid=0x7ff)
raw: 057ff00000000200 dead000000000100 dead000000000122 ffff888010c413c0
raw: 0000000000000000 0000000080800080 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 0, migratetype Unmovable, gfp_mask 0x12cc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY), pid 1, tgid 1 (swapper/0), ts 11401463538, free_ts 0
 get_page_from_freelist+0x1601/0x31d0
 __alloc_pages+0x1b1/0x500
 alloc_page_interleave+0x1e/0x250
 alloc_pages+0x2aa/0x310
 allocate_slab+0x25a/0x3b0
 ___slab_alloc+0x7d7/0xef0
 __slab_alloc.constprop.0+0x4d/0xa0
 __kmalloc+0x311/0x350
 usb_hcd_submit_urb+0x6ab/0x2050
 usb_submit_urb+0x873/0x1820
 usb_start_wait_urb+0xfe/0x4c0
 usb_control_msg+0x31b/0x4a0
 usb_get_descriptor+0xbd/0x1b0
 usb_get_configuration+0x289/0x1020
 usb_new_device+0x589/0x7e0
 usb_add_hcd.cold+0x1128/0x14ee
page_owner free stack trace missing

Memory state around the buggy address:
 ffff888149150400: fb fb fc fc fb fb fc fc fb fb fc fc fb fb fc fc
 ffff888149150480: fb fb fc fc fb fb fc fc fb fb fc fc fb fb fc fc
>ffff888149150500: fb fb fc fc fb fb fc fc 00 04 fc fc 00 00 fc fc
                                              ^
 ffff888149150580: fa fb fc fc fa fb fc fc 00 00 fc fc 00 00 fc fc
 ffff888149150600: 00 00 fc fc 00 00 fc fc 00 00 fc fc 00 00 fc fc
==================================================================
