====================================== | [ 198.450055][ T2834] ================================================================== | [ 198.450400][ T2834] BUG: KASAN: null-ptr-deref in try_to_grab_pending (./arch/x86/include/asm/bitops.h:136 ./include/asm-generic/bitops/instrumented-atomic.h:72 kernel/workqueue.c:2072) | [ 198.450730][ T2834] Write of size 8 at addr 0000000000000000 by task ip/2834 | [ 198.451029][ T2834] [ 198.451147][ T2834] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 198.451152][ T2834] Call Trace: [ 198.451157][ T2834] [ 198.451160][ T2834] dump_stack_lvl (lib/dump_stack.c:123) [ 198.451182][ T2834] ? try_to_grab_pending (./arch/x86/include/asm/bitops.h:136 ./include/asm-generic/bitops/instrumented-atomic.h:72 kernel/workqueue.c:2072) [ 198.451186][ T2834] kasan_report (mm/kasan/report.c:597) [ 198.451198][ T2834] ? try_to_grab_pending (./arch/x86/include/asm/bitops.h:136 ./include/asm-generic/bitops/instrumented-atomic.h:72 kernel/workqueue.c:2072) [ 198.451203][ T2834] kasan_check_range (mm/kasan/generic.c:194 mm/kasan/generic.c:200) [ 198.451207][ T2834] try_to_grab_pending (./arch/x86/include/asm/bitops.h:136 ./include/asm-generic/bitops/instrumented-atomic.h:72 kernel/workqueue.c:2072) [ 198.451212][ T2834] __cancel_work (kernel/workqueue.c:2161 kernel/workqueue.c:4364) [ 198.451215][ T2834] ? enable_delayed_work (kernel/workqueue.c:4359) [ 198.451219][ T2834] ? queue_delayed_work_on (kernel/workqueue.c:2590) [ 198.451223][ T2834] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4472) [ 198.451232][ T2834] __cancel_work_sync (kernel/workqueue.c:4383) [ 198.451236][ T2834] __dev_close_many (net/core/dev.c:1879 (discriminator 2) net/core/dev.c:1932 (discriminator 2)) [ 198.451252][ T2834] ? netdev_notify_peers (net/core/dev.c:1891) [ 198.451256][ T2834] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/softirq.c:455) [ 198.451265][ T2834] __dev_change_flags (./include/linux/list.h:119 ./include/linux/list.h:223 ./include/linux/list.h:237 net/core/dev.c:1945 net/core/dev.c:9924) [ 198.451268][ T2834] ? __free_zapped_classes (kernel/locking/lockdep.c:5343) [ 198.451278][ T2834] ? netif_set_allmulti (net/core/dev.c:9890) [ 198.451283][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.451292][ T2834] netif_change_flags (net/core/dev.c:9989) [ 198.451296][ T2834] do_setlink.constprop.0 (net/core/rtnetlink.c:3158) [ 198.451304][ T2834] ? rtnl_newlink_create (net/core/rtnetlink.c:3036) [ 198.451310][ T2834] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 198.451320][ T2834] ? validate_chain (kernel/locking/lockdep.c:3801 kernel/locking/lockdep.c:3821 kernel/locking/lockdep.c:3876) [ 198.451325][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.451331][ T2834] ? __mutex_trylock_common (./arch/x86/include/asm/atomic64_64.h:101 ./include/linux/atomic/atomic-arch-fallback.h:4296 ./include/linux/atomic/atomic-long.h:1482 ./include/linux/atomic/atomic-instrumented.h:4458 kernel/locking/mutex.c:113) [ 198.451335][ T2834] ? __mutex_handoff (kernel/locking/mutex.c:88) [ 198.451338][ T2834] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:751) [ 198.451346][ T2834] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:751) [ 198.451349][ T2834] ? trace_contention_end (./include/trace/events/lock.h:122 (discriminator 21)) [ 198.451353][ T2834] ? __mutex_lock (./arch/x86/include/asm/preempt.h:104 kernel/locking/mutex.c:739 kernel/locking/mutex.c:760) [ 198.451362][ T2834] ? __create_object (mm/kmemleak.c:786) [ 198.451370][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.451373][ T2834] ? rtnl_newlink (net/core/rtnetlink.c:343 net/core/rtnetlink.c:4071) [ 198.451376][ T2834] ? ww_mutex_lock (kernel/locking/mutex.c:759) [ 198.451379][ T2834] ? trace_cap_capable (./include/trace/events/capability.h:26 (discriminator 21)) [ 198.451392][ T2834] ? __rtnl_newlink (net/core/rtnetlink.c:3922) [ 198.451397][ T2834] rtnl_newlink (net/core/rtnetlink.c:351 net/core/rtnetlink.c:4073) [ 198.451402][ T2834] ? __rtnl_newlink (net/core/rtnetlink.c:3963) [ 198.451405][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.451411][ T2834] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 198.451415][ T2834] ? rtnetlink_rcv_msg (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:897 net/core/rtnetlink.c:6956) [ 198.451417][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.451422][ T2834] ? __rtnl_newlink (net/core/rtnetlink.c:3963) [ 198.451425][ T2834] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958) [ 198.451429][ T2834] ? rtnl_port_fill (net/core/rtnetlink.c:6861) [ 198.451432][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.451439][ T2834] netlink_rcv_skb (net/netlink/af_netlink.c:2550) [ 198.451448][ T2834] ? rtnl_port_fill (net/core/rtnetlink.c:6861) [ 198.451452][ T2834] ? netlink_ack (net/netlink/af_netlink.c:2527) [ 198.451458][ T2834] ? netlink_deliver_tap (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:897 net/netlink/af_netlink.c:340) [ 198.451462][ T2834] ? netlink_deliver_tap (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:897 ./include/net/netns/generic.h:48 net/netlink/af_netlink.c:333) [ 198.451466][ T2834] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) [ 198.451470][ T2834] ? netlink_attachskb (net/netlink/af_netlink.c:1329) [ 198.451474][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.451480][ T2834] netlink_sendmsg (net/netlink/af_netlink.c:1894) [ 198.451485][ T2834] ? netlink_unicast (net/netlink/af_netlink.c:1813) [ 198.451488][ T2834] ? __import_iovec (lib/iov_iter.c:1346 lib/iov_iter.c:1361) [ 198.451502][ T2834] ? netlink_unicast (net/netlink/af_netlink.c:1813) [ 198.451506][ T2834] ____sys_sendmsg (net/socket.c:727 net/socket.c:742 net/socket.c:2630) [ 198.451517][ T2834] ? get_timestamp.constprop.0 (net/socket.c:2576) [ 198.451520][ T2834] ? __copy_msghdr (net/socket.c:2556) [ 198.451528][ T2834] ___sys_sendmsg (net/socket.c:2686) [ 198.451531][ T2834] ? kasan_record_aux_stack (mm/kasan/generic.c:559) [ 198.451534][ T2834] ? __call_rcu_common.constprop.0 (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:109 ./arch/x86/include/asm/irqflags.h:127 kernel/rcu/tree.c:3125) [ 198.451541][ T2834] ? copy_msghdr_from_user (net/socket.c:2673) [ 198.451546][ T2834] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 198.451551][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.451557][ T2834] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 198.451560][ T2834] ? __virt_addr_valid (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:979 ./include/linux/mmzone.h:2197 arch/x86/mm/physaddr.c:65) [ 198.451573][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.451580][ T2834] __sys_sendmsg (net/socket.c:2716) [ 198.451583][ T2834] ? __call_rcu_common.constprop.0 (kernel/rcu/tree.c:3148) [ 198.451587][ T2834] ? __sys_sendmsg_sock (net/socket.c:2701) [ 198.451595][ T2834] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:751) [ 198.451599][ T2834] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 198.451606][ T2834] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 198.451615][ T2834] RIP: 0033:0x7fbb901bd1d7 [ 198.451624][ T2834] Code: 0e 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 All code ======== 0: 0e (bad) 1: 00 f7 add %dh,%bh 3: d8 64 89 02 fsubs 0x2(%rcx,%rcx,4) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b9 jmp 0xffffffffffffffc9 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 2e 00 00 00 mov $0x2e,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 89 54 24 1c mov %edx,0x1c(%rsp) 3b: 48 89 74 24 10 mov %rsi,0x10(%rsp) Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 89 54 24 1c mov %edx,0x1c(%rsp) 11: 48 89 74 24 10 mov %rsi,0x10(%rsp) [ 198.451627][ T2834] RSP: 002b:00007ffed2a321d8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 198.451634][ T2834] RAX: ffffffffffffffda RBX: 00007ffed2a32900 RCX: 00007fbb901bd1d7 [ 198.451637][ T2834] RDX: 0000000000000000 RSI: 00007ffed2a32240 RDI: 0000000000000005 [ 198.451639][ T2834] RBP: 0000000000000003 R08: 0000000000000003 R09: 0000000000000078 [ 198.451641][ T2834] R10: 00007fbb900b9f60 R11: 0000000000000246 R12: 0000000000000003 [ 198.451643][ T2834] R13: 00000000691cd3eb R14: 0000000000499600 R15: 0000000000000000 | [ 198.471104][ T2834] #PF: error_code(0x0002) - not-present page | [ 198.471333][ T2834] PGD 59b7067 P4D 59b7067 PUD f172067 PMD 0 | [ 198.471575][ T2834] Oops: Oops: 0002 [#1] SMP KASAN | [ 198.472151][ T2834] Tainted: [B]=BAD_PAGE [ 198.472295][ T2834] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 198.472533][ T2834] RIP: 0010:try_to_grab_pending (./arch/x86/include/asm/bitops.h:136 ./include/asm-generic/bitops/instrumented-atomic.h:72 kernel/workqueue.c:2072) [ 198.472790][ T2834] Code: 00 41 89 c0 b8 01 00 00 00 45 85 c0 74 0f 48 83 c4 10 5b 5d 41 5c 41 5d 41 5e 41 5f c3 be 08 00 00 00 48 89 df e8 7f 7f 81 00 48 0f ba 2b 00 72 11 48 83 c4 10 31 c0 5b 5d 41 5c 41 5d 41 5e All code ======== 0: 00 41 89 add %al,-0x77(%rcx) 3: c0 b8 01 00 00 00 45 sarb $0x45,0x1(%rax) a: 85 c0 test %eax,%eax c: 74 0f je 0x1d e: 48 83 c4 10 add $0x10,%rsp 12: 5b pop %rbx 13: 5d pop %rbp 14: 41 5c pop %r12 16: 41 5d pop %r13 18: 41 5e pop %r14 1a: 41 5f pop %r15 1c: c3 ret 1d: be 08 00 00 00 mov $0x8,%esi 22: 48 89 df mov %rbx,%rdi 25: e8 7f 7f 81 00 call 0x817fa9 2a:* f0 48 0f ba 2b 00 lock btsq $0x0,(%rbx) <-- trapping instruction 30: 72 11 jb 0x43 32: 48 83 c4 10 add $0x10,%rsp 36: 31 c0 xor %eax,%eax 38: 5b pop %rbx 39: 5d pop %rbp 3a: 41 5c pop %r12 3c: 41 5d pop %r13 3e: 41 5e pop %r14 Code starting with the faulting instruction =========================================== 0: f0 48 0f ba 2b 00 lock btsq $0x0,(%rbx) 6: 72 11 jb 0x19 8: 48 83 c4 10 add $0x10,%rsp c: 31 c0 xor %eax,%eax e: 5b pop %rbx f: 5d pop %rbp 10: 41 5c pop %r12 12: 41 5d pop %r13 14: 41 5e pop %r14 [ 198.473455][ T2834] RSP: 0018:ffffc90003c96f40 EFLAGS: 00010046 [ 198.473693][ T2834] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffffaa84090a [ 198.473982][ T2834] RDX: fffffbfff5d4f2cd RSI: 0000000000000008 RDI: ffffffffaea79660 [ 198.474265][ T2834] RBP: ffffc90003c96fa8 R08: 0000000000000001 R09: fffffbfff5d4f2cc [ 198.474555][ T2834] R10: ffffffffaea79667 R11: ffffc90003c96a00 R12: 0000000000000000 [ 198.474845][ T2834] R13: 0000000000000282 R14: ffff88800be84000 R15: dffffc0000000000 [ 198.475125][ T2834] FS: 00007fbb8ffef800(0000) GS:ffff888081df2000(0000) knlGS:0000000000000000 [ 198.475451][ T2834] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 198.475692][ T2834] CR2: 0000000000000000 CR3: 000000000edad006 CR4: 0000000000772ef0 [ 198.475978][ T2834] PKRU: 55555554 [ 198.476117][ T2834] Call Trace: [ 198.476260][ T2834] [ 198.476360][ T2834] __cancel_work (kernel/workqueue.c:2161 kernel/workqueue.c:4364) [ 198.476569][ T2834] ? enable_delayed_work (kernel/workqueue.c:4359) [ 198.476766][ T2834] ? queue_delayed_work_on (kernel/workqueue.c:2590) [ 198.476952][ T2834] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4472) [ 198.477148][ T2834] __cancel_work_sync (kernel/workqueue.c:4383) [ 198.477335][ T2834] __dev_close_many (net/core/dev.c:1879 (discriminator 2) net/core/dev.c:1932 (discriminator 2)) [ 198.477526][ T2834] ? netdev_notify_peers (net/core/dev.c:1891) [ 198.477715][ T2834] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/softirq.c:455) [ 198.477911][ T2834] __dev_change_flags (./include/linux/list.h:119 ./include/linux/list.h:223 ./include/linux/list.h:237 net/core/dev.c:1945 net/core/dev.c:9924) [ 198.478097][ T2834] ? __free_zapped_classes (kernel/locking/lockdep.c:5343) [ 198.478287][ T2834] ? netif_set_allmulti (net/core/dev.c:9890) [ 198.478475][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.478663][ T2834] netif_change_flags (net/core/dev.c:9989) [ 198.478848][ T2834] do_setlink.constprop.0 (net/core/rtnetlink.c:3158) [ 198.479040][ T2834] ? rtnl_newlink_create (net/core/rtnetlink.c:3036) [ 198.479225][ T2834] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 198.479417][ T2834] ? validate_chain (kernel/locking/lockdep.c:3801 kernel/locking/lockdep.c:3821 kernel/locking/lockdep.c:3876) [ 198.479604][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.479800][ T2834] ? __mutex_trylock_common (./arch/x86/include/asm/atomic64_64.h:101 ./include/linux/atomic/atomic-arch-fallback.h:4296 ./include/linux/atomic/atomic-long.h:1482 ./include/linux/atomic/atomic-instrumented.h:4458 kernel/locking/mutex.c:113) [ 198.479985][ T2834] ? __mutex_handoff (kernel/locking/mutex.c:88) [ 198.480169][ T2834] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:751) [ 198.480356][ T2834] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:751) [ 198.480541][ T2834] ? trace_contention_end (./include/trace/events/lock.h:122 (discriminator 21)) [ 198.480725][ T2834] ? __mutex_lock (./arch/x86/include/asm/preempt.h:104 kernel/locking/mutex.c:739 kernel/locking/mutex.c:760) [ 198.480922][ T2834] ? __create_object (mm/kmemleak.c:786) [ 198.481132][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.481324][ T2834] ? rtnl_newlink (net/core/rtnetlink.c:343 net/core/rtnetlink.c:4071) [ 198.481507][ T2834] ? ww_mutex_lock (kernel/locking/mutex.c:759) [ 198.481693][ T2834] ? trace_cap_capable (./include/trace/events/capability.h:26 (discriminator 21)) [ 198.481888][ T2834] ? __rtnl_newlink (net/core/rtnetlink.c:3922) [ 198.482074][ T2834] rtnl_newlink (net/core/rtnetlink.c:351 net/core/rtnetlink.c:4073) [ 198.482260][ T2834] ? __rtnl_newlink (net/core/rtnetlink.c:3963) [ 198.482446][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.482630][ T2834] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 198.482828][ T2834] ? rtnetlink_rcv_msg (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:897 net/core/rtnetlink.c:6956) [ 198.483012][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.483197][ T2834] ? __rtnl_newlink (net/core/rtnetlink.c:3963) [ 198.483383][ T2834] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958) [ 198.483569][ T2834] ? rtnl_port_fill (net/core/rtnetlink.c:6861) [ 198.483756][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.483946][ T2834] netlink_rcv_skb (net/netlink/af_netlink.c:2550) [ 198.484131][ T2834] ? rtnl_port_fill (net/core/rtnetlink.c:6861) [ 198.484326][ T2834] ? netlink_ack (net/netlink/af_netlink.c:2527) [ 198.484514][ T2834] ? netlink_deliver_tap (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:897 net/netlink/af_netlink.c:340) [ 198.484717][ T2834] ? netlink_deliver_tap (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:897 ./include/net/netns/generic.h:48 net/netlink/af_netlink.c:333) [ 198.484914][ T2834] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) [ 198.485102][ T2834] ? netlink_attachskb (net/netlink/af_netlink.c:1329) [ 198.485286][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.485474][ T2834] netlink_sendmsg (net/netlink/af_netlink.c:1894) [ 198.485667][ T2834] ? netlink_unicast (net/netlink/af_netlink.c:1813) [ 198.485854][ T2834] ? __import_iovec (lib/iov_iter.c:1346 lib/iov_iter.c:1361) [ 198.486042][ T2834] ? netlink_unicast (net/netlink/af_netlink.c:1813) [ 198.486229][ T2834] ____sys_sendmsg (net/socket.c:727 net/socket.c:742 net/socket.c:2630) [ 198.486416][ T2834] ? get_timestamp.constprop.0 (net/socket.c:2576) [ 198.486655][ T2834] ? __copy_msghdr (net/socket.c:2556) [ 198.486848][ T2834] ___sys_sendmsg (net/socket.c:2686) [ 198.487033][ T2834] ? kasan_record_aux_stack (mm/kasan/generic.c:559) [ 198.487227][ T2834] ? __call_rcu_common.constprop.0 (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:109 ./arch/x86/include/asm/irqflags.h:127 kernel/rcu/tree.c:3125) [ 198.487463][ T2834] ? copy_msghdr_from_user (net/socket.c:2673) [ 198.487653][ T2834] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 198.487844][ T2834] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 198.488034][ T2834] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 198.488217][ T2834] ? __virt_addr_valid (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:979 ./include/linux/mmzone.h:2197 arch/x86/mm/physaddr.c:65) [ 198.488406][ T2834] ? __lock_release (kernel/locking/lockdep.c:5536) [ 198.488597][ T2834] __sys_sendmsg (net/socket.c:2716) [ 198.488787][ T2834] ? __call_rcu_common.constprop.0 (kernel/rcu/tree.c:3148) [ 198.489016][ T2834] ? __sys_sendmsg_sock (net/socket.c:2701) [ 198.489206][ T2834] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:751) [ 198.489390][ T2834] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 198.489581][ T2834] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 198.489929][ T2834] RIP: 0033:0x7fbb901bd1d7 [ 198.490135][ T2834] Code: 0e 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 All code ======== 0: 0e (bad) 1: 00 f7 add %dh,%bh 3: d8 64 89 02 fsubs 0x2(%rcx,%rcx,4) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b9 jmp 0xffffffffffffffc9 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 2e 00 00 00 mov $0x2e,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 89 54 24 1c mov %edx,0x1c(%rsp) 3b: 48 89 74 24 10 mov %rsi,0x10(%rsp) Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 89 54 24 1c mov %edx,0x1c(%rsp) 11: 48 89 74 24 10 mov %rsi,0x10(%rsp) [ 198.490920][ T2834] RSP: 002b:00007ffed2a321d8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 198.491201][ T2834] RAX: ffffffffffffffda RBX: 00007ffed2a32900 RCX: 00007fbb901bd1d7 [ 198.491484][ T2834] RDX: 0000000000000000 RSI: 00007ffed2a32240 RDI: 0000000000000005 [ 198.491873][ T2834] RBP: 0000000000000003 R08: 0000000000000003 R09: 0000000000000078 [ 198.492157][ T2834] R10: 00007fbb900b9f60 R11: 0000000000000246 R12: 0000000000000003 Finger prints: try_to_grab_pending:__cancel_work:__cancel_work_sync:__dev_close_many:__dev_change_flags kasan_report:kasan_check_range:try_to_grab_pending:__cancel_work:__cancel_work_sync