======================================
| [  330.259215] #PF: supervisor read access in kernel mode
| [  330.259249] #PF: error_code(0x0000) - not-present page
| [  330.259286] PGD 25a5067 P4D 25a5067 PUD 2978067 PMD 0
| [  330.259326] Oops: 0000 [#1] PREEMPT SMP NOPTI
[  330.259408] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[  330.259479] RIP: 0010:nh_valid_get_del_req (./include/net/netlink.h:1680 net/ipv4/nexthop.c:3235) 
[ 330.259525] Code: 11 00 75 47 8b 47 14 85 c0 75 40 48 8b 46 08 48 85 c0 0f 84 81 00 00 00 8b 40 04 89 02 85 c0 74 51 48 8b 46 70 48 85 c0 74 10 <8b> 40 04 89 01 31 c0 48 83 c4 08 c3 cc cc cc cc c7 01 00 00 00 00
All code
========
   0:	11 00                	adc    %eax,(%rax)
   2:	75 47                	jne    0x4b
   4:	8b 47 14             	mov    0x14(%rdi),%eax
   7:	85 c0                	test   %eax,%eax
   9:	75 40                	jne    0x4b
   b:	48 8b 46 08          	mov    0x8(%rsi),%rax
   f:	48 85 c0             	test   %rax,%rax
  12:	0f 84 81 00 00 00    	je     0x99
  18:	8b 40 04             	mov    0x4(%rax),%eax
  1b:	89 02                	mov    %eax,(%rdx)
  1d:	85 c0                	test   %eax,%eax
  1f:	74 51                	je     0x72
  21:	48 8b 46 70          	mov    0x70(%rsi),%rax
  25:	48 85 c0             	test   %rax,%rax
  28:	74 10                	je     0x3a
  2a:*	8b 40 04             	mov    0x4(%rax),%eax		<-- trapping instruction
  2d:	89 01                	mov    %eax,(%rcx)
  2f:	31 c0                	xor    %eax,%eax
  31:	48 83 c4 08          	add    $0x8,%rsp
  35:	c3                   	ret
  36:	cc                   	int3
  37:	cc                   	int3
  38:	cc                   	int3
  39:	cc                   	int3
  3a:	c7 01 00 00 00 00    	movl   $0x0,(%rcx)

Code starting with the faulting instruction
===========================================
   0:	8b 40 04             	mov    0x4(%rax),%eax
   3:	89 01                	mov    %eax,(%rcx)
   5:	31 c0                	xor    %eax,%eax
   7:	48 83 c4 08          	add    $0x8,%rsp
   b:	c3                   	ret
   c:	cc                   	int3
   d:	cc                   	int3
   e:	cc                   	int3
   f:	cc                   	int3
  10:	c7 01 00 00 00 00    	movl   $0x0,(%rcx)
[  330.259633] RSP: 0018:ffffb8e181d5b9d8 EFLAGS: 00010202
[  330.259672] RAX: 0000000000000202 RBX: ffffb8e181d5bb58 RCX: ffffb8e181d5b9e8
[  330.259720] RDX: ffffb8e181d5b9ec RSI: ffffb8e181d5ba08 RDI: ffff95d1812a6ac0
[  330.259777] RBP: ffff95d182740f80 R08: ffffb8e181d5bb58 R09: ffffb8e181d5bb58
[  330.259822] R10: ffffb8e181d5ba08 R11: 0000000000000002 R12: 0000000000000000
[  330.259872] R13: ffff95d1812a6ac0 R14: 0000000000000000 R15: 0000000000000000
[  330.259922] FS:  00007f88f2616c40(0000) GS:ffff95d1bec80000(0000) knlGS:0000000000000000
[  330.259975] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  330.260016] CR2: 0000000000000206 CR3: 0000000003592001 CR4: 0000000000770ef0
[  330.260066] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[  330.260115] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[  330.260164] PKRU: 55555554
[  330.260185] Call Trace:
[  330.260206]  <TASK>
[  330.260230] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434) 
[  330.260265] ? page_fault_oops (arch/x86/mm/fault.c:707) 
[  330.260299] ? radix_tree_node_alloc.constprop.0 (lib/radix-tree.c:255) 
[  330.260339] ? exc_page_fault (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/mm/fault.c:1506 arch/x86/mm/fault.c:1554) 
[  330.260371] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:570) 
[  330.260406] ? nh_valid_get_del_req (./include/net/netlink.h:1680 net/ipv4/nexthop.c:3235) 
[  330.260442] ? rtm_del_nexthop (./include/net/netlink.h:756 ./include/net/netlink.h:777 net/ipv4/nexthop.c:3258) 
[  330.260470] rtm_del_nexthop (net/ipv4/nexthop.c:3264) 
[  330.260501] ? __rmqueue_pcplist (mm/page_alloc.c:2824) 
[  330.260539] rtnetlink_rcv_msg (net/core/rtnetlink.c:6595) 
[  330.260573] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6489) 
[  330.260609] netlink_rcv_skb (net/netlink/af_netlink.c:2559) 
[  330.260639] netlink_unicast (net/netlink/af_netlink.c:1335 net/netlink/af_netlink.c:1361) 
[  330.260669] netlink_sendmsg (net/netlink/af_netlink.c:1905) 
[  330.260697] ____sys_sendmsg (net/socket.c:730 net/socket.c:745 net/socket.c:2584) 
[  330.260730] ? copy_msghdr_from_user (net/socket.c:2524) 
[  330.260766] ___sys_sendmsg (net/socket.c:2640) 
[  330.260798] ? __handle_mm_fault (mm/memory.c:4750 mm/memory.c:4888 mm/memory.c:3745 mm/memory.c:5164 mm/memory.c:5305) 
[  330.260836] __sys_sendmsg (./include/linux/file.h:32 net/socket.c:2669) 
[  330.260864] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) 
[  330.260894] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129) 
[  330.260932] RIP: 0033:0x7f88f281f7b7
[ 330.260961] Code: 0a 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10
All code
========
   0:	0a 00                	or     (%rax),%al
   2:	f7 d8                	neg    %eax
   4:	64 89 02             	mov    %eax,%fs:(%rdx)
   7:	48 c7 c0 ff ff ff ff 	mov    $0xffffffffffffffff,%rax
   e:	eb b9                	jmp    0xffffffffffffffc9
  10:	0f 1f 00             	nopl   (%rax)
  13:	f3 0f 1e fa          	endbr64
  17:	64 8b 04 25 18 00 00 	mov    %fs:0x18,%eax
  1e:	00 
  1f:	85 c0                	test   %eax,%eax
  21:	75 10                	jne    0x33
  23:	b8 2e 00 00 00       	mov    $0x2e,%eax
  28:	0f 05                	syscall
  2a:*	48 3d 00 f0 ff ff    	cmp    $0xfffffffffffff000,%rax		<-- trapping instruction
  30:	77 51                	ja     0x83
  32:	c3                   	ret
  33:	48 83 ec 28          	sub    $0x28,%rsp
  37:	89 54 24 1c          	mov    %edx,0x1c(%rsp)
  3b:	48 89 74 24 10       	mov    %rsi,0x10(%rsp)

Code starting with the faulting instruction
===========================================
   0:	48 3d 00 f0 ff ff    	cmp    $0xfffffffffffff000,%rax
   6:	77 51                	ja     0x59
   8:	c3                   	ret
   9:	48 83 ec 28          	sub    $0x28,%rsp
   d:	89 54 24 1c          	mov    %edx,0x1c(%rsp)
  11:	48 89 74 24 10       	mov    %rsi,0x10(%rsp)
[  330.261069] RSP: 002b:00007ffd0064c138 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
[  330.261126] RAX: ffffffffffffffda RBX: 00007ffd0064cc90 RCX: 00007f88f281f7b7
[  330.261176] RDX: 0000000000000000 RSI: 00007ffd0064c1a0 RDI: 0000000000000005
[  330.261231] RBP: 00007ffd0064c660 R08: 0000000000000004 R09: 0000000000000000
[  330.261280] R10: 00007f88f26d8708 R11: 0000000000000246 R12: 00007ffd0064da50


Finger prints:
nh_valid_get_del_req:rtm_del_nexthop:rtnetlink_rcv_msg:netlink_rcv_skb