======================================
| [  232.432635] #PF: supervisor read access in kernel mode
| [  232.432664] #PF: error_code(0x0000) - not-present page
| [  232.432695] PGD 4b0c067 P4D 4b0c067 PUD 56f2067 PMD 0
| [  232.432725] Oops: 0000 [#1] PREEMPT SMP NOPTI
[  232.432795] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[  232.432857] RIP: 0010:nh_valid_get_del_req (./include/net/netlink.h:1680 net/ipv4/nexthop.c:3235) 
[ 232.432892] Code: 11 00 75 47 8b 47 14 85 c0 75 40 48 8b 46 08 48 85 c0 0f 84 81 00 00 00 8b 40 04 89 02 85 c0 74 51 48 8b 46 70 48 85 c0 74 10 <8b> 40 04 89 01 31 c0 48 83 c4 08 c3 cc cc cc cc c7 01 00 00 00 00
All code
========
   0:	11 00                	adc    %eax,(%rax)
   2:	75 47                	jne    0x4b
   4:	8b 47 14             	mov    0x14(%rdi),%eax
   7:	85 c0                	test   %eax,%eax
   9:	75 40                	jne    0x4b
   b:	48 8b 46 08          	mov    0x8(%rsi),%rax
   f:	48 85 c0             	test   %rax,%rax
  12:	0f 84 81 00 00 00    	je     0x99
  18:	8b 40 04             	mov    0x4(%rax),%eax
  1b:	89 02                	mov    %eax,(%rdx)
  1d:	85 c0                	test   %eax,%eax
  1f:	74 51                	je     0x72
  21:	48 8b 46 70          	mov    0x70(%rsi),%rax
  25:	48 85 c0             	test   %rax,%rax
  28:	74 10                	je     0x3a
  2a:*	8b 40 04             	mov    0x4(%rax),%eax		<-- trapping instruction
  2d:	89 01                	mov    %eax,(%rcx)
  2f:	31 c0                	xor    %eax,%eax
  31:	48 83 c4 08          	add    $0x8,%rsp
  35:	c3                   	ret
  36:	cc                   	int3
  37:	cc                   	int3
  38:	cc                   	int3
  39:	cc                   	int3
  3a:	c7 01 00 00 00 00    	movl   $0x0,(%rcx)

Code starting with the faulting instruction
===========================================
   0:	8b 40 04             	mov    0x4(%rax),%eax
   3:	89 01                	mov    %eax,(%rcx)
   5:	31 c0                	xor    %eax,%eax
   7:	48 83 c4 08          	add    $0x8,%rsp
   b:	c3                   	ret
   c:	cc                   	int3
   d:	cc                   	int3
   e:	cc                   	int3
   f:	cc                   	int3
  10:	c7 01 00 00 00 00    	movl   $0x0,(%rcx)
[  232.432985] RSP: 0018:ffffaaeb4081b9d8 EFLAGS: 00010202
[  232.433016] RAX: 0000000000000246 RBX: ffffaaeb4081bb58 RCX: ffffaaeb4081b9e8
[  232.433059] RDX: ffffaaeb4081b9ec RSI: ffffaaeb4081ba08 RDI: ffff9b0241fd0fc0
[  232.433102] RBP: ffff9b0243112640 R08: ffffaaeb4081bb58 R09: ffffaaeb4081bb58
[  232.433144] R10: ffffaaeb4081ba08 R11: 0000000000000002 R12: 0000000000000000
[  232.433187] R13: ffff9b0241fd0fc0 R14: 0000000000000000 R15: 0000000000000000
[  232.433226] FS:  00007fce3ababc40(0000) GS:ffff9b027ed00000(0000) knlGS:0000000000000000
[  232.433268] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  232.433304] CR2: 000000000000024a CR3: 000000000324a002 CR4: 0000000000770ef0
[  232.433348] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[  232.433390] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[  232.433427] PKRU: 55555554
[  232.433439] Call Trace:
[  232.433455]  <TASK>
[  232.433471] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434) 
[  232.433497] ? page_fault_oops (arch/x86/mm/fault.c:707) 
[  232.433522] ? exc_page_fault (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/mm/fault.c:1506 arch/x86/mm/fault.c:1554) 
[  232.433545] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:570) 
[  232.433570] ? nh_valid_get_del_req (./include/net/netlink.h:1680 net/ipv4/nexthop.c:3235) 
[  232.433600] ? rtm_del_nexthop (./include/net/netlink.h:756 ./include/net/netlink.h:777 net/ipv4/nexthop.c:3258) 
[  232.433625] rtm_del_nexthop (net/ipv4/nexthop.c:3264) 
[  232.433651] ? skb_queue_tail (./include/linux/spinlock.h:406 net/core/skbuff.c:3975) 
[  232.433678] rtnetlink_rcv_msg (net/core/rtnetlink.c:6595) 
[  232.433704] ? netlink_dump (net/netlink/af_netlink.c:2324 (discriminator 2)) 
[  232.433731] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6489) 
[  232.433761] netlink_rcv_skb (net/netlink/af_netlink.c:2559) 
[  232.433788] netlink_unicast (net/netlink/af_netlink.c:1335 net/netlink/af_netlink.c:1361) 
[  232.433810] netlink_sendmsg (net/netlink/af_netlink.c:1905) 
[  232.433835] ____sys_sendmsg (net/socket.c:730 net/socket.c:745 net/socket.c:2584) 
[  232.433860] ? copy_msghdr_from_user (net/socket.c:2524) 
[  232.433889] ___sys_sendmsg (net/socket.c:2640) 
[  232.433914] ? ___sys_recvmsg (net/socket.c:2848) 
[  232.433937] ? __sys_sendto (net/socket.c:730 net/socket.c:745 net/socket.c:2191) 
[  232.433962] __sys_sendmsg (./include/linux/file.h:32 net/socket.c:2669) 
[  232.433986] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) 
[  232.434013] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129) 
[  232.434043] RIP: 0033:0x7fce3adb47b7
[ 232.434065] Code: 0a 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10
All code
========
   0:	0a 00                	or     (%rax),%al
   2:	f7 d8                	neg    %eax
   4:	64 89 02             	mov    %eax,%fs:(%rdx)
   7:	48 c7 c0 ff ff ff ff 	mov    $0xffffffffffffffff,%rax
   e:	eb b9                	jmp    0xffffffffffffffc9
  10:	0f 1f 00             	nopl   (%rax)
  13:	f3 0f 1e fa          	endbr64
  17:	64 8b 04 25 18 00 00 	mov    %fs:0x18,%eax
  1e:	00 
  1f:	85 c0                	test   %eax,%eax
  21:	75 10                	jne    0x33
  23:	b8 2e 00 00 00       	mov    $0x2e,%eax
  28:	0f 05                	syscall
  2a:*	48 3d 00 f0 ff ff    	cmp    $0xfffffffffffff000,%rax		<-- trapping instruction
  30:	77 51                	ja     0x83
  32:	c3                   	ret
  33:	48 83 ec 28          	sub    $0x28,%rsp
  37:	89 54 24 1c          	mov    %edx,0x1c(%rsp)
  3b:	48 89 74 24 10       	mov    %rsi,0x10(%rsp)

Code starting with the faulting instruction
===========================================
   0:	48 3d 00 f0 ff ff    	cmp    $0xfffffffffffff000,%rax
   6:	77 51                	ja     0x59
   8:	c3                   	ret
   9:	48 83 ec 28          	sub    $0x28,%rsp
   d:	89 54 24 1c          	mov    %edx,0x1c(%rsp)
  11:	48 89 74 24 10       	mov    %rsi,0x10(%rsp)
[  232.434158] RSP: 002b:00007ffcdd1e64b8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
[  232.434200] RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007fce3adb47b7
[  232.434237] RDX: 0000000000000000 RSI: 00007ffcdd1e6520 RDI: 0000000000000006
[  232.434275] RBP: 00007ffcdd1e67b8 R08: 0000000000000004 R09: 0000000000000078
[  232.434312] R10: 00007fce3ac6d708 R11: 0000000000000246 R12: 0000000000495540


Finger prints:
nh_valid_get_del_req:rtm_del_nexthop:rtnetlink_rcv_msg:netlink_rcv_skb