RHEL7: kernel paging request issue on free_pipe_info+0x5f/0xa0 or in6_dev_finish_destroy.
Issue
- System panics with RIP :
free_pipe_info+0x5f/0xa0
.
crash> bt
PID: 30984 TASK: ffff8812976a1fa0 CPU: 11 COMMAND: "java"
#0 [ffff8805a4e93a98] machine_kexec at ffffffff8105c4cb
#1 [ffff8805a4e93af8] __crash_kexec at ffffffff81104a32
#2 [ffff8805a4e93bc8] crash_kexec at ffffffff81104b20
#3 [ffff8805a4e93be0] oops_end at ffffffff816ad278
#4 [ffff8805a4e93c08] no_context at ffffffff8169d29a
#5 [ffff8805a4e93c58] __bad_area_nosemaphore at ffffffff8169d330
#6 [ffff8805a4e93ca0] bad_area at ffffffff8169d654
#7 [ffff8805a4e93cc8] __do_page_fault at ffffffff816b023c
#8 [ffff8805a4e93d28] trace_do_page_fault at ffffffff816b0396
#9 [ffff8805a4e93d68] do_async_page_fault at ffffffff816afa2a
#10 [ffff8805a4e93d80] async_page_fault at ffffffff816ac538
[exception RIP: free_pipe_info+95]
RIP: ffffffff8120a80f RSP: ffff8805a4e93e30 RFLAGS: 00010202
RAX: 00000000fffffffd RBX: 0000000000000008 RCX: 0000000000000123
RDX: 0000000000000028 RSI: ffff8802bee69d40 RDI: ffff880213bda900
RBP: ffff8805a4e93e40 R8: 0000000000000000 R9: 0000000000000000
R10: ffff880831e61bc0 R11: ffff880d5ebc5710 R12: ffff880213bda900
R13: ffff880831e61bc0 R14: ffff88003eb92fc0 R15: ffff88143fb24020
ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018
#11 [ffff8805a4e93e48] put_pipe_info at ffffffff8120a8a9
#12 [ffff8805a4e93e70] pipe_release at ffffffff8120a950
#13 [ffff8805a4e93e98] __fput at ffffffff81202fb9
#14 [ffff8805a4e93ee0] ____fput at ffffffff8120321e
#15 [ffff8805a4e93ef0] task_work_run at ffffffff810ad247
#16 [ffff8805a4e93f30] do_notify_resume at ffffffff8102ab62
#17 [ffff8805a4e93f50] int_signal at ffffffff816b527d
RIP: 00007ff1cdb4b76d RSP: 00007feff1e66930 RFLAGS: 00000293
RAX: 0000000000000000 RBX: 00007feff1e66990 RCX: ffffffffffffffff
RDX: 00007ff1cd12fc10 RSI: 00000006a54675e8 RDI: 00000000000002ea
RBP: 00007feff1e66980 R8: 00000000d4a8cebd R9: 00000006a54675e8
R10: 0000000000003388 R11: 0000000000000293 R12: 0000000000000042
R13: 00000000000002ea R14: 00007ff00401ca58 R15: 00007ff1cc812db0
ORIG_RAX: 0000000000000003 CS: 0033 SS: 002b
- System panics with RIP :
in6_dev_finish_destroy+0x35
.
[2954228.387363] BUG: unable to handle kernel NULL pointer dereference at 0000000000000398
[2954228.387396] IP: [<ffffffff8167be35>] in6_dev_finish_destroy+0x35/0xf0
[2954228.387421] PGD 137eee7067 PUD 138c3f6067 PMD 0
[2954228.387441] Oops: 0000 [#1] SMP
[2954228.387935] CPU: 6 PID: 25564 Comm: kworker/u20:1 Tainted: G W ------------ T 3.10.0-693.el7.x86_64 #1
[2954228.387976] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016
[2954228.388010] Workqueue: netns cleanup_net
[2954228.388026] task: ffff8812aa745ee0 ti: ffff880a60784000 task.ti: ffff880a60784000
[2954228.388050] RIP: 0010:[<ffffffff8167be35>] [<ffffffff8167be35>] in6_dev_finish_destroy+0x35/0xf0
[2954228.388082] RSP: 0018:ffff880a60787c00 EFLAGS: 00010286
[2954228.388103] RAX: 0000000000000024 RBX: ffff8813e6f08c00 RCX: 0000000000000006
[2954228.388159] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000009
[2954228.388183] RBP: ffff880a60787c10 R08: 000000005b2d2d2d R09: 3361346432343863
[2954228.388207] R10: 0000000000001370 R11: 61727420646e6520 R12: 0000000000000000
[2954228.388232] R13: 0000000000000006 R14: ffff880a60787cb0 R15: 0000000000000000
[2954228.388256] FS: 0000000000000000(0000) GS:ffff8813ef300000(0000) knlGS:0000000000000000
[2954228.388289] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[2954228.388309] CR2: 0000000000000398 CR3: 00000013b6294000 CR4: 00000000003407e0
[2954228.389318] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[2954228.390282] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[2954228.391208] Stack:
[2954228.392117] ffff88137b20a880 0000000000000000 ffff880a60787c28 ffffffff8165019f
[2954228.393032] 00000000ffffffea ffff880a60787c60 ffffffff816b04dc 0000000000000006
[2954228.393942] ffff880c8dadd000 ffff880a60787cb0 00000001b0114e12 00000000000003e8
[2954228.394839] Call Trace:
[2954228.395730] [<ffffffff8165019f>] ip6_route_dev_notify+0x12f/0x140
[2954228.396635] [<ffffffff816b04dc>] notifier_call_chain+0x4c/0x70
[2954228.397537] [<ffffffff810b68d6>] raw_notifier_call_chain+0x16/0x20
[2954228.398444] [<ffffffff8158306d>] call_netdevice_notifiers_info+0x4d/0x80
[2954228.399341] [<ffffffff8158c7bf>] netdev_run_todo+0x14f/0x2f0
[2954228.400244] [<ffffffff81598d7e>] rtnl_unlock+0xe/0x10
[2954228.401135] [<ffffffff8158407e>] default_device_exit_batch+0x16e/0x1a0
[2954228.402013] [<ffffffff810b1790>] ? abort_exclusive_wait+0xa0/0xa0
[2954228.402904] [<ffffffff8157c473>] ops_exit_list.isra.5+0x53/0x60
[2954228.403791] [<ffffffff8157d550>] cleanup_net+0x1d0/0x2c0
[2954228.404698] [<ffffffff810a881a>] process_one_work+0x17a/0x440
[2954228.405613] [<ffffffff810a94e6>] worker_thread+0x126/0x3c0
[2954228.406509] [<ffffffff810a93c0>] ? manage_workers.isra.24+0x2a0/0x2a0
[2954228.407425] [<ffffffff810b098f>] kthread+0xcf/0xe0
[2954228.408348] [<ffffffff810b08c0>] ? insert_kthread_work+0x40/0x40
[2954228.409256] [<ffffffff816b4f18>] ret_from_fork+0x58/0x90
[2954228.410155] [<ffffffff810b08c0>] ? insert_kthread_work+0x40/0x40
[2954228.411040] Code: 48 89 e5 41 54 53 48 39 47 08 48 89 fb 4c 8b 27 75 7c 48 83 7b 18 00 0f 85 b2 00 00 00 48 83 bb a8 02 00 00 00 0f 85 8e 00 00 00 <49> 8b 84 24 98 03 00 00 65 ff 08 8b 83 58 01 00 00 85 c0 74 66
[2954228.412930] RIP [<ffffffff8167be35>] in6_dev_finish_destroy+0x35/0xf0
[2954228.413829] RSP <ffff880a60787c00>
[2954228.414689] CR2: 0000000000000398
Environment
- Red Hat Enterprise Linux 7.4
- kernel-3.10.0-693.el7 or later.
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.