System crashed with message 'kernel BUG at mm/vmalloc.c:2488!' which was related to 'falcon_lsm_serviceable'

Solution Unverified - Updated -

Issue

  • System crashed with the below log in vmcore.
...
[2587210.680863] ------------[ cut here ]------------
[2587210.680866] kernel BUG at mm/vmalloc.c:2488!
[2587210.685356] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI
[2587210.685359] CPU: 4 PID: 2889794 Comm: piper Kdump: loaded Tainted: P        W   E     -------  ---  5.14.0-427.37.1.el9_4.x86_64 #1
[2587210.685361] Hardware name: Dell Inc. PowerEdge R760/05H0JD, BIOS 2.1.5 03/14/2024
[2587210.685361] RIP: 0010:__get_vm_area_node+0x166/0x170
[2587210.685366] Code: 4f c8 48 d3 e6 49 89 f5 e9 11 ff ff ff 4c 89 e7 e8 9f 99 fc ff 45 31 e4 5b 5d 4c 89 e0 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc <0f> 0b 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90
[2587210.685367] RSP: 0018:ff8cbad43ddafb00 EFLAGS: 00010206
[2587210.685369] RAX: 000000000000000c RBX: 0000000000000022 RCX: 0000000000ffff00
[2587210.685370] RDX: 000000000000000c RSI: 0000000000000001 RDI: 000000000000801f
[2587210.685371] RBP: 0000000000000cc0 R08: 00000000ffffffff R09: ffbebad3ffffffff
[2587210.685372] R10: ffbebad3ffffffff R11: ffffffffc1de9400 R12: 000000000000801f
[2587210.685373] R13: 00000000ffffffff R14: ff8cbad400000000 R15: 000000000000000c
[2587210.685374] FS:  0000152455a8ae80(0000) GS:ff4e6db27fa80000(0000) knlGS:0000000000000000
[2587210.685375] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[2587210.685376] CR2: 0000152455cd3b50 CR3: 000000030a560006 CR4: 0000000000771ee0
[2587210.685376] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[2587210.685377] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400
[2587210.685378] PKRU: 55555554
[2587210.685379] Call Trace:
[2587210.685379]  <TASK>
[2587210.685380]  ? show_trace_log_lvl+0x1c4/0x2df
[2587210.685384]  ? show_trace_log_lvl+0x1c4/0x2df
[2587210.685386]  ? __vmalloc_node_range+0xa6/0x220
[2587210.685387]  ? __die_body.cold+0x8/0xd
[2587210.685389]  ? die+0x2b/0x50
[2587210.685393]  ? do_trap+0xce/0x120
[2587210.685395]  ? __get_vm_area_node+0x166/0x170
[2587210.685397]  ? do_error_trap+0x65/0x80
[2587210.685398]  ? __get_vm_area_node+0x166/0x170
[2587210.685400]  ? exc_invalid_op+0x4e/0x70
[2587210.685403]  ? __get_vm_area_node+0x166/0x170
[2587210.685405]  ? asm_exc_invalid_op+0x16/0x20
[2587210.685410]  ? __get_vm_area_node+0x166/0x170
[2587210.685412]  __vmalloc_node_range+0xa6/0x220
[2587210.685414]  ? cshook_security_ptrace_access_check+0x13fc5/0x1be70 [falcon_lsm_serviceable]
[2587210.685419]  __vmalloc_node+0x4a/0x70
[2587210.685421]  ? cshook_security_ptrace_access_check+0x13fc5/0x1be70 [falcon_lsm_serviceable]
[2587210.685423]  cshook_security_ptrace_access_check+0x13fc5/0x1be70 [falcon_lsm_serviceable]
[2587210.685426]  _ZdlPvmSt11align_val_t+0x8bda1/0x8f320 [falcon_lsm_serviceable]
[2587210.685429]  _ZdlPvmSt11align_val_t+0x8bf6e/0x8f320 [falcon_lsm_serviceable]
[2587210.685432]  ? cshook_security_ptrace_access_check+0x1404e/0x1be70 [falcon_lsm_serviceable]
[2587210.685434]  ? cshook_security_ptrace_access_check+0x1404e/0x1be70 [falcon_lsm_serviceable]
[2587210.685437]  _ZdlPvmSt11align_val_t+0x8c26c/0x8f320 [falcon_lsm_serviceable]
[2587210.685439]  _ZdlPvmSt11align_val_t+0x8c2c7/0x8f320 [falcon_lsm_serviceable]
[2587210.685441]  _ZdlPvmSt11align_val_t+0x8dd06/0x8f320 [falcon_lsm_serviceable]
[2587210.685444]  cshook_security_netlink_send+0x20cba/0x2da30 [falcon_lsm_serviceable]
[2587210.685447]  cshook_systemcalltable_pre_close+0x1e/0x20 [falcon_lsm_serviceable]
[2587210.685451]  unload_network_ops_symbols+0xb62f/0xd470 [falcon_lsm_pinned_17308]
[2587210.685458]  ? do_syscall_64+0x59/0x90
[2587210.685459]  ? ktime_get+0x35/0xa0
[2587210.685463]  ? clockevents_program_event+0x93/0x100
[2587210.685468]  ? hrtimer_interrupt+0x126/0x210
[2587210.685471]  ? sched_clock+0xc/0x30
[2587210.685475]  ? sched_clock_cpu+0x9/0xc0
[2587210.685477]  ? irqtime_account_irq+0x3c/0xb0
[2587210.685480]  ? __irq_exit_rcu+0x46/0xc0
[2587210.685484]  ? sysvec_apic_timer_interrupt+0x3c/0x90
[2587210.685486]  ? entry_SYSCALL_64_after_hwframe+0x72/0xdc
[2587210.685489]  </TASK>
[2587210.685489] Modules linked in:
[2587210.685490]  falcon_lsm_serviceable(PE)...
...

Environment

  • Red Hat Enterprise Linux 9
  • 3rd party module falcon_lsm_serviceable loaded

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content