Kernel panic - not syncing: audit: backlog limit exceeded

Solution Verified - Updated -

Issue

  • Kernel panic on "audit: backlog limit exceeded" error with following call traces.
audit: audit_backlog=8193 > audit_backlog_limit=8192
audit: audit_lost=1 audit_rate_limit=0 audit_backlog_limit=8192
Kernel panic - not syncing: audit: backlog limit exceeded
----------- [cut here ] --------- [please bite here ] ---------
Kernel BUG at panic:77
invalid operand: 0000 [1] SMP 
CPU 3 
Modules linked in: vsock(U) vmci(U) vmmemctl(U) nfs nfsd exportfs lockd nfs_acl parport_pc lp parport netconsole netdump i2c_dev i2c_core sunrpc ds yenta_socket pcmcia_core cpufreq_powersave dm_mirror dm_mod button battery ac md5 ipv6 e1000 floppy vmxnet3(U) vmxnet(U) ext3 jbd ata_piix libata mptscsih mptsas mptspi mptscsi mptbase sd_mod scsi_mod
Pid: 935, comm: chmod Not tainted 2.6.9-103.ELsmp
RIP: 0010:[<ffffffff801386c2>] <ffffffff801386c2>{panic+211}
RSP: 0018:0000010150f03ca8  EFLAGS: 00010286
RAX: 000000000000003e RBX: ffffffff803309f1 RCX: 0000000000000246
RDX: 0000000000024a2f RSI: 0000000000000246 RDI: ffffffff803f8500
RBP: 0000000128f23b35 R08: 00000000ffffffff R09: ffffffff803309f1
R10: 0000000000000038 R11: 0000010275b61380 R12: 00000000000000d0
R13: 00000102725de800 R14: 000000000000051b R15: 0000000000000000
FS:  0000002a95581b00(0000) GS:ffffffff80506a80(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003b
CR2: 00000000f7bdf000 CR3: 00000000efe04000 CR4: 00000000000006e0
Process chmod (pid: 935, threadinfo 0000010150f02000, task 000001024d90b030)
Stack: 0000003000000010 0000010150f03d88 0000010150f03cc8 0000000000000001 
       0000000000000000 ffffffff80330b03 00000000000249ee 0000000000000246 
       0000000000000000 0000000000000000 
Call Trace:<ffffffff80316403>{schedule_timeout+396} <ffffffff80155da0>{audit_log_lost+131} 
       <ffffffff80155d1b>{audit_panic+51} <ffffffff80156736>{audit_log_start+423} 
       <ffffffff801347c1>{default_wake_function+0} <ffffffff801347c1>{default_wake_function+0} 
       <ffffffff80158463>{audit_log_exit+1592} <ffffffff80189151>{path_release+12} 
       <ffffffff8017b5fd>{sys_chmod+212} <ffffffff80158aaf>{audit_syscall_exit+301} 
       <ffffffff8011461a>{syscall_trace_leave+53} <ffffffff80110470>{tracesys+255} 


Code: 0f 0b 31 a3 32 80 ff ff ff ff 4d 00 31 ff e8 df be fe ff 83 
RIP <ffffffff801386c2>{panic+211} RSP <0000010150f03ca8>

Environment

  • Red Hat Enterprise Linux (RHEL) 4, 5, 6, 7, 8
  • auditd

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In