Server panic rebooted due to third party Imperva kernel module "krg_629288_imRH7_K1S_smp64"

Solution Verified - Updated -

Issue

  • Server panic rebooted with exception RIP: strstr+33 because of third-party kernel module krg_629288_imRH7_K1S_smp64.
  • Call traces look similar to those below.
crash> bt
PID: 67753    TASK: ffff9a4abdaa4200  CPU: 59   COMMAND: "oracle_67753_do"
 #0 [ffff9aa2c943f3f0] machine_kexec at ffffffffa96663d4
 #1 [ffff9aa2c943f450] __crash_kexec at ffffffffa9722ae2
 #2 [ffff9aa2c943f520] crash_kexec at ffffffffa9722bd0
 #3 [ffff9aa2c943f538] oops_end at ffffffffa9d91798
 #4 [ffff9aa2c943f560] no_context at ffffffffa9675d14
 #5 [ffff9aa2c943f5b0] __bad_area_nosemaphore at ffffffffa9675fe2
 #6 [ffff9aa2c943f600] bad_area_nosemaphore at ffffffffa9676104
 #7 [ffff9aa2c943f610] __do_page_fault at ffffffffa9d94750
 #8 [ffff9aa2c943f680] do_page_fault at ffffffffa9d94975
 #9 [ffff9aa2c943f6b0] page_fault at ffffffffa9d90778
    [exception RIP: strstr+33]
    RIP: ffffffffa9990c41  RSP: ffff9aa2c943f768  RFLAGS: 00010216
    RAX: 0000000000000000  RBX: ffff9aa2c943f84c  RCX: 0000000000000000
    RDX: 0000000000000005  RSI: ffffffffc171e69e  RDI: 0000000000000000
    RBP: ffff9aa2c943f768   R8: 0000000000000000   R9: 00000000000108a9
    R10: 0000000000000000  R11: ffffffffc17957d8  R12: ffff9c3542665ca0
    R13: 0000000000000000  R14: 00000000000108a9  R15: ffff9c3542665c38
    ORIG_RAX: ffffffffffffffff  CS: 0010  SS: 0018
#10 [ffff9aa2c943f770] oracle_aso_tools_is_oracle_dispatcher at ffffffffc1680275 [krg_629288_imRH7_K1S_smp64]
#11 [ffff9aa2c943f7f0] _classify_process_monitored_from_us at ffffffffc167e24f [krg_629288_imRH7_K1S_smp64]
#12 [ffff9aa2c943f838] oracle_connect_flow_check_if_encrypted at ffffffffc167f3ce [krg_629288_imRH7_K1S_smp64]
#13 [ffff9aa2c943f880] _create_message at ffffffffc1679c03 [krg_629288_imRH7_K1S_smp64]
#14 [ffff9aa2c943f990] krapi_messages_send_rw_message at ffffffffc167b4e6 [krg_629288_imRH7_K1S_smp64]
#15 [ffff9aa2c943f9f8] krapi_post_read_sync at ffffffffc167593d [krg_629288_imRH7_K1S_smp64]
#16 [ffff9aa2c943fbd0] krapi_post_read at ffffffffc1677887 [krg_629288_imRH7_K1S_smp64]
#17 [ffff9aa2c943fc48] _generic_fd_read_postcode at ffffffffc15f3e02 [krg_629288_imRH7_K1S_smp64]
#18 [ffff9aa2c943fcc8] syscall_wrappers_generic_flow_with_param at ffffffffc1605a50 [krg_629288_imRH7_K1S_smp64]
#19 [ffff9aa2c943fd78] syscall_wrappers_generic_read.constprop.60 at ffffffffc160618d [krg_629288_imRH7_K1S_smp64]
#20 [ffff9aa2c943feb8] SYS_read_common_wrap at ffffffffc1606fa7 [krg_629288_imRH7_K1S_smp64]
#21 [ffff9aa2c943ff40] SYS_read_wrap64 at ffffffffc160704e [krg_629288_imRH7_K1S_smp64]
#22 [ffff9aa2c943ff50] system_call_fastpath at ffffffffa9d99f92
    RIP: 00007ffff40ea740  RSP: 00007ffffffeede0  RFLAGS: 00010202
    RAX: 0000000000000000  RBX: 0000000000002010  RCX: 00007ffff2e955b8
    RDX: 0000000000002010  RSI: 00007ffff2e62ca6  RDI: 000000000000001c
    RBP: 00007ffffffed6d0   R8: 0000000000000000   R9: 000000000000001c
    R10: 0000000000000000  R11: 0000000000000246  R12: 000000000000001c
    R13: 00007ffff2e62ca6  R14: 00007ffff2e64da0  R15: 00007ffff2e61c98
    ORIG_RAX: 0000000000000000  CS: 0033  SS: 002b

Environment

  • Red Hat Enterprise Linux 7.9
  • Third-party kernel module [krg_629288_imRH7_K1S_smp64]

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content