Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #79638 > unrolled thread

Bug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038

Started byDaniel Gröber <dxld@darkboxed.org>
First post2023-07-18 02:40 +0200
Last post2024-08-10 14:30 +0200
Articles 5 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038 Daniel Gröber <dxld@darkboxed.org> - 2023-07-18 02:40 +0200
    Processed: Re: Bug#1041363: nft BUG: kernel NULL pointer  dereference, address: 0000000000000038 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2023-07-22 22:10 +0200
    Bug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038 Salvatore Bonaccorso <carnil@debian.org> - 2023-07-22 22:10 +0200
      Bug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038 Daniel Gröber <dxld@darkboxed.org> - 2023-07-22 23:20 +0200
    Bug#1041363: marked as done (nft BUG: kernel NULL pointer  dereference, address: 0000000000000038) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-08-10 14:30 +0200

#79638 — Bug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038

FromDaniel Gröber <dxld@darkboxed.org>
Date2023-07-18 02:40 +0200
SubjectBug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038
Message-ID<GSGUV-Y1w-1@gated-at.bofh.it>
Package: src:linux
Version: 6.1.27-1
Severity: normal

Dear Maintainer,

I got the following BUG on my router while working on my nftables
ruleset. After this happened network connectivity was broken quite severely
so some internal state might have gotten messed up too. An attempted reboot
never completed and a hard power cut was necessary.

    kernel: BUG: kernel NULL pointer dereference, address: 0000000000000038
    kernel: #PF: supervisor read access in kernel mode
    kernel: #PF: error_code(0x0000) - not-present page
    kernel: PGD 0 P4D 0 
    kernel: Oops: 0000 [#1] PREEMPT SMP NOPTI
    kernel: CPU: 2 PID: 902522 Comm: kworker/2:3 Tainted: G        W          6.1.0-9-amd64 #1  Debian 6.1.27-1
    kernel: Hardware name: PC Engines apu3/apu3, BIOS v4.11.0.3 01/29/2020
    kernel: Workqueue: events nf_tables_trans_destroy_work [nf_tables]
    kernel: RIP: 0010:nft_set_elem_expr_destroy+0x56/0xa0 [nf_tables]
    kernel: Code: 6b 20 d9 48 8b 03 48 8b 40 78 48 8b 78 30 e8 f1 6e 54 d8 48 8b 03 8b 40 10 01 c5 48 01 c3 41 0f b6 04 24 39 c5 73 2f 48 8b 13 <48> 8b 42 38 48 85 c0 75 c5>
    kernel: RSP: 0018:ffffb4e1484cfd28 EFLAGS: 00010246
    kernel: RAX: 0000000000000000 RBX: ffff940746193d08 RCX: ffff940764e89200
    kernel: RDX: 0000000000000000 RSI: ffff940746193d00 RDI: ffffb4e1484cfd58
    kernel: RBP: 0000000000000000 R08: 0000000000000003 R09: 000000008020001d
    kernel: R10: 0000000000000000 R11: 0000000000000000 R12: ffff940746193d00
    kernel: R13: ffffb4e1484cfd58 R14: dead000000000122 R15: ffff940746c23e80
    kernel: FS:  0000000000000000(0000) GS:ffff9407b5f00000(0000) knlGS:0000000000000000
    kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
    kernel: CR2: 0000000000000038 CR3: 000000006eac2000 CR4: 00000000000406e0
    kernel: Call Trace:
    kernel:  <TASK>
    kernel:  nft_set_elem_destroy+0xe5/0x100 [nf_tables]
    kernel:  nft_set_pipapo_match_destroy+0x65/0x80 [nf_tables]
    kernel:  nft_pipapo_destroy+0x2e/0x1b0 [nf_tables]
    kernel:  nft_set_destroy+0x95/0x120 [nf_tables]
    kernel:  nf_tables_trans_destroy_work+0x303/0x330 [nf_tables]
    kernel:  process_one_work+0x1c7/0x380
    kernel:  worker_thread+0x4d/0x380
    kernel:  ? _raw_spin_lock_irqsave+0x23/0x50
    kernel:  ? rescuer_thread+0x3a0/0x3a0
    kernel:  kthread+0xe9/0x110
    kernel:  ? kthread_complete_and_exit+0x20/0x20
    kernel:  ret_from_fork+0x22/0x30
    kernel:  </TASK>
    kernel: Modules linked in: mptcp_diag sctp_diag raw_diag unix_diag af_packet_diag netlink_diag nf_conntrack_netlink sctp udp_diag tcp_diag inet_diag ip_set_hash_ip ip_s>
    kernel:  zstd_compress raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c crc32c_generic raid1 raid0 multipath cdc_ether l>
    kernel: CR2: 0000000000000038
    kernel: ---[ end trace 0000000000000000 ]---
    kernel: RIP: 0010:nft_set_elem_expr_destroy+0x56/0xa0 [nf_tables]
    kernel: Code: 6b 20 d9 48 8b 03 48 8b 40 78 48 8b 78 30 e8 f1 6e 54 d8 48 8b 03 8b 40 10 01 c5 48 01 c3 41 0f b6 04 24 39 c5 73 2f 48 8b 13 <48> 8b 42 38 48 85 c0 75 c5>
    kernel: RSP: 0018:ffffb4e1484cfd28 EFLAGS: 00010246
    kernel: RAX: 0000000000000000 RBX: ffff940746193d08 RCX: ffff940764e89200
    kernel: RDX: 0000000000000000 RSI: ffff940746193d00 RDI: ffffb4e1484cfd58
    kernel: RBP: 0000000000000000 R08: 0000000000000003 R09: 000000008020001d
    kernel: R10: 0000000000000000 R11: 0000000000000000 R12: ffff940746193d00
    kernel: R13: ffffb4e1484cfd58 R14: dead000000000122 R15: ffff940746c23e80
    kernel: FS:  0000000000000000(0000) GS:ffff9407b5f00000(0000) knlGS:0000000000000000
    kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
    kernel: CR2: 0000000000000038 CR3: 000000006eac2000 CR4: 00000000000406e0
    kernel: note: kworker/2:3[902522] exited with irqs disabled

Thanks,
--Daniel

-- System Information:
Debian Release: 12.0
  APT prefers stable
  APT policy: (990, 'stable'), (500, 'stable-security'), (500, 'stable-debug'), (500, 'proposed-updates-debug')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.1.0-9-amd64 (SMP w/16 CPU threads; PREEMPT)
Kernel taint flags: TAINT_WARN
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

[toc] | [next] | [standalone]


#79673 — Processed: Re: Bug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2023-07-22 22:10 +0200
SubjectProcessed: Re: Bug#1041363: nft BUG: kernel NULL pointer dereference, address: 0000000000000038
Message-ID<GUr5o-22FJ-1@gated-at.bofh.it>
In reply to#79638
Processing control commands:

> tags -1 + moreinfo
Bug #1041363 [src:linux] nft BUG: kernel NULL pointer dereference, address: 0000000000000038
Added tag(s) moreinfo.

-- 
1041363: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1041363
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#79674

FromSalvatore Bonaccorso <carnil@debian.org>
Date2023-07-22 22:10 +0200
Message-ID<GUr5o-22FJ-3@gated-at.bofh.it>
In reply to#79638
Control: tags -1 + moreinfo

Hi Daniel,

On Tue, Jul 18, 2023 at 02:35:25AM +0200, Daniel Gröber wrote:
> Package: src:linux
> Version: 6.1.27-1
> Severity: normal
> 
> Dear Maintainer,
> 
> I got the following BUG on my router while working on my nftables
> ruleset. After this happened network connectivity was broken quite severely
> so some internal state might have gotten messed up too. An attempted reboot
> never completed and a hard power cut was necessary.
> 
>     kernel: BUG: kernel NULL pointer dereference, address: 0000000000000038
>     kernel: #PF: supervisor read access in kernel mode
>     kernel: #PF: error_code(0x0000) - not-present page
>     kernel: PGD 0 P4D 0 
>     kernel: Oops: 0000 [#1] PREEMPT SMP NOPTI
>     kernel: CPU: 2 PID: 902522 Comm: kworker/2:3 Tainted: G        W          6.1.0-9-amd64 #1  Debian 6.1.27-1
>     kernel: Hardware name: PC Engines apu3/apu3, BIOS v4.11.0.3 01/29/2020
>     kernel: Workqueue: events nf_tables_trans_destroy_work [nf_tables]
>     kernel: RIP: 0010:nft_set_elem_expr_destroy+0x56/0xa0 [nf_tables]
>     kernel: Code: 6b 20 d9 48 8b 03 48 8b 40 78 48 8b 78 30 e8 f1 6e 54 d8 48 8b 03 8b 40 10 01 c5 48 01 c3 41 0f b6 04 24 39 c5 73 2f 48 8b 13 <48> 8b 42 38 48 85 c0 75 c5>
>     kernel: RSP: 0018:ffffb4e1484cfd28 EFLAGS: 00010246
>     kernel: RAX: 0000000000000000 RBX: ffff940746193d08 RCX: ffff940764e89200
>     kernel: RDX: 0000000000000000 RSI: ffff940746193d00 RDI: ffffb4e1484cfd58
>     kernel: RBP: 0000000000000000 R08: 0000000000000003 R09: 000000008020001d
>     kernel: R10: 0000000000000000 R11: 0000000000000000 R12: ffff940746193d00
>     kernel: R13: ffffb4e1484cfd58 R14: dead000000000122 R15: ffff940746c23e80
>     kernel: FS:  0000000000000000(0000) GS:ffff9407b5f00000(0000) knlGS:0000000000000000
>     kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
>     kernel: CR2: 0000000000000038 CR3: 000000006eac2000 CR4: 00000000000406e0
>     kernel: Call Trace:
>     kernel:  <TASK>
>     kernel:  nft_set_elem_destroy+0xe5/0x100 [nf_tables]
>     kernel:  nft_set_pipapo_match_destroy+0x65/0x80 [nf_tables]
>     kernel:  nft_pipapo_destroy+0x2e/0x1b0 [nf_tables]
>     kernel:  nft_set_destroy+0x95/0x120 [nf_tables]
>     kernel:  nf_tables_trans_destroy_work+0x303/0x330 [nf_tables]
>     kernel:  process_one_work+0x1c7/0x380
>     kernel:  worker_thread+0x4d/0x380
>     kernel:  ? _raw_spin_lock_irqsave+0x23/0x50
>     kernel:  ? rescuer_thread+0x3a0/0x3a0
>     kernel:  kthread+0xe9/0x110
>     kernel:  ? kthread_complete_and_exit+0x20/0x20
>     kernel:  ret_from_fork+0x22/0x30
>     kernel:  </TASK>
>     kernel: Modules linked in: mptcp_diag sctp_diag raw_diag unix_diag af_packet_diag netlink_diag nf_conntrack_netlink sctp udp_diag tcp_diag inet_diag ip_set_hash_ip ip_s>
>     kernel:  zstd_compress raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c crc32c_generic raid1 raid0 multipath cdc_ether l>
>     kernel: CR2: 0000000000000038
>     kernel: ---[ end trace 0000000000000000 ]---
>     kernel: RIP: 0010:nft_set_elem_expr_destroy+0x56/0xa0 [nf_tables]
>     kernel: Code: 6b 20 d9 48 8b 03 48 8b 40 78 48 8b 78 30 e8 f1 6e 54 d8 48 8b 03 8b 40 10 01 c5 48 01 c3 41 0f b6 04 24 39 c5 73 2f 48 8b 13 <48> 8b 42 38 48 85 c0 75 c5>
>     kernel: RSP: 0018:ffffb4e1484cfd28 EFLAGS: 00010246
>     kernel: RAX: 0000000000000000 RBX: ffff940746193d08 RCX: ffff940764e89200
>     kernel: RDX: 0000000000000000 RSI: ffff940746193d00 RDI: ffffb4e1484cfd58
>     kernel: RBP: 0000000000000000 R08: 0000000000000003 R09: 000000008020001d
>     kernel: R10: 0000000000000000 R11: 0000000000000000 R12: ffff940746193d00
>     kernel: R13: ffffb4e1484cfd58 R14: dead000000000122 R15: ffff940746c23e80
>     kernel: FS:  0000000000000000(0000) GS:ffff9407b5f00000(0000) knlGS:0000000000000000
>     kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
>     kernel: CR2: 0000000000000038 CR3: 000000006eac2000 CR4: 00000000000406e0
>     kernel: note: kworker/2:3[902522] exited with irqs disabled

As this is not the newest kernel in bookworm, please test with
6.1.38-1. 

Are you able to reliably reproduce the issue and can share the poc?

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#79676

FromDaniel Gröber <dxld@darkboxed.org>
Date2023-07-22 23:20 +0200
Message-ID<GUsb7-23md-5@gated-at.bofh.it>
In reply to#79674
Hi Salvatore,

On Sat, Jul 22, 2023 at 10:07:39PM +0200, Salvatore Bonaccorso wrote:
> On Tue, Jul 18, 2023 at 02:35:25AM +0200, Daniel Gröber wrote:
> > I got the following BUG on my router while working on my nftables
> > ruleset. After this happened network connectivity was broken quite severely
> > so some internal state might have gotten messed up too. An attempted reboot
> > never completed and a hard power cut was necessary.
>
> As this is not the newest kernel in bookworm, please test with
> 6.1.38-1. 
> 
> Are you able to reliably reproduce the issue and can share the poc?

Unfortunately this bug only reared it's ugly head once so far. I upgraded
to 6.1-38-1 just after sending this report.

Since that upgrade I have

[   27.057795] WARNING: CPU: 0 PID: 1180 at net/core/flow_dissector.c:1016 __skb_flow_dissect+0xa91/0x1cd0

on every boot on the two of my routers. Is that a known issue? I can't seem
to find any reports but this also happens on my workstation. Let me know if
I should open another bug for that.

The original bug is likely very hard to trigger if it still exists. It's
hard to reconstruct the various changes I was making while testing my
ruleset :/

I'd be happy to have a quick look at the code to see if I can deduce what
triggered it, but I'm not familliar with how to parse these kernel BUG
traces. Could you point me to any docs on how to get some line numbers for
that backtrace?

Thanks,
--Daniel

[toc] | [prev] | [next] | [standalone]


#83411 — Bug#1041363: marked as done (nft BUG: kernel NULL pointer dereference, address: 0000000000000038)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2024-08-10 14:30 +0200
SubjectBug#1041363: marked as done (nft BUG: kernel NULL pointer dereference, address: 0000000000000038)
Message-ID<J9Tor-43OB-73@gated-at.bofh.it>
In reply to#79638

[Multipart message — attachments visible in raw view] — view raw

Your message dated Sat, 10 Aug 2024 14:23:13 +0200 (CEST)
with message-id <20240810122313.E713ABE2DE0@eldamar.lan>
and subject line Closing this bug (BTS maintenance for src:linux bugs)
has caused the Debian Bug report #1041363,
regarding nft BUG: kernel NULL pointer dereference, address: 0000000000000038
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1041363: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1041363
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web