Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #87671 > unrolled thread

Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core

Started byKim Alvefur <zash@zash.se>
First post2025-05-24 17:00 +0200
Last post2025-06-04 13:10 +0200
Articles 9 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core Kim Alvefur <zash@zash.se> - 2025-05-24 17:00 +0200
    Processed: Re: Bug#1106411: linux-image-6.12.27-amd64: kernel  NULL pointer dereference in bmc150_accel_core "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-05-25 17:00 +0200
    Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core Salvatore Bonaccorso <carnil@debian.org> - 2025-05-25 17:00 +0200
    Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core Salvatore Bonaccorso <carnil@debian.org> - 2025-05-31 21:00 +0200
    Processed: Re: Bug#1106411: linux-image-6.12.27-amd64: kernel  NULL pointer dereference in bmc150_accel_core "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-05-31 21:00 +0200
    Bug#1106411: kernel NULL pointer dereference in bmc150_accel_core / RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core] Kim Alvefur <zash@zash.se> - 2025-06-01 00:10 +0200
      Bug#1106411: kernel NULL pointer dereference in bmc150_accel_core / RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core] Salvatore Bonaccorso <carnil@debian.org> - 2025-07-17 23:20 +0200
    Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core Salvatore Bonaccorso <carnil@debian.org> - 2025-06-04 09:40 +0200
      Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core Kim Alvefur <zash@zash.se> - 2025-06-04 13:10 +0200

#87671 — Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core

FromKim Alvefur <zash@zash.se>
Date2025-05-24 17:00 +0200
SubjectBug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core
Message-ID<KPYvT-5peA-1@gated-at.bofh.it>
Package: src:linux
Version: 6.12.27-1
Severity: important
X-Debbugs-Cc: debian-amd64@lists.debian.org
User: debian-amd64@lists.debian.org
Usertags: amd64

Dear Maintainer,

I noticed a kernel BUG line in the logs.

> BUG: kernel NULL pointer dereference, address: 0000000000000001

-- Package-specific info:
** Version:
Linux version 6.12.27-amd64 (debian-kernel@lists.debian.org) (x86_64-linux-gnu-gcc-14 (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44) #1 SMP PREEMPT_DYNAMIC Debian 6.12.27-1 (2025-05-06)

** Command line:
BOOT_IMAGE=/vmlinuz-6.12.27-amd64 root=/dev/mapper/spisula--vg-root ro quiet

** Tainted: D (128)
 * kernel died recently, i.e. there was an OOPS or BUG

** Kernel log:
[   15.089146] RDX: ffffffff83326d30 RSI: 0000000000000202 RDI: ffff9a9190947504
[   15.089148] RBP: ffff9a9190947420 R08: ffff9a919c498be8 R09: 0000000000000000
[   15.089149] R10: ffffb83f40d27ac8 R11: 0000000000000009 R12: ffff9a919c498d50
[   15.089151] R13: 0000000000000000 R14: 0000000000000001 R15: ffff9a919c498b30
[   15.089153] FS:  00007f10b2d30940(0000) GS:ffff9a91fbd00000(0000) knlGS:0000000000000000
[   15.089155] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   15.089157] CR2: 0000000000000001 CR3: 000000011c33c000 CR4: 0000000000352ef0
[   15.089159] Call Trace:
[   15.089163]  <TASK>
[   15.089167]  bmc150_accel_buffer_postenable+0x5d/0x90 [bmc150_accel_core]
[   15.089173]  __iio_update_buffers+0x731/0xb20 [industrialio]
[   15.089198]  enable_store+0x84/0xe0 [industrialio]
[   15.089214]  kernfs_fop_write_iter+0x13b/0x1f0
[   15.089222]  vfs_write+0x28d/0x450
[   15.089230]  ksys_write+0x6d/0xf0
[   15.089235]  do_syscall_64+0x82/0x190
[   15.089241]  ? syscall_exit_to_user_mode+0x4d/0x210
[   15.089245]  ? do_syscall_64+0x8e/0x190
[   15.089248]  ? __memcg_slab_free_hook+0xf7/0x140
[   15.089253]  ? __x64_sys_close+0x3c/0x80
[   15.089255]  ? kmem_cache_free+0x3ee/0x440
[   15.089260]  ? syscall_exit_to_user_mode+0x4d/0x210
[   15.089263]  ? do_syscall_64+0x8e/0x190
[   15.089265]  ? kernfs_fop_write_iter+0x9d/0x1f0
[   15.089268]  ? vfs_write+0x28d/0x450
[   15.089272]  ? syscall_exit_to_user_mode+0x4d/0x210
[   15.089275]  ? clear_bhb_loop+0x25/0x80
[   15.089279]  ? clear_bhb_loop+0x25/0x80
[   15.089281]  ? clear_bhb_loop+0x25/0x80
[   15.089284]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[   15.089288] RIP: 0033:0x7f10b31369ee
[   15.089319] Code: 08 0f 85 f5 4b ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
[   15.089321] RSP: 002b:00007ffc6dbe57d8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
[   15.089324] RAX: ffffffffffffffda RBX: 00007f10b2d30940 RCX: 00007f10b31369ee
[   15.089325] RDX: 0000000000000001 RSI: 00007ffc6dbe5980 RDI: 0000000000000009
[   15.089327] RBP: 00007ffc6dbe5980 R08: 0000000000000000 R09: 0000000000000000
[   15.089328] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
[   15.089329] R13: 0000559ac7f662a0 R14: 00007f10b3281e80 R15: 0000000000000001
[   15.089333]  </TASK>
[   15.089333] Modules linked in: snd_hda_ext_core snd_soc_core snd_compress snd_pcm_dmaengine overlay bnep zram processor_thermal_device_pci_legacy snd_hda_intel lz4hc_compress snd_intel_dspcfg lz4_compress i915(+) processor_thermal_device x86_pkg_temp_thermal uvcvideo intel_powerclamp snd_intel_sdw_acpi processor_thermal_wt_hint coretemp videobuf2_vmalloc iwlmvm btusb snd_hda_codec binfmt_misc processor_thermal_rfim drm_buddy kvm_intel uvc drm_display_helper btrtl snd_hda_core mac80211 intel_rapl_msr processor_thermal_rapl videobuf2_memops nls_ascii btintel snd_hwdep cec intel_rapl_common kvm libarc4 bmc150_accel_i2c videobuf2_v4l2 nls_cp437 btbcm snd_pcm acer_wmi rc_core processor_thermal_wt_req bmc150_accel_core iwlwifi irqbypass videodev vfat btmtk intel_pmc_core snd_timer mei_hdcp mei_pxp sparse_keymap ttm processor_thermal_power_floor industrialio_triggered_buffer rapl fat videobuf2_common rtsx_usb_ms cfg80211 intel_vsec snd bluetooth platform_profile mei_me drm_kms_helper processor_thermal_mbox kfifo_buf
[   15.089389]  intel_cstate pcspkr mc wmi_bmof memstick pmt_telemetry soundcore rfkill mei i2c_algo_bit intel_soc_dts_iosf industrialio int3400_thermal ac acer_wireless int3403_thermal pmt_class soc_button_array button acpi_thermal_rel int340x_thermal_zone joydev evdev msr parport_pc ppdev lp parport efi_pstore configfs nfnetlink efivarfs ip_tables x_tables autofs4 ext4 crc16 mbcache jbd2 crc32c_generic rtsx_usb_sdmmc rtsx_usb dm_crypt dm_mod crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel hid_multitouch sha512_ssse3 hid_generic sha256_ssse3 xhci_pci sha1_ssse3 r8169 i2c_hid_acpi sdhci_pci xhci_hcd aesni_intel nvme realtek i2c_hid intel_lpss_pci cqhci usbcore gf128mul nvme_core mdio_devres hid intel_lpss sdhci i2c_i801 wdat_wdt crypto_simd cryptd watchdog serio_raw video i2c_smbus lpc_ich libphy mmc_core usb_common idma64 drm nvme_auth battery wmi
[   15.089449] CR2: 0000000000000001
[   15.089451] ---[ end trace 0000000000000000 ]---
[   15.207536] RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core]
[   15.207561] Code: 84 86 00 00 00 ba 01 00 00 00 f0 0f c1 10 83 c2 01 83 fa 01 7f 64 49 8b 3c 24 be 01 00 00 00 e8 5e fc ff ff 89 c3 85 c0 75 52 <41> 0f b6 55 01 41 0f b6 75 00 45 31 c9 45 31 c0 49 8b 3c 24 6a 00
[   15.207563] RSP: 0018:ffffb83f40d27ab0 EFLAGS: 00010246
[   15.207567] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00000000ffffff01
[   15.207569] RDX: ffffffff83326d30 RSI: 0000000000000202 RDI: ffff9a9190947504
[   15.207571] RBP: ffff9a9190947420 R08: ffff9a919c498be8 R09: 0000000000000000
[   15.207572] R10: ffffb83f40d27ac8 R11: 0000000000000009 R12: ffff9a919c498d50
[   15.207574] R13: 0000000000000000 R14: 0000000000000001 R15: ffff9a919c498b30
[   15.207575] FS:  00007f10b2d30940(0000) GS:ffff9a91fbd00000(0000) knlGS:0000000000000000
[   15.207577] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   15.207579] CR2: 0000000000000001 CR3: 000000011c33c000 CR4: 0000000000352ef0
[   15.207582] note: iio-sensor-prox[804] exited with irqs disabled
[   15.281160] Generic FE-GE Realtek PHY r8169-0-200:00: attached PHY driver (mii_bus:phy_addr=r8169-0-200:00, irq=MAC)
[   15.300168] snd_hda_codec_realtek hdaudioC0D0: autoconfig for ALC256: line_outs=1 (0x14/0x0/0x0/0x0/0x0) type:speaker
[   15.300176] snd_hda_codec_realtek hdaudioC0D0:    speaker_outs=0 (0x0/0x0/0x0/0x0/0x0)
[   15.300179] snd_hda_codec_realtek hdaudioC0D0:    hp_outs=1 (0x21/0x0/0x0/0x0/0x0)
[   15.300181] snd_hda_codec_realtek hdaudioC0D0:    mono: mono_out=0x0
[   15.300182] snd_hda_codec_realtek hdaudioC0D0:    inputs:
[   15.300184] snd_hda_codec_realtek hdaudioC0D0:      Internal Mic=0x12
[   15.300186] snd_hda_codec_realtek hdaudioC0D0:      Headset Mic=0x19
[   15.461236] r8169 0000:02:00.0 enp2s0: Link is Down
[   15.666827] iwlwifi 0000:00:0c.0: Registered PHC clock: iwlwifi-PTP, with index: 0
[   15.749241] Bluetooth: hci0: Waiting for firmware download to complete
[   15.749426] Bluetooth: hci0: Firmware loaded in 1795145 usecs
[   15.749520] Bluetooth: hci0: Waiting for device to boot
[   15.753647] input: HDA Digital PCBeep as /devices/pci0000:00/0000:00:0e.0/sound/card0/input23
[   15.753728] input: HDA Intel PCH Front Headphone as /devices/pci0000:00/0000:00:0e.0/sound/card0/input24
[   15.753797] input: HDA Intel PCH HDMI/DP,pcm=3 as /devices/pci0000:00/0000:00:0e.0/sound/card0/input25
[   15.753859] input: HDA Intel PCH HDMI/DP,pcm=7 as /devices/pci0000:00/0000:00:0e.0/sound/card0/input26
[   15.753929] input: HDA Intel PCH HDMI/DP,pcm=8 as /devices/pci0000:00/0000:00:0e.0/sound/card0/input27
[   15.763426] Bluetooth: hci0: Device booted in 13644 usecs
[   15.764861] Bluetooth: hci0: Found Intel DDC parameters: intel/ibt-17-16-1.ddc
[   15.766480] Bluetooth: hci0: Applying Intel DDC parameters completed
[   15.767483] Bluetooth: hci0: Firmware revision 0.1 build 201 week 12 2024
[   15.769492] Bluetooth: hci0: HCI LE Coded PHY feature bit is set, but its usage is not supported.
[   15.825248] Bluetooth: MGMT ver 1.23
[   15.862572] NET: Registered PF_ALG protocol family
[   16.107882] Console: switching to colour frame buffer device 170x48
[   16.186327] i915 0000:00:02.0: [drm] fb0: i915drmfb frame buffer device
[   16.188401] Bluetooth: RFCOMM TTY layer initialized
[   16.189294] Bluetooth: RFCOMM socket layer initialized
[   16.190089] Bluetooth: RFCOMM ver 1.11
[   18.899809] wlp0s12f0: authenticate with 14:91:82:2e:1c:5b (local address=f4:b3:01:63:29:78)
[   18.900292] wlp0s12f0: send auth to 14:91:82:2e:1c:5b (try 1/3)
[   18.939856] wlp0s12f0: authenticated
[   18.941129] wlp0s12f0: associate with 14:91:82:2e:1c:5b (try 1/3)
[   18.960084] wlp0s12f0: RX AssocResp from 14:91:82:2e:1c:5b (capab=0x11 status=0 aid=2)
[   18.963364] wlp0s12f0: associated
[   19.726378] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[   20.032936] rfkill: input handler disabled
[   56.015476] systemd-journald[486]: File /var/log/journal/1ee1fc9b6cdc4cf895119313e2529972/user-1000.journal corrupted or uncleanly shut down, renaming and replacing.
[   56.441048] rfkill: input handler enabled
[   57.651916] snd_hda_intel 0000:00:0e.0: azx_get_response timeout, switching to polling mode: last cmd=0x20bf8100
[   58.655918] snd_hda_intel 0000:00:0e.0: No response from codec, disabling MSI: last cmd=0x20bf8100
[   59.663910] snd_hda_intel 0000:00:0e.0: azx_get_response timeout, switching to single_cmd mode: last cmd=0x20bf8100
[   59.664135] azx_single_wait_for_response: 119 callbacks suppressed
[   71.688065] azx_single_send_cmd: 161 callbacks suppressed

** Model information
sys_vendor: Acer
product_name: TravelMate Spin B311R-31
product_version: V1.18
chassis_vendor: Acer
chassis_version: Chassis Version
bios_vendor: Insyde Corp.
bios_version: V1.18
board_vendor: GLK
board_name: Maracas_GL
board_version: V1.18

** Configuration for modprobe:
blacklist arkfb
blacklist aty128fb
blacklist atyfb
blacklist radeonfb
blacklist cirrusfb
blacklist cyber2000fb
blacklist kyrofb
blacklist matroxfb_base
blacklist mb862xxfb
blacklist neofb
blacklist pm2fb
blacklist pm3fb
blacklist s3fb
blacklist savagefb
blacklist sisfb
blacklist tdfxfb
blacklist tridentfb
blacklist vt8623fb
blacklist microcode
options snd_pcsp index=-2
options cx88_alsa index=-2
options snd_atiixp_modem index=-2
options snd_intel8x0m index=-2
options snd_via82xx_modem index=-2
options bonding max_bonds=0
options dummy numdummies=0
options ifb numifbs=0

** Loaded modules:
ccm
snd_seq_dummy
snd_hrtimer
snd_seq
snd_seq_device
snd_sof_pci_intel_apl
snd_sof_intel_hda_generic
rfcomm
soundwire_intel
cmac
soundwire_generic_allocation
algif_hash
soundwire_cadence
algif_skcipher
snd_sof_intel_hda_common
af_alg
snd_soc_hdac_hda
snd_sof_intel_hda_mlink
snd_sof_intel_hda
snd_hda_codec_hdmi
snd_sof_pci
snd_sof_xtensa_dsp
snd_sof
snd_sof_utils
snd_soc_acpi_intel_match
snd_soc_acpi
soundwire_bus
snd_hda_codec_realtek
snd_soc_avs
snd_hda_codec_generic
snd_soc_hda_codec
snd_hda_scodec_component
snd_hda_ext_core
snd_soc_core
snd_compress
snd_pcm_dmaengine
overlay
bnep
zram
processor_thermal_device_pci_legacy
snd_hda_intel
lz4hc_compress
snd_intel_dspcfg
lz4_compress
i915
processor_thermal_device
x86_pkg_temp_thermal
uvcvideo
intel_powerclamp
snd_intel_sdw_acpi
processor_thermal_wt_hint
coretemp
videobuf2_vmalloc
iwlmvm
btusb
snd_hda_codec
binfmt_misc
processor_thermal_rfim
drm_buddy
kvm_intel
uvc
drm_display_helper
btrtl
snd_hda_core
mac80211
intel_rapl_msr
processor_thermal_rapl
videobuf2_memops
nls_ascii
btintel
snd_hwdep
cec
intel_rapl_common
kvm
libarc4
bmc150_accel_i2c
videobuf2_v4l2
nls_cp437
btbcm
snd_pcm
acer_wmi
rc_core
processor_thermal_wt_req
bmc150_accel_core
iwlwifi
irqbypass
videodev
vfat
btmtk
intel_pmc_core
snd_timer
mei_hdcp
mei_pxp
sparse_keymap
ttm
processor_thermal_power_floor
industrialio_triggered_buffer
rapl
fat
videobuf2_common
rtsx_usb_ms
cfg80211
intel_vsec
snd
bluetooth
platform_profile
mei_me
drm_kms_helper
processor_thermal_mbox
kfifo_buf
intel_cstate
pcspkr
mc
wmi_bmof
memstick
pmt_telemetry
soundcore
rfkill
mei
i2c_algo_bit
intel_soc_dts_iosf
industrialio
int3400_thermal
ac
acer_wireless
int3403_thermal
pmt_class
soc_button_array
button
acpi_thermal_rel
int340x_thermal_zone
joydev
evdev
msr
parport_pc
ppdev
lp
parport
efi_pstore
configfs
nfnetlink
efivarfs
ip_tables
x_tables
autofs4
ext4
crc16
mbcache
jbd2
crc32c_generic
rtsx_usb_sdmmc
rtsx_usb
dm_crypt
dm_mod
crct10dif_pclmul
crc32_pclmul
crc32c_intel
ghash_clmulni_intel
hid_multitouch
sha512_ssse3
hid_generic
sha256_ssse3
xhci_pci
sha1_ssse3
r8169
i2c_hid_acpi
sdhci_pci
xhci_hcd
aesni_intel
nvme
realtek
i2c_hid
intel_lpss_pci
cqhci
usbcore
gf128mul
nvme_core
mdio_devres
hid
intel_lpss
sdhci
i2c_i801
wdat_wdt
crypto_simd
cryptd
watchdog
serio_raw
video
i2c_smbus
lpc_ich
libphy
mmc_core
usb_common
idma64
drm
nvme_auth
battery
wmi

** PCI devices:
00:00.0 Host bridge [0600]: Intel Corporation Gemini Lake Host Bridge [8086:31f0] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	IOMMU group: 1

00:00.1 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor Dynamic Platform and Thermal Framework Processor Participant [8086:318c] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx+
	Latency: 0
	Interrupt: pin B routed to IRQ 24
	IOMMU group: 1
	Region 0: Memory at 80000000 (64-bit, non-prefetchable) [size=32K]
	Capabilities: <access denied>
	Kernel driver in use: proc_thermal
	Kernel modules: processor_thermal_device_pci_legacy

00:00.3 System peripheral [0880]: Intel Corporation Celeron/Pentium Silver Processor Gaussian Mixture Model [8086:3190] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 23
	IOMMU group: 1
	Region 0: Memory at a1318000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>

00:02.0 VGA compatible controller [0300]: Intel Corporation GeminiLake [UHD Graphics 600] [8086:3185] (rev 06) (prog-if 00 [VGA controller])
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 139
	IOMMU group: 0
	Region 0: Memory at a0000000 (64-bit, non-prefetchable) [size=16M]
	Region 2: Memory at 90000000 (64-bit, prefetchable) [size=256M]
	Region 4: I/O ports at 2000 [size=64]
	Expansion ROM at 000c0000 [virtual] [disabled] [size=128K]
	Capabilities: <access denied>
	Kernel driver in use: i915
	Kernel modules: i915

00:0c.0 Network controller [0280]: Intel Corporation Gemini Lake PCH CNVi WiFi [8086:31dc] (rev 06)
	Subsystem: Intel Corporation Wireless-AC 9560 [8086:0034]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 138
	IOMMU group: 2
	Region 0: Memory at a1310000 (64-bit, non-prefetchable) [size=16K]
	Capabilities: <access denied>
	Kernel driver in use: iwlwifi
	Kernel modules: iwlwifi

00:0e.0 Audio device [0403]: Intel Corporation Celeron/Pentium Silver Processor High Definition Audio [8086:3198] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 25
	IOMMU group: 3
	Region 0: Memory at a1314000 (64-bit, non-prefetchable) [size=16K]
	Region 4: Memory at a1000000 (64-bit, non-prefetchable) [size=1M]
	Capabilities: <access denied>
	Kernel driver in use: snd_hda_intel
	Kernel modules: snd_hda_intel, snd_soc_avs, snd_sof_pci_intel_apl

00:0f.0 Communication controller [0780]: Intel Corporation Celeron/Pentium Silver Processor Trusted Execution Engine Interface [8086:319a] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	Interrupt: pin A routed to IRQ 137
	IOMMU group: 4
	Region 0: Memory at a1319000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: mei_me
	Kernel modules: mei_me

00:13.0 PCI bridge [0604]: Intel Corporation Gemini Lake PCI Express Root Port [8086:31d8] (rev f6) (prog-if 00 [Normal decode])
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 122
	IOMMU group: 5
	Bus: primary=00, secondary=01, subordinate=01, sec-latency=0
	I/O behind bridge: [disabled] [16-bit]
	Memory behind bridge: a1200000-a12fffff [size=1M] [32-bit]
	Prefetchable memory behind bridge: [disabled] [64-bit]
	Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
	BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16- MAbort- >Reset- FastB2B-
		PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
	Capabilities: <access denied>
	Kernel driver in use: pcieport

00:14.0 PCI bridge [0604]: Intel Corporation Gemini Lake PCI Express Root Port [8086:31d6] (rev f6) (prog-if 00 [Normal decode])
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 123
	IOMMU group: 6
	Bus: primary=00, secondary=02, subordinate=02, sec-latency=0
	I/O behind bridge: 1000-1fff [size=4K] [16-bit]
	Memory behind bridge: a1100000-a11fffff [size=1M] [32-bit]
	Prefetchable memory behind bridge: [disabled] [64-bit]
	Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
	BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16- MAbort- >Reset- FastB2B-
		PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
	Capabilities: <access denied>
	Kernel driver in use: pcieport

00:15.0 USB controller [0c03]: Intel Corporation Celeron/Pentium Silver Processor USB 3.0 xHCI Controller [8086:31a8] (rev 06) (prog-if 30 [XHCI])
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	Interrupt: pin A routed to IRQ 132
	IOMMU group: 7
	Region 0: Memory at a1300000 (64-bit, non-prefetchable) [size=64K]
	Capabilities: <access denied>
	Kernel driver in use: xhci_hcd
	Kernel modules: xhci_pci

00:16.0 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor I2C 0 [8086:31ac] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 27
	IOMMU group: 8
	Region 0: Memory at a131a000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a131b000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:16.3 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor I2C 3 [8086:31b2] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin D routed to IRQ 30
	IOMMU group: 8
	Region 0: Memory at a131c000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a131d000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:17.0 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor I2C 4 [8086:31b4] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 31
	IOMMU group: 9
	Region 0: Memory at a131e000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a131f000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:17.1 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor I2C 5 [8086:31b6] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin B routed to IRQ 32
	IOMMU group: 9
	Region 0: Memory at a1320000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a1321000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:17.2 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor I2C 6 [8086:31b8] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin C routed to IRQ 33
	IOMMU group: 9
	Region 0: Memory at a1322000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a1323000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:18.0 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor Serial IO UART Host Controller [8086:31bc] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 4
	IOMMU group: 10
	Region 0: Memory at a1324000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a1325000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:18.1 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor Serial IO UART Host Controller [8086:31be] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin B routed to IRQ 5
	IOMMU group: 10
	Region 0: Memory at a1326000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a1327000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:18.3 Signal processing controller [1180]: Intel Corporation Celeron/Pentium Silver Processor Serial IO UART Host Controller [8086:31ee] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin D routed to IRQ 7
	IOMMU group: 10
	Region 0: Memory at a1328000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a1329000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci

00:1c.0 SD Host controller [0805]: Intel Corporation Celeron/Pentium Silver Processor SDA Standard Compliant SD Host Controller [8086:31cc] (rev 06) (prog-if 01)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 39
	IOMMU group: 11
	Region 0: Memory at a132a000 (64-bit, non-prefetchable) [size=4K]
	Region 2: Memory at a132b000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: sdhci-pci
	Kernel modules: sdhci_pci

00:1f.0 ISA bridge [0601]: Intel Corporation Celeron/Pentium Silver Processor LPC Controller [8086:31e8] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	IOMMU group: 12
	Kernel modules: lpc_ich

00:1f.1 SMBus [0c05]: Intel Corporation Celeron/Pentium Silver Processor Gaussian Mixture Model [8086:31d4] (rev 06)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O+ Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap- 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Interrupt: pin A routed to IRQ 20
	IOMMU group: 12
	Region 0: Memory at a132c000 (64-bit, non-prefetchable) [size=256]
	Region 4: I/O ports at 2040 [size=32]
	Kernel driver in use: i801_smbus
	Kernel modules: i2c_i801

01:00.0 Non-Volatile memory controller [0108]: Kingston Technology Company, Inc. OM3PDP3 NVMe SSD [2646:500d] (rev 01) (prog-if 02 [NVM Express])
	Subsystem: Kingston Technology Company, Inc. OM3PDP3 NVMe SSD [2646:500d]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 22
	IOMMU group: 13
	Region 0: Memory at a1200000 (64-bit, non-prefetchable) [size=16K]
	Capabilities: <access denied>
	Kernel driver in use: nvme
	Kernel modules: nvme

02:00.0 Ethernet controller [0200]: Realtek Semiconductor Co., Ltd. RTL8111/8168/8211/8411 PCI Express Gigabit Ethernet Controller [10ec:8168] (rev 15)
	Subsystem: Acer Incorporated [ALI] Device [1025:1430]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 22
	IOMMU group: 14
	Region 0: I/O ports at 1000 [size=256]
	Region 2: Memory at a1104000 (64-bit, non-prefetchable) [size=4K]
	Region 4: Memory at a1100000 (64-bit, non-prefetchable) [size=16K]
	Capabilities: <access denied>
	Kernel driver in use: r8169
	Kernel modules: r8169


** USB devices:
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 001 Device 002: ID 04f2:b6db Chicony Electronics Co., Ltd 5MP World Facing
Bus 001 Device 003: ID 0408:a061 Quanta Computer, Inc. HD User Facing
Bus 001 Device 004: ID 0bda:0129 Realtek Semiconductor Corp. RTS5129 Card Reader Controller
Bus 001 Device 005: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak (JfP)
Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub


-- System Information:
Debian Release: 13.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 6.12.27-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_DIE
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages linux-image-6.12.27-amd64 depends on:
ii  initramfs-tools [linux-initramfs-tool]  0.147
ii  kmod                                    34.2-2
ii  linux-base                              4.11

Versions of packages linux-image-6.12.27-amd64 recommends:
ii  apparmor  4.1.0-1

Versions of packages linux-image-6.12.27-amd64 suggests:
pn  debian-kernel-handbook  <none>
ii  firmware-linux-free     20241210-2
ii  grub-efi-amd64          2.12-7
pn  linux-doc-6.12          <none>

Versions of packages linux-image-6.12.27-amd64 is related to:
ii  firmware-amd-graphics      20250410-2
pn  firmware-atheros           <none>
pn  firmware-bnx2              <none>
pn  firmware-bnx2x             <none>
pn  firmware-brcm80211         <none>
pn  firmware-cavium            <none>
pn  firmware-cirrus            <none>
pn  firmware-intel-graphics    <none>
pn  firmware-intel-misc        <none>
pn  firmware-intel-sound       <none>
pn  firmware-ipw2x00           <none>
pn  firmware-ivtv              <none>
ii  firmware-iwlwifi           20250410-2
pn  firmware-libertas          <none>
pn  firmware-marvell-prestera  <none>
pn  firmware-mediatek          <none>
ii  firmware-misc-nonfree      20250410-2
pn  firmware-myricom           <none>
pn  firmware-netronome         <none>
pn  firmware-netxen            <none>
pn  firmware-nvidia-graphics   <none>
pn  firmware-qcom-soc          <none>
pn  firmware-qlogic            <none>
ii  firmware-realtek           20250410-2
pn  firmware-samsung           <none>
pn  firmware-siano             <none>
pn  firmware-ti-connectivity   <none>
pn  xen-hypervisor             <none>

-- no debconf information

[toc] | [next] | [standalone]


#87679 — Processed: Re: Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2025-05-25 17:00 +0200
SubjectProcessed: Re: Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core
Message-ID<KQkZr-5DYZ-3@gated-at.bofh.it>
In reply to#87671
Processing control commands:

> tags -1 + moreinfo
Bug #1106411 [src:linux] linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core
Added tag(s) moreinfo.

-- 
1106411: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106411
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#87680

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-05-25 17:00 +0200
Message-ID<KQkZr-5DYZ-1@gated-at.bofh.it>
In reply to#87671
Control: tags -1 + moreinfo

Hi Kim,

On Sat, May 24, 2025 at 04:44:05PM +0200, Kim Alvefur wrote:
> Package: src:linux
> Version: 6.12.27-1
> Severity: important
> X-Debbugs-Cc: debian-amd64@lists.debian.org
> User: debian-amd64@lists.debian.org
> Usertags: amd64
> 
> Dear Maintainer,
> 
> I noticed a kernel BUG line in the logs.
> 
> > BUG: kernel NULL pointer dereference, address: 0000000000000001
> 
> -- Package-specific info:
> ** Version:
> Linux version 6.12.27-amd64 (debian-kernel@lists.debian.org) (x86_64-linux-gnu-gcc-14 (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44) #1 SMP PREEMPT_DYNAMIC Debian 6.12.27-1 (2025-05-06)
> 
> ** Command line:
> BOOT_IMAGE=/vmlinuz-6.12.27-amd64 root=/dev/mapper/spisula--vg-root ro quiet
> 
> ** Tainted: D (128)
>  * kernel died recently, i.e. there was an OOPS or BUG
> 
> ** Kernel log:
> [   15.089146] RDX: ffffffff83326d30 RSI: 0000000000000202 RDI: ffff9a9190947504
> [   15.089148] RBP: ffff9a9190947420 R08: ffff9a919c498be8 R09: 0000000000000000
> [   15.089149] R10: ffffb83f40d27ac8 R11: 0000000000000009 R12: ffff9a919c498d50
> [   15.089151] R13: 0000000000000000 R14: 0000000000000001 R15: ffff9a919c498b30
> [   15.089153] FS:  00007f10b2d30940(0000) GS:ffff9a91fbd00000(0000) knlGS:0000000000000000
> [   15.089155] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [   15.089157] CR2: 0000000000000001 CR3: 000000011c33c000 CR4: 0000000000352ef0
> [   15.089159] Call Trace:
> [   15.089163]  <TASK>
> [   15.089167]  bmc150_accel_buffer_postenable+0x5d/0x90 [bmc150_accel_core]
> [   15.089173]  __iio_update_buffers+0x731/0xb20 [industrialio]
> [   15.089198]  enable_store+0x84/0xe0 [industrialio]
> [   15.089214]  kernfs_fop_write_iter+0x13b/0x1f0
> [   15.089222]  vfs_write+0x28d/0x450
> [   15.089230]  ksys_write+0x6d/0xf0
> [   15.089235]  do_syscall_64+0x82/0x190
> [   15.089241]  ? syscall_exit_to_user_mode+0x4d/0x210
> [   15.089245]  ? do_syscall_64+0x8e/0x190
> [   15.089248]  ? __memcg_slab_free_hook+0xf7/0x140
> [   15.089253]  ? __x64_sys_close+0x3c/0x80
> [   15.089255]  ? kmem_cache_free+0x3ee/0x440
> [   15.089260]  ? syscall_exit_to_user_mode+0x4d/0x210
> [   15.089263]  ? do_syscall_64+0x8e/0x190
> [   15.089265]  ? kernfs_fop_write_iter+0x9d/0x1f0
> [   15.089268]  ? vfs_write+0x28d/0x450
> [   15.089272]  ? syscall_exit_to_user_mode+0x4d/0x210
> [   15.089275]  ? clear_bhb_loop+0x25/0x80
> [   15.089279]  ? clear_bhb_loop+0x25/0x80
> [   15.089281]  ? clear_bhb_loop+0x25/0x80
> [   15.089284]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
> [   15.089288] RIP: 0033:0x7f10b31369ee
> [   15.089319] Code: 08 0f 85 f5 4b ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
> [   15.089321] RSP: 002b:00007ffc6dbe57d8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
> [   15.089324] RAX: ffffffffffffffda RBX: 00007f10b2d30940 RCX: 00007f10b31369ee
> [   15.089325] RDX: 0000000000000001 RSI: 00007ffc6dbe5980 RDI: 0000000000000009
> [   15.089327] RBP: 00007ffc6dbe5980 R08: 0000000000000000 R09: 0000000000000000
> [   15.089328] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
> [   15.089329] R13: 0000559ac7f662a0 R14: 00007f10b3281e80 R15: 0000000000000001
> [   15.089333]  </TASK>
> [   15.089333] Modules linked in: snd_hda_ext_core snd_soc_core snd_compress snd_pcm_dmaengine overlay bnep zram processor_thermal_device_pci_legacy snd_hda_intel lz4hc_compress snd_intel_dspcfg lz4_compress i915(+) processor_thermal_device x86_pkg_temp_thermal uvcvideo intel_powerclamp snd_intel_sdw_acpi processor_thermal_wt_hint coretemp videobuf2_vmalloc iwlmvm btusb snd_hda_codec binfmt_misc processor_thermal_rfim drm_buddy kvm_intel uvc drm_display_helper btrtl snd_hda_core mac80211 intel_rapl_msr processor_thermal_rapl videobuf2_memops nls_ascii btintel snd_hwdep cec intel_rapl_common kvm libarc4 bmc150_accel_i2c videobuf2_v4l2 nls_cp437 btbcm snd_pcm acer_wmi rc_core processor_thermal_wt_req bmc150_accel_core iwlwifi irqbypass videodev vfat btmtk intel_pmc_core snd_timer mei_hdcp mei_pxp sparse_keymap ttm processor_thermal_power_floor industrialio_triggered_buffer rapl fat videobuf2_common rtsx_usb_ms cfg80211 intel_vsec snd bluetooth platform_profile mei_me drm_kms_helper processor_thermal_mbox kfifo_buf
> [   15.089389]  intel_cstate pcspkr mc wmi_bmof memstick pmt_telemetry soundcore rfkill mei i2c_algo_bit intel_soc_dts_iosf industrialio int3400_thermal ac acer_wireless int3403_thermal pmt_class soc_button_array button acpi_thermal_rel int340x_thermal_zone joydev evdev msr parport_pc ppdev lp parport efi_pstore configfs nfnetlink efivarfs ip_tables x_tables autofs4 ext4 crc16 mbcache jbd2 crc32c_generic rtsx_usb_sdmmc rtsx_usb dm_crypt dm_mod crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel hid_multitouch sha512_ssse3 hid_generic sha256_ssse3 xhci_pci sha1_ssse3 r8169 i2c_hid_acpi sdhci_pci xhci_hcd aesni_intel nvme realtek i2c_hid intel_lpss_pci cqhci usbcore gf128mul nvme_core mdio_devres hid intel_lpss sdhci i2c_i801 wdat_wdt crypto_simd cryptd watchdog serio_raw video i2c_smbus lpc_ich libphy mmc_core usb_common idma64 drm nvme_auth battery wmi
> [   15.089449] CR2: 0000000000000001
> [   15.089451] ---[ end trace 0000000000000000 ]---
> [   15.207536] RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core]
> [   15.207561] Code: 84 86 00 00 00 ba 01 00 00 00 f0 0f c1 10 83 c2 01 83 fa 01 7f 64 49 8b 3c 24 be 01 00 00 00 e8 5e fc ff ff 89 c3 85 c0 75 52 <41> 0f b6 55 01 41 0f b6 75 00 45 31 c9 45 31 c0 49 8b 3c 24 6a 00
> [   15.207563] RSP: 0018:ffffb83f40d27ab0 EFLAGS: 00010246
> [   15.207567] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00000000ffffff01
> [   15.207569] RDX: ffffffff83326d30 RSI: 0000000000000202 RDI: ffff9a9190947504
> [   15.207571] RBP: ffff9a9190947420 R08: ffff9a919c498be8 R09: 0000000000000000
> [   15.207572] R10: ffffb83f40d27ac8 R11: 0000000000000009 R12: ffff9a919c498d50
> [   15.207574] R13: 0000000000000000 R14: 0000000000000001 R15: ffff9a919c498b30
> [   15.207575] FS:  00007f10b2d30940(0000) GS:ffff9a91fbd00000(0000) knlGS:0000000000000000
> [   15.207577] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [   15.207579] CR2: 0000000000000001 CR3: 000000011c33c000 CR4: 0000000000352ef0
> [   15.207582] note: iio-sensor-prox[804] exited with irqs disabled
> [   15.281160] Generic FE-GE Realtek PHY r8169-0-200:00: attached PHY driver (mii_bus:phy_addr=r8169-0-200:00, irq=MAC)
> [   15.300168] snd_hda_codec_realtek hdaudioC0D0: autoconfig for ALC256: line_outs=1 (0x14/0x0/0x0/0x0/0x0) type:speaker
> [   15.300176] snd_hda_codec_realtek hdaudioC0D0:    speaker_outs=0 (0x0/0x0/0x0/0x0/0x0)
> [   15.300179] snd_hda_codec_realtek hdaudioC0D0:    hp_outs=1 (0x21/0x0/0x0/0x0/0x0)
> [   15.300181] snd_hda_codec_realtek hdaudioC0D0:    mono: mono_out=0x0
> [   15.300182] snd_hda_codec_realtek hdaudioC0D0:    inputs:
> [   15.300184] snd_hda_codec_realtek hdaudioC0D0:      Internal Mic=0x12
> [   15.300186] snd_hda_codec_realtek hdaudioC0D0:      Headset Mic=0x19
> [   15.461236] r8169 0000:02:00.0 enp2s0: Link is Down
> [   15.666827] iwlwifi 0000:00:0c.0: Registered PHC clock: iwlwifi-PTP, with index: 0
> [   15.749241] Bluetooth: hci0: Waiting for firmware download to complete
> [   15.749426] Bluetooth: hci0: Firmware loaded in 1795145 usecs
> [   15.749520] Bluetooth: hci0: Waiting for device to boot
> [   15.753647] input: HDA Digital PCBeep as /devices/pci0000:00/0000:00:0e.0/sound/card0/input23
> [   15.753728] input: HDA Intel PCH Front Headphone as /devices/pci0000:00/0000:00:0e.0/sound/card0/input24
> [   15.753797] input: HDA Intel PCH HDMI/DP,pcm=3 as /devices/pci0000:00/0000:00:0e.0/sound/card0/input25
> [   15.753859] input: HDA Intel PCH HDMI/DP,pcm=7 as /devices/pci0000:00/0000:00:0e.0/sound/card0/input26
> [   15.753929] input: HDA Intel PCH HDMI/DP,pcm=8 as /devices/pci0000:00/0000:00:0e.0/sound/card0/input27
> [   15.763426] Bluetooth: hci0: Device booted in 13644 usecs
> [   15.764861] Bluetooth: hci0: Found Intel DDC parameters: intel/ibt-17-16-1.ddc
> [   15.766480] Bluetooth: hci0: Applying Intel DDC parameters completed
> [   15.767483] Bluetooth: hci0: Firmware revision 0.1 build 201 week 12 2024
> [   15.769492] Bluetooth: hci0: HCI LE Coded PHY feature bit is set, but its usage is not supported.
> [   15.825248] Bluetooth: MGMT ver 1.23
> [   15.862572] NET: Registered PF_ALG protocol family
> [   16.107882] Console: switching to colour frame buffer device 170x48
> [   16.186327] i915 0000:00:02.0: [drm] fb0: i915drmfb frame buffer device
> [   16.188401] Bluetooth: RFCOMM TTY layer initialized
> [   16.189294] Bluetooth: RFCOMM socket layer initialized
> [   16.190089] Bluetooth: RFCOMM ver 1.11
> [   18.899809] wlp0s12f0: authenticate with 14:91:82:2e:1c:5b (local address=f4:b3:01:63:29:78)
> [   18.900292] wlp0s12f0: send auth to 14:91:82:2e:1c:5b (try 1/3)
> [   18.939856] wlp0s12f0: authenticated
> [   18.941129] wlp0s12f0: associate with 14:91:82:2e:1c:5b (try 1/3)
> [   18.960084] wlp0s12f0: RX AssocResp from 14:91:82:2e:1c:5b (capab=0x11 status=0 aid=2)
> [   18.963364] wlp0s12f0: associated
> [   19.726378] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
> [   20.032936] rfkill: input handler disabled
> [   56.015476] systemd-journald[486]: File /var/log/journal/1ee1fc9b6cdc4cf895119313e2529972/user-1000.journal corrupted or uncleanly shut down, renaming and replacing.
> [   56.441048] rfkill: input handler enabled
> [   57.651916] snd_hda_intel 0000:00:0e.0: azx_get_response timeout, switching to polling mode: last cmd=0x20bf8100
> [   58.655918] snd_hda_intel 0000:00:0e.0: No response from codec, disabling MSI: last cmd=0x20bf8100
> [   59.663910] snd_hda_intel 0000:00:0e.0: azx_get_response timeout, switching to single_cmd mode: last cmd=0x20bf8100
> [   59.664135] azx_single_wait_for_response: 119 callbacks suppressed
> [   71.688065] azx_single_send_cmd: 161 callbacks suppressed

Can you please test 6.12.29-1 from unstable (and which should migrate
soon to trixie)?

If you can reproduce the issue, can you please post the full kernel
log once the issue has happened, so we get the full context (The
previous log is capped).

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#87792

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-05-31 21:00 +0200
Message-ID<KSzAZ-74SF-1@gated-at.bofh.it>
In reply to#87671
Control: tags -1 + moreinfo

Hi Kim,

On Fri, May 30, 2025 at 07:42:12PM +0200, Kim Alvefur wrote:
> On Sun, May 25, 2025 at 04:50:14PM +0200, Salvatore Bonaccorso wrote:
> > Can you please test 6.12.29-1 from unstable (and which should migrate
> > soon to trixie)?
> > 
> > If you can reproduce the issue, can you please post the full kernel
> > log once the issue has happened, so we get the full context (The
> > previous log is capped).
> 
> Output of `journalctl --boot --dmseg` from 6.12.29 attached.
> 
> So far it seems to happen on every boot, between unlocking LUKS and the
> login manager starting.
> 
> I wonder if this is related to another symptom this machine has, where
> it fails to complete suspend and goes into a state where the only action
> that has any effect is a long-press of the power button to turn it off.

Thanks for providing the full log, going through it.

One additional preliminary question, since I missed to ask it in the
earlier reply: Is this a regression you are seeing when updating to
6.12.27-1 (and later)? If so can you pinpoint the Debian revision
where you first saw this happening?

In case we have a regression, would you be able to bisect the
respective upstream stable versions to pinpoint the breaking commit,
which would be helpful for the upstream report?

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#87793 — Processed: Re: Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2025-05-31 21:00 +0200
SubjectProcessed: Re: Bug#1106411: linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core
Message-ID<KSzB0-74SF-7@gated-at.bofh.it>
In reply to#87671
Processing control commands:

> tags -1 + moreinfo
Bug #1106411 [src:linux] linux-image-6.12.27-amd64: kernel NULL pointer dereference in bmc150_accel_core
Added tag(s) moreinfo.

-- 
1106411: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106411
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#87797 — Bug#1106411: kernel NULL pointer dereference in bmc150_accel_core / RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core]

FromKim Alvefur <zash@zash.se>
Date2025-06-01 00:10 +0200
SubjectBug#1106411: kernel NULL pointer dereference in bmc150_accel_core / RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core]
Message-ID<KSCyR-772b-1@gated-at.bofh.it>
In reply to#87671
On Sat, May 31, 2025 at 09:34:03PM +0200, Salvatore Bonaccorso wrote:
>On Fri, May 30, 2025 at 07:42:12PM +0200, Kim Alvefur wrote:
>> So far it seems to happen on every boot, between unlocking LUKS and the
>> login manager starting.
>>
>> I wonder if this is related to another symptom this machine has, where
>> it fails to complete suspend and goes into a state where the only action
>> that has any effect is a long-press of the power button to turn it off.
>
>Looking through the boot log I'm noticing the following:
>
>> May 30 19:21:47 spisula kernel: bmc150_accel_i2c i2c-BOSC0200:00: supply vdd not found, using dummy regulator
>> May 30 19:21:47 spisula kernel: bmc150_accel_i2c i2c-BOSC0200:00: supply vddio not found, using dummy regulator
>[...]
>> May 30 19:21:47 spisula kernel: bmc150_accel_i2c i2c-BOSC0200:base: supply vdd not found, using dummy regulator
>> May 30 19:21:47 spisula kernel: bmc150_accel_i2c i2c-BOSC0200:base: supply vddio not found, using dummy regulator
>
>and iio-sensor-proxy might fail to handle then the bosch 0200
>accelerometer. You proobably cannot temporary purge the
>iio-sensor-proxy if installed by reverse dependencies, but might you
>try to temporarily mask the service and retest a boot?

That seems to have an effect, no "BUG: ..." in dmesg now, and the
machine made it trough a suspends and resume cycle.

-- 
Kim "Zash" Alvefur

[toc] | [prev] | [next] | [standalone]


#88463 — Bug#1106411: kernel NULL pointer dereference in bmc150_accel_core / RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core]

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-07-17 23:20 +0200
SubjectBug#1106411: kernel NULL pointer dereference in bmc150_accel_core / RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120 [bmc150_accel_core]
Message-ID<L9Ebf-K2r-1@gated-at.bofh.it>
In reply to#87797
Hi

FTR, the patch submitted a while ago
https://lore.kernel.org/linux-iio/20250613124648.14141-1-marek.vasut+bmc150@mailbox.org/
raised some discussion on the proper fix, and AFAIK there was not yet
a conclusion.

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#87840

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-06-04 09:40 +0200
Message-ID<KTQT7-8622-1@gated-at.bofh.it>
In reply to#87671
Hi Kim,

On Sat, May 31, 2025 at 11:41:49PM +0200, Kim Alvefur wrote:
> Hi Salvatore,
> 
> On Sat, May 31, 2025 at 08:53:26PM +0200, Salvatore Bonaccorso wrote:
> > One additional preliminary question, since I missed to ask it in the
> > earlier reply: Is this a regression you are seeing when updating to
> > 6.12.27-1 (and later)? If so can you pinpoint the Debian revision
> > where you first saw this happening?
> 
> Looking at earlier kernel logs in the journal, this happened for the
> first time in March, which was after I upgraded to Debian 13.
> 
> Using Debian snapshots I tried a few older kernels, the earliest being
> 6.12.6-1 from late 2024 and it happened there too.
> 
> > In case we have a regression, would you be able to bisect the
> > respective upstream stable versions to pinpoint the breaking commit,
> > which would be helpful for the upstream report?
> 
> I can certainly try, at least using repository snapshots to narrow it
> down. It has been many years since I last compiled a kernel, so I could
> do with a refresher there :)
> 
> Any suggestions for how far back to go?

If you updates from bookworm to trixie then start with the bookworm
based kernel and bisect there the debian image versions first until we
get a closer range where an upstream change happened.

Note I have forwarded the report to usptream but so far no reaction.
It might actually be that with the trixie system and the older kernel
you will hit now the issue as well as it is just undovered by having 
iio-sensor-proxy running (you could double check in your apt/dpkg logs
if it was already installed under bookworm though).

Once we have a closer range, bisecting the upstream changes would be
the next step.

I still have some hope that we get on board upstream people :)

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#87849

FromKim Alvefur <zash@zash.se>
Date2025-06-04 13:10 +0200
Message-ID<KTUam-88kU-13@gated-at.bofh.it>
In reply to#87840
Hi Salvatore,

Thanks for all your help so far!

On Wed, Jun 04, 2025 at 09:32:05AM +0200, Salvatore Bonaccorso wrote:
>If you updates from bookworm to trixie then start with the bookworm
>based kernel and bisect there the debian image versions first until we
>get a closer range where an upstream change happened.

>Note I have forwarded the report to usptream but so far no reaction.
>It might actually be that with the trixie system and the older kernel
>you will hit now the issue as well as it is just undovered by having
>iio-sensor-proxy running (you could double check in your apt/dpkg logs
>if it was already installed under bookworm though).

I installed the bookworm kernel and the null pointer dereference
happened there too with iio-sensor-proxy unmasked.

After also downgrading iio-sensor-proxy to the bookworm version it did
not happen, which explains why I never saw this while on bookworm.

Older iio-s-p on kernel 6.12.29 doesn't trigger it either.

 From what I can tell, iio-sensor-proxy was installed before upgrading to
trixie, it was upgraded from 3.0-2 to 3.5-2 on Feb 27 which was when I
upgraded to trixie.

Tried downgrading to linux 5.10.0-32 from oldstable, with iio-s-p from
trixie, not seeing the null pointer deref then.

iio-sensor-proxy says this:
Jun 04 12:58:44 spisula systemd[1]: Starting iio-sensor-proxy.service - IIO Sensor Proxy service...
Jun 04 12:58:44 spisula systemd[1]: Started iio-sensor-proxy.service - IIO Sensor Proxy service.
Jun 04 12:58:44 spisula iio-sensor-prox[2532]: Could not find trigger name associated with /sys/devices/pci0000:00/0000:00:16.0/i2c_designware.0/i2c-0/i2c-BOSC0200:00/iio:device0
Jun 04 12:58:44 spisula iio-sensor-prox[2532]: Could not write to '/sys/devices/pci0000:00/0000:00:16.0/i2c_designware.0/i2c-0/i2c-BOSC0200:00/iio:device0/buffer/enable': Operation not permitted
Jun 04 12:58:44 spisula iio-sensor-prox[2532]: Unable to enable ring buffer for /sys/devices/pci0000:00/0000:00:16.0/i2c_designware.0/i2c-0/i2c-BOSC0200:00/iio:device0
Jun 04 12:58:44 spisula iio-sensor-prox[2532]: Not a switch [/sys/devices/pci0000:00/0000:00:16.0/i2c_designware.0/i2c-0/i2c-BOSC0200:00/iio:device0/../capabilities/sw]
Jun 04 12:58:44 spisula iio-sensor-prox[2532]: Invalid bitmask entry for /sys/devices/LNXSYSTM:00/LNXPWRBN:00/input/input18/event9

-- 
Kim

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web