#1133144 linux-image-6.19.10+deb14-amd64: Kernel panic for module mt76 with mt792x_lib

Package:
src:linux
Source:
src:linux
Submitter:
Hendrik Bruinsma
Date:
2026-04-21 12:41:00 UTC
Severity:
normal
Tags:
#1133144#5
Date:
2026-04-10 12:31:16 UTC
From:
To:
Dear Maintainer,

It looks like (as far as I can see with the information of the
crashlog), the
wifi module caused a kernel panic.
Is there in anyway I can add more information to help out with this?


Cheers, Hendrik
------

Below the kernel panic log:

[60324.959946] Tainted: [D]=DIE
[60324.959947] Hardware name: HP HP EliteBook X G1a 14 AI/8D08, BIOS X88
Ver.
01.01.02 11/08/2024
[60324.959948] RIP: 0010:__kmem_cache_alloc_bulk+0x66/0x220
[60324.959959] Code: 48 83 c0 20 65 48 03 05 c0 ec 57 02 c6 00 01 48 85
d2 0f
84 b9 01 00 00 49 89 d5 31 db 45 31 e4 eb 34 41 8b 57 30 48 8d 34 02
<48> 8b 14
10 49 33 97 c0 00 00 00 48 0f ce 48 31 f2 49 89 10 48 89
[60324.959960] RSP: 0018:ffffcb8980defbe8 EFLAGS: 00010086
[60324.959962] RAX: affece1108100624 RBX: 0000000000000000 RCX:
0000000000000283
[60324.959963] RDX: 0000000000000070 RSI: affece1108100694 RDI:
ffff8a5340833800
[60324.959963] RBP: ffff8a6251130678 R08: ffff8a6251139b40 R09:
0000000000000800
[60324.959964] R10: ffff8a6295ce2060 R11: ffff8a6295ce2060 R12:
0000000000000000
[60324.959964] R13: 0000000000000020 R14: ffff8a6251130678 R15:
ffff8a5340833800
[60324.959966] FS: 0000000000000000(0000) GS:ffff8a62b42a7000(0000)
knlGS:0000000000000000
[60324.959966] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[60324.959967] CR2: 00007ff305044000 CR3: 000000083d22c000 CR4:
0000000000f50ef0
[60324.959968] PKRU: 55555554
[60324.959968] Call Trace:
[60324.959971] <TASK>
[60324.959973] kmem_cache_alloc_bulk_noprof+0x347/0x460
[60324.959975] ? netif_receive_skb_list_internal+0x1e7/0x300
[60324.959979] napi_skb_cache_get+0x8a/0x110
[60324.959985] ? mt76_set_irq_mask+0x2e/0xc0 [mt76]
[60324.959991] __napi_build_skb+0x19/0x70
[60324.959992] napi_build_skb+0x15/0xb0
[60324.959994] mt76_dma_rx_poll+0x507/0x7a0 [mt76]
[60324.960000] mt792x_poll_rx+0x52/0xe0 [mt792x_lib]
[60324.960004] __napi_poll+0x30/0x1d0
[60324.960006] ? psi_task_switch+0x18d/0x390
[60324.960009] napi_threaded_poll_loop+0x211/0x260
[60324.960010] ? __pfx_napi_threaded_poll+0x10/0x10
[60324.960011] napi_threaded_poll+0xdf/0x120
[60324.960012] kthread+0xfc/0x240
[60324.960015] ? __pfx_kthread+0x10/0x10
[60324.960016] ret_from_fork+0x24d/0x290
[60324.960020] ? __pfx_kthread+0x10/0x10
[60324.960020] ret_from_fork_asm+0x1a/0x30
[60324.960024] </TASK>
[60324.960024] Modules linked in: nft_ct nft_fib_inet nft_fib_ipv4
nft_fib_ipv6
nft_fib nft_masq veth tun sd_mod scsi_mod scsi_common snd_seq_dummy
snd_hrtimer
rfcomm snd_seq snd_seq_device ccm xt_CHECKSUM xt_MASQUERADE xt_conntrack
ipt_REJECT xt_tcpudp nft_compat x_tables uhid cmac algif_hash algif_skcipher
af_alg bridge snd_acp_legacy_mach snd_acp_mach snd_soc_nau8821 stp
snd_acp3x_rn
llc snd_acp70 snd_acp_i2s snd_acp_pdm snd_acp_pcm snd_soc_dmic
snd_sof_amd_rembrandt snd_sof_amd_acp snd_sof_pci qrtr snd_sof_xtensa_dsp
overlay snd_sof snd_sof_utils snd_pci_ps snd_soc_acpi_amd_match
snd_amd_sdw_acpi soundwire_amd soundwire_generic_allocation
soundwire_bus bnep
snd_hda_codec_alc269 snd_soc_sdca snd_hda_scodec_component amd_atl
intel_rapl_msr snd_soc_core snd_hda_codec_realtek_lib snd_hda_codec_atihdmi
snd_hda_scodec_cs35l56_spi intel_rapl_common regmap_spi
snd_hda_codec_generic
snd_hda_codec_hdmi snd_compress snd_hda_intel mt7925e snd_pcm_dmaengine
snd_rpl_pci_acp6x mt7925_common snd_hda_codec snd_acp_pci btusb
[60324.960056] mt792x_lib uvcvideo snd_amd_acpi_mach snd_hda_core btmtk
mt76_connac_lib videobuf2_vmalloc snd_acp_legacy_common snd_intel_dspcfg
btrtl
uvc snd_hda_scodec_cs35l56_i2c mt76 hp_bioscfg snd_pci_acp6x edac_mce_amd
snd_intel_sdw_acpi btbcm videobuf2_memops snd_hda_scodec_cs35l56 mac80211
hid_sensor_gyro_3d hid_sensor_prox firmware_attributes_class snd_pci_acp5x
snd_hwdep kvm_amd nls_ascii btintel videobuf2_v4l2 snd_hda_cirrus_scodec
hid_sensor_trigger snd_rn_pci_acp3x snd_pcm snd_soc_cs35l56_shared
hid_sensor_iio_common nls_cp437 kvm hp_wmi amd_pmf videodev spd5118
snd_soc_cs_amp_lib snd_acp_config industrialio_triggered_buffer bluetooth
snd_timer vfat cfg80211 amdtee kfifo_buf irqbypass ecdh_generic
sparse_keymap
videobuf2_common amdxdna i2c_piix4 cs_dsp snd_soc_acpi snd fat tee
industrialio
rapl rfkill wmi_bmof pcspkr mc drm_shmem_helper i2c_smbus k10temp libarc4
snd_pci_acp3x soundcore serial_multi_instantiate amd_pmc acpi_tad ac
platform_profile joydev evdev nft_reject_inet nf_reject_ipv4 binfmt_misc
[60324.960088] nf_reject_ipv6 nft_reject nft_chain_nat nf_nat nf_conntrack
nf_defrag_ipv6 nf_defrag_ipv4 nf_tables lp ppdev parport_pc parport configfs
efi_pstore nfnetlink crc32c_cryptoapi hid_sensor_hub btrfs blake2b
libblake2b
xor raid6_pq dm_crypt usbhid amdgpu amdxcp drm_panel_backlight_quirks
gpu_sched
drm_buddy drm_ttm_helper ttm drm_exec i2c_algo_bit drm_suballoc_helper
drm_display_helper ucsi_acpi typec_ucsi cec roles hid_multitouch typec
rc_core
nvme hid_generic xhci_pci nvme_core xhci_hcd drm_client_lib i2c_hid_acpi
nvme_keyring drm_kms_helper i2c_hid usbcore nvme_auth thunderbolt video
amd_sfh
sp5100_tco ghash_clmulni_intel drm hid ccp crc16 hkdf battery wmi usb_common
watchdog button serio_raw dm_mirror dm_region_hash dm_log dm_mod i2c_dev msr
efivarfs autofs4 aesni_intel
[60324.960122] ---[ end trace 0000000000000000 ]---
[60324.970034] cs35l56-hda i2c-CSC3554:00-cs35l54-hda.1: MBOX command
0xb000001
failed: -16
[60324.970042] cs35l56-hda i2c-CSC3554:00-cs35l54-hda.2: MBOX command
0xb000001
failed: -16
[60324.974590] RIP: 0010:kmem_cache_alloc_node_noprof+0x47d/0x610
[60324.974597] Code: c2 e9 ec fc ff ff 48 85 ff 0f 84 4c ff ff ff 48 85
c9 0f
84 43 ff ff ff 41 ba ff ff ff ff 41 8b 44 24 30 49 8b 34 24 48 01 f8
<4c> 8b 18
48 89 c1 4d 33 9c 24 c0 00 00 00 48 89 f8 48 0f c9 49 31
[60324.974598] RSP: 0018:ffffcb898cb07920 EFLAGS: 00010282
[60324.974600] RAX: affece1108100694 RBX: 0000000000000000 RCX:
fffffb2984401380
[60324.974601] RDX: 0000000979e18004 RSI: ffffffff9ce92b40 RDI:
affece1108100624
[60324.974601] RBP: ffffcb898cb07988 R08: 00000000000000e8 R09:
ffffffff9b0768f8
[60324.974601] R10: 00000000ffffffff R11: 000000000000001d R12:
ffff8a5340833800
[60324.974602] R13: 0000000000400cc0 R14: 00000000ffffffff R15:
0000000000000000
[60324.974603] FS: 0000000000000000(0000) GS:ffff8a62b42a7000(0000)
knlGS:0000000000000000
[60324.974603] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[60324.974604] CR2: 00007ff305044000 CR3: 000000083d22c000 CR4:
0000000000f50ef0
[60324.974604] PKRU: 55555554
[60324.974606] Kernel panic - not syncing: Fatal exception in interrupt
[60324.975059] Kernel Offset: 0x19200000 from 0xffffffff81000000 (relocation
range: 0xffffffff80000000-0xffffffffbfffffff)

#1133144#10
Date:
2026-04-10 14:46:51 UTC
From:
To:
Hi Hendrik,

Is this issue reproducible and a regression from an earlier version?
If so we can try to do a bisect attempt to identify a problematic
commit.

Furthermore, can you please provide the full kernel log up to the
crash? The kernel is already tainted AFAICS, so we would want to see
the very first crash log.

Regards,
Salvatore

#1133144#17
Date:
2026-04-12 12:09:13 UTC
From:
To:
Hi Hendrik

Unfortunately in this one we do not have the kenel traces around the
panic (AFAICS). I'm forwarding it back to the bugreport in any case
though to further investigate the issue (remmeber please to always
include the bugreport address as well so that I'm not the single
person bus factor person, and we want to have a track of information
for the bug anyway).

I'm keeping for now the moreinfo tag on the bug, in case you can
revisit the logs and see if you can gther the one containing the
oops'es.

Quckly searching trough the upstream lists I have not found something
similar so far, but having the very first oops would be give more
hints on the issue to look at.

Regards,
Salvatore

#1133144#22
Date:
2026-04-14 17:37:21 UTC
From:
To:
Hey Salvatore,

Sorry, I didn't notice that. Will take that into account.

I attached the logs from that session, and not just the kernel messages.
The only things I filtered, where two noisy apps that where logging
private information, and I replaced the SSID names.

Can't find any oopses in it though. So it might just be a random case of
bad luck.

Cheers, Hendrik

#1133144#29
Date:
2026-04-21 12:39:15 UTC
From:
To:
Hello,

RAX and RSI look fishy, typically they contain pointers that on x86
start with ffff. So on first glance that looks like a memory corruption.
Is your machine over-clocked?

Can you try a memory test on your machine using the memtest86+ package?

If that finds something loading safe defaults in the BIOS might help, or
switching RAM dimms.

Best regards
Uwe