#1142424 linux-image-6.12.95+deb13-amd64: kernel crash with maybe SMAP trigger

#1142424#5
Date:
2026-07-19 16:38:51 UTC
From:
To:
Dear Maintainer,

as instructed on IRC, here's a bug report for a kernel crash on my
homeserver running Trixie.

The dmesg is attached but here's a relevant part from the "first"
problem:

Jul 18 16:33:14 molly kernel: BUG: unable to handle page fault for address: ffff88dd88a90000
Jul 18 16:33:14 molly kernel: #PF: supervisor write access in kernel mode
Jul 18 16:33:14 molly kernel: #PF: error_code(0x000b) - reserved bit violation
Jul 18 16:33:14 molly kernel: PGD 19ee01067 P4D 19ee01067 PUD 47fff3067 PMD 8000008408a000e3
Jul 18 16:33:14 molly kernel: Oops: Oops: 000b [#1] PREEMPT SMP PTI
Jul 18 16:33:14 molly kernel: CPU: 2 UID: 1700000 PID: 10981 Comm: containerd-shim Not tainted 6.12.95+deb13-amd64 #1  Debian 6.12.95-1
Jul 18 16:33:14 molly kernel: Hardware name: Gigabyte Technology Co., Ltd. Default string/N3150ND3V, BIOS F4 04/11/2016
Jul 18 16:33:14 molly kernel: RIP: 0010:clear_page_erms+0xb/0x20
Jul 18 16:33:14 molly kernel: Code: 48 8d 7f 40 75 d9 90 c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa b9 00 10 00 00 31 c0 <f3> aa c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 90
Jul 18 16:33:14 molly kernel: RSP: 0000:ffffd23ec75afb20 EFLAGS: 00010246
Jul 18 16:33:14 molly kernel: RAX: 0000000000000000 RBX: fffff82d9022a400 RCX: 0000000000001000
Jul 18 16:33:14 molly kernel: RDX: fffff82d9022a400 RSI: fffff82d9022a440 RDI: ffff88dd88a90000
Jul 18 16:33:14 molly kernel: RBP: 0000000000000901 R08: ffffff800000007c R09: 0000000000000000
Jul 18 16:33:14 molly kernel: R10: 0000000000000000 R11: 0000000000000100 R12: 0000000000000000
Jul 18 16:33:14 molly kernel: R13: 0000000000000001 R14: 0000000000140dca R15: 0000000000000001
Jul 18 16:33:14 molly kernel: FS:  00007a1d8e8ae6c0(0000) GS:ffff88ddefd00000(0000) knlGS:0000000000000000
Jul 18 16:33:14 molly kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Jul 18 16:33:14 molly kernel: CR2: ffff88dd88a90000 CR3: 0000000272f8c000 CR4: 00000000001026f0
Jul 18 16:33:14 molly kernel: Call Trace:
Jul 18 16:33:14 molly kernel:  <TASK>
Jul 18 16:33:14 molly kernel:  prep_new_page+0xc7/0x1b0
Jul 18 16:33:14 molly kernel:  get_page_from_freelist+0x376/0x15f0
Jul 18 16:33:14 molly kernel:  ? vfs_read+0x15e/0x360
Jul 18 16:33:14 molly kernel:  __alloc_pages_noprof+0x16b/0x310
Jul 18 16:33:14 molly kernel:  alloc_pages_mpol_noprof+0xd7/0x1c0
Jul 18 16:33:14 molly kernel:  folio_alloc_mpol_noprof+0x14/0x30
Jul 18 16:33:14 molly kernel:  vma_alloc_folio_noprof+0x69/0xb0
Jul 18 16:33:14 molly kernel:  do_anonymous_page+0x343/0x870
Jul 18 16:33:14 molly kernel:  ? __pte_offset_map+0x1b/0x180
Jul 18 16:33:14 molly kernel:  __handle_mm_fault+0xb14/0xf70
Jul 18 16:33:14 molly kernel:  handle_mm_fault+0xe2/0x2c0
Jul 18 16:33:14 molly kernel:  do_user_addr_fault+0x217/0x620
Jul 18 16:33:14 molly kernel:  exc_page_fault+0x7e/0x180
Jul 18 16:33:14 molly kernel:  asm_exc_page_fault+0x26/0x30
Jul 18 16:33:14 molly kernel: RIP: 0033:0x80beb0
Jul 18 16:33:14 molly kernel: Code: 0f 6f 06 f3 0f 6f 4e 10 f3 0f 6f 56 20 f3 0f 6f 5e 30 f3 0f 6f 64 1e c0 f3 0f 6f 6c 1e d0 f3 0f 6f 74 1e e0 f3 0f 6f 7c 1e f0 <f3> 0f 7f 07 f3 0f 7f 4f 10 f3 0f 7f 57 20 f3 0f 7f 5f 30 f3 0f 7f
Jul 18 16:33:14 molly kernel: RSP: 002b:000000c000450e80 EFLAGS: 00010287
Jul 18 16:33:14 molly kernel: RAX: 000000c0003de000 RBX: 0000000000000045 RCX: 0000000000000045
Jul 18 16:33:14 molly kernel: RDX: 000000000024b2d0 RSI: 000000c0000d22b7 RDI: 000000c0003de000
Jul 18 16:33:14 molly kernel: RBP: 000000c000450ea8 R08: 00007a1d8c575580 R09: 7fffffffffffffff
Jul 18 16:33:14 molly kernel: R10: 0000000000000001 R11: 00007a1dd5a15000 R12: 000000c0003de000
Jul 18 16:33:14 molly kernel: R13: 0000000000000066 R14: 000000c000229c00 R15: 0000000000000001
Jul 18 16:33:14 molly kernel:  </TASK>
Jul 18 16:33:14 molly kernel: Modules linked in: veth nf_conntrack_netlink xt_nat nft_chain_nat xt_MASQUERADE nf_nat bridge stp llc nft_compat nf_tables overlay xfrm_interface xfrm6_tunnel tunnel6 tunnel4 xfrm_user xfrm_algo macvlan snd_hda_codec_hdmi snd_hda_codec_realtek snd_hda_codec_generic snd_hda_scodec_component intel_rapl_msr intel_rapl_common intel_powerclamp kvm_intel kvm hci_uart nls_ascii btqca btrtl nls_cp437 irqbypass snd_hda_intel vfat fat snd_intel_dspcfg crct10dif_pclmul btintel iTCO_wdt intel_xhci_usb_role_switch crc32_pclmul intel_pmc_bxt snd_intel_sdw_acpi i915 ghash_clmulni_intel roles iTCO_vendor_support btbcm ppdev watchdog sha512_ssse3 snd_hda_codec mei_hdcp sha256_ssse3 evdev mei_pxp sha1_ssse3 r8169 snd_hda_core aesni_intel gf128mul snd_hwdep xhci_pci realtek bluetooth crypto_simd mdio_devres xhci_hcd cryptd i2c_hid_acpi snd_pcm i2c_hid lpc_ich intel_cstate snd_timer libphy parport_pc serio_raw drm_buddy ecdh_generic parport drm_display_helper usbcore hid snd mei_txe cec rfkill rc_core ttm mei drm_kms_helper
Jul 18 16:33:14 molly kernel:  pwm_lpss_platform soundcore i2c_algo_bit pwm_lpss video usb_common wmi button ip6t_REJECT nf_reject_ipv6 ip6t_rt ip6table_filter ip6_tables sg xt_addrtype ipt_REJECT nf_reject_ipv4 xt_tcpudp xt_LOG nf_log_syslog xt_conntrack at24 nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_filter coretemp it87 hwmon_vid i2c_i801 i2c_smbus loop drm efi_pstore configfs nfnetlink ip_tables x_tables autofs4 ext4 crc16 mbcache jbd2 raid10 raid456 libcrc32c crc32c_generic async_raid6_recov async_memcpy async_pq async_xor xor async_tx raid6_pq raid0 ansi_cprng dm_mod raid1 md_mod sd_mod ahci libahci libata psmouse scsi_mod crc32c_intel fan scsi_common intel_int0002_vgpio efivarfs
Jul 18 16:33:14 molly kernel: CR2: ffff88dd88a90000
Jul 18 16:33:14 molly kernel: ---[ end trace 0000000000000000 ]---

I'm a bit worried ab out the "supervisor write access in kernel mode" as
I think it might be SMAP beeing triggered

The box is running a home server with multiple LXC, one of them running
Docker inside (from where the relevant containerd-shim process is
originating from).

There are I/O errors earlier in the log, I'm unsure if they're relevant
(they're few days earlier).

I'll keep monitoring the bug in case it happens again.