#1145111 linux: kernel NULL pointer dereference when running snapd testsuite

Package:
src:linux
Source:
src:linux
Submitter:
Aurelien Jarno
Date:
2026-08-23 21:33:02 UTC
Severity:
normal
Tags:
#1145111#5
Date:
2026-08-22 18:34:46 UTC
From:
To:
Dear maintainers,

The rv-manda-04 build daemon got a kernel oops this morning when
building the snapd package. It currently runs a 7.1.7+deb13-riscv64
kernel. Here is the backtrace:

[265841.801920] Unable to handle kernel NULL pointer dereference at virtual address 000000000000004c
[265841.810839] Current systemd.test pgtable: 4K pagesize, 39-bit VAs, pgdp=0x0000000157206000
[265841.819037] [000000000000004c] pgd=0000000000000000, p4d=0000000000000000, pud=0000000000000000
[265841.827796] Oops [#1]
[265841.830412] Modules linked in: nls_ascii nls_cp437 vfat fat ftdi_sio usbserial onie_tlv ofpart spi_nor at24 ledtrig_default_on k1_tsensor leds_gpio ip6t_REJECT nf_reject_ipv6 ip6table_filter ip6_tables xt_hashlimit ipt_REJECT nf_reject_ipv4 xt_NFLOG nfnetlink_log xt_multiport xt_tcpudp xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_filter mtdblock mtd_blkdevs mtd drm sch_fq tcp_bbr nvme_fabrics configfs nfnetlink efivarfs ip_tables x_tables autofs4 ext4 crc16 mbcache jbd2 crc32c_cryptoapi mmc_spi crc7 of_mmc_spi crc_itu_t mmc_block dm_mod onboard_usb_dev xhci_plat_hcd xhci_hcd dwc3_generic_plat dwc3 udc_core roles nvme sdhci_of_k1 realtek sdhci_pltfm usbcore phy_package nvme_core sdhci mmc_core nvme_keyring nvme_auth k1_emac usb_common mmp_pdma spi_fsl_qspi i2c_k1 phy_k1_usb2
[265841.907949] CPU: 1 UID: 193463271 PID: 1864225 Comm: systemd.test Not tainted 7.1.7+deb13-riscv64 #1 PREEMPTLAZY  Debian 7.1.7-1~bpo13+1
[265841.920327] Hardware name: Unknown Unknown Product/Unknown Product, BIOS 2022.10spacemit-82694-gff90af2940 10/01/2022
[265841.931104] epc : __aa_label_next_not_in_set+0x16/0xd8
[265841.936393]  ra : aa_label_is_subset+0x36/0x60
[265841.940846] epc : ffffffff805bdf3e ra : ffffffff805be036 sp : ffffffc61a6b3780
[265841.948283]  gp : ffffffff822bffd0 tp : ffffffd70b013000 t0 : ffffffff80021f28
[265841.955523]  t1 : ffffffd701bfe00c t2 : ffffffff81201660 s0 : ffffffc61a6b37c0
[265841.962803]  s1 : ffffffd70c670ef8 a0 : ffffffc61a6b37c0 a1 : ffffffd70c670ef8
[265841.970159]  a2 : 0000000000000000 a3 : 0000000000000000 a4 : 0000000000000000
[265841.977384]  a5 : ffffffd70c670ef8 a6 : 0000000000000000 a7 : ffffffc61a6b35b0
[265841.984720]  s2 : 0000000000000000 s3 : ffffffd70c670ef8 s4 : ffffffd7fea14960
[265841.992508]  s5 : 0000000000000000 s6 : ffffffff81663100 s7 : 0000000000000000
[265842.000004]  s8 : ffffffd80384e2c0 s9 : ffffffd70425d480 s10: ffffffd88aa61700
[265842.007363]  s11: 0000000000000009 t3 : ffffffd701bfb00c t4 : 0000000000000001
[265842.014780]  t5 : 0000000000000002 t6 : ffffffc61a6b35e4 ssp : 0000000000000000
[265842.022324] status: 0000000200000120 badaddr: 000000000000004c cause: 000000000000000d
[265842.030538] [<ffffffff805bdf3e>] __aa_label_next_not_in_set+0x16/0xd8
[265842.037405] [<ffffffff805be036>] aa_label_is_subset+0x36/0x60
[265842.044021] [<ffffffff805c6110>] aa_unix_file_perm+0x3b0/0x8a8
[265842.050211] [<ffffffff805c3d44>] aa_sock_file_perm+0x74/0x88
[265842.056193] [<ffffffff805bc18c>] aa_file_perm+0x424/0x4c8
[265842.061895] [<ffffffff805b6eac>] apparmor_file_permission+0x54/0x200
[265842.068511] [<ffffffff80558eb4>] security_file_permission+0x5c/0x150
[265842.075262] [<ffffffff8042b9d0>] rw_verify_area+0x48/0x140
[265842.080991] [<ffffffff8042e186>] vfs_write+0x7e/0x4f0
[265842.086084] [<ffffffff8042e7c8>] ksys_write+0xb8/0xe8
[265842.091150] [<ffffffff8042e818>] __riscv_sys_write+0x20/0x30
[265842.096858] [<ffffffff80d0d7c6>] do_trap_ecall_u+0x156/0x520
[265842.102608] [<ffffffff80d202ec>] handle_exception+0x16c/0x178
[265842.108308] Code: ffa6 0013 0000 7139 f822 fc06 f04a 0080 2903 0045 (4678) 5b63
[265842.116173] ---[ end trace 0000000000000000 ]---
[265842.120608] note: systemd.test[1864225] exited with preempt_count 1
[265862.805959] rcu: INFO: rcu_sched self-detected stall on CPU
[265862.811445] rcu:    4-....: (5248 ticks this GP) idle=ddac/1/0x4000000000000000 softirq=29553384/29553384 fqs=2387
[265862.821649] rcu:    (t=5253 jiffies g=30403905 q=244873 ncpus=8)

I have been able to reproduce it on another system running the same
kernel, but not when running a manually build 7.1.4 kernel. I have then
been able to reproduce it on a amd64 system running a 7.1.9+deb14-amd64
kernel. I therefore *suspect* the issue have been introduced by one of
the many apparmor fixes that went in 7.1.5. Here is the corresponding
amd64 backtrace:

[ 3686.682567] BUG: kernel NULL pointer dereference, address: 000000000000004c
[ 3686.684051] #PF: supervisor read access in kernel mode
[ 3686.685078] #PF: error_code(0x0000) - not-present page
[ 3686.685949] PGD 0 P4D 0
[ 3686.685949] Oops: Oops: 0000 [#1] SMP NOPTI
[ 3686.685949] CPU: 3 UID: 428679 PID: 319766 Comm: systemd.test Not tainted 7.1.9+deb14-amd64 #1 PREEMPT(lazy)  Debian 7.1.9-1
[ 3686.685949] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 2025.11-5 04/03/2026
[ 3686.685949] RIP: 0010:__aa_label_next_not_in_set+0xb/0xd0
[ 3686.685949] Code: f0 e9 e4 14 79 ff 66 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 40 d6 0f 1f 44 00 00 41 57 <8b> 42 4c 49 89 f7 41 56 49 89 d6 41 55 49 89 fd 41 54 55 53 8b 6f
[ 3686.685949] RSP: 0018:ffffd06109cf3888 EFLAGS: 00010213
[ 3686.685949] RAX: ffff89b1a103a8f8 RBX: ffff89b1af0421e0 RCX: ffffd06109cf3780
[ 3686.685949] RDX: 0000000000000000 RSI: ffff89b1a103a8f8 RDI: ffffd06109cf3898
[ 3686.685949] RBP: ffffd06109cf3940 R08: ffff89b183a26300 R09: 0000000000000000
[ 3686.685949] R10: 0000000000000000 R11: ffff89b1a103b600 R12: 0000000000000000
[ 3686.685949] R13: ffff89b1a103a8f8 R14: ffff89b1a103a8f8 R15: ffff89b183a26680
[ 3686.685949] FS:  00007f30a3aa5780(0000) GS:ffff89b350cef000(0000) knlGS:0000000000000000
[ 3686.685949] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 3686.685949] CR2: 000000000000004c CR3: 000000000235e000 CR4: 0000000000750ef0
[ 3686.685949] PKRU: 55555554
[ 3686.685949] Call Trace:
[ 3686.685949]  <TASK>
[ 3686.685949]  aa_label_is_subset+0x3f/0x70
[ 3686.685949]  aa_unix_file_perm+0x5e8/0x9d0
[ 3686.685949]  aa_file_perm+0x45a/0x550
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? aa_do_perms+0xc6/0x120
[ 3686.685949]  apparmor_file_permission+0x44/0xb0
[ 3686.685949]  security_file_permission+0x40/0x100
[ 3686.685949]  rw_verify_area+0x56/0x180
[ 3686.685949]  vfs_write+0x7c/0x480
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ksys_write+0xbf/0xf0
[ 3686.685949]  do_syscall_64+0xe1/0x640
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? aa_match_to_prot+0xab/0x150
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? aa_do_perms+0xc6/0x120
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? aa_unix_label_sk_perm.part.0.isra.0+0x142/0x1f0
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? __check_object_size+0x48/0x220
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? move_addr_to_user+0xe7/0x110
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? do_getsockname+0x7b/0xb0
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? __sys_getsockname+0x7f/0xb0
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? do_syscall_64+0x11e/0x640
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? sock_alloc_file+0x63/0xc0
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? __sys_socket+0xd0/0x100
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 3686.685949]  ? do_syscall_64+0x98/0x640
[ 3686.685949]  ? exc_page_fault+0x82/0x1d0
[ 3686.685949]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 3686.685949] RIP: 0033:0x55ad1c8928ae
[ 3686.685949] Code: ff cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc 49 89 f2 48 89 fa 48 89 ce 48 89 df 0f 05 <48> 3d 01 f0 ff ff 76 15 48 f7 d8 48 89 c1 48 c7 c0 ff ff ff ff 48
[ 3686.685949] RSP: 002b:00002b7a7ff63420 EFLAGS: 00000216 ORIG_RAX: 0000000000000001
[ 3686.685949] RAX: ffffffffffffffda RBX: 0000000000000008 RCX: 000055ad1c8928ae
[ 3686.685949] RDX: 0000000000000009 RSI: 00002b7a7ff636b8 RDI: 0000000000000008
[ 3686.685949] RBP: 00002b7a7ff63460 R08: 0000000000000000 R09: 0000000000000000
[ 3686.685949] R10: 0000000000000000 R11: 0000000000000216 R12: 00002b7a7ff63590
[ 3686.685949] R13: 00002b7a7fe121a8 R14: 00002b7a7ff04f00 R15: ffffffffffffffff
[ 3686.685949]  </TASK>
[ 3686.685949] Modules linked in: overlay nls_ascii nls_cp437 vfat fat bridge stp llc nfnetlink cfg80211 rfkill intel_rapl_msr intel_rapl_common binfmt_misc kvm_amd ccp kvm irqbypass aesni_intel gf128mul virtio_balloon pcspkr button joydev evdev sg vhost_net vhost tun nbd vhost_iotlb drm loop tap msr cpuid efi_pstore configfs efivarfs qemu_fw_cfg vsock_loopback vmw_vsock_virtio_transport vmw_vsock_virtio_transport_common vsock virtio_rng autofs4 ext4 crc16 mbcache jbd2 crc32c_cryptoapi lz4 lz4_compress dm_mod ahci sd_mod iTCO_wdt libahci intel_pmc_bxt watchdog virtio_net libata virtio_scsi net_failover psmouse scsi_mod serio_raw failover i2c_i801 scsi_common i2c_smbus lpc_ich
[ 3686.765532] CR2: 000000000000004c
[ 3686.765532] ---[ end trace 0000000000000000 ]---

Regards
Aurelien

#1145111#14
Date:
2026-08-22 22:07:17 UTC
From:
To:
control: found -1 7.1.5-1
control: found -1 7.2~rc7-1~exp1

Hi,

I can confirm that the issue got in introduced in version 7.1.5, it is
*not* reproducible with version 7.1.4.

It is also reproducible with version 7.2~rc7.

Regards
Aurelien

#1145111#21
Date:
2026-08-23 21:30:46 UTC
From:
To:
Hi,

commit ec95dec9ae2c30e99bbb3e59950d7493021961ec (HEAD)
Author: John Johansen <john.johansen@canonical.com>
Date:   Wed Oct 22 23:46:19 2025 -0700

    apparmor: fix shadowing of plabel that prevents cache from being updated

    [ Upstream commit 4483efe4f21510b30c24bc97d9fd0e8feab94125 ]

    Unfortunately the plabel was being shadowed by an unused local var.
    This didn't affect the mediation check but did cauase the cache to
    not correctly be updated resulting in extra mediation checks.

    Fixes: 88fec3526e841 ("apparmor: make sure unix socket labeling is correctly updated.")
    Signed-off-by: John Johansen <john.johansen@canonical.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>

 security/apparmor/af_unix.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

I have verified that manually reverting it (context has changed a bit) on 7.1.9
fixes the kernel oops.

Regards
Aurelien