On 1/2/2026 9:51 AM, Venkat Rao Bagalkote wrote:
Greetings!!!


IBM CI has reported a below crash. This occurs, in the TX path while sending data over TCP. e.g., cloning the linux repo or running iperf3 tool.


Environment
-----------
- Platform: IBM,9080-HEX Power11 (architected), HV: phyp (pSeries)
- Firmware: FW1110.01 (NH1110_069)
- Kernel: v6.19-rc3 (Linus master)
- Config: LE, PAGE_SIZE=64K, MMU=Radix, SMP NR_CPUS=8192, NUMA pSeries
- Workload: sustained TCP send from sshd


Traces:


[ 2480.578185] BUG: Kernel NULL pointer dereference on read at 0x00000000
[ 2480.578189] Faulting instruction address: 0xc000000000f92830
[ 2480.578192] Oops: Kernel access of bad area, sig: 11 [#1]
[ 2480.578195] LE PAGE_SIZE=64K MMU=Radix  SMP NR_CPUS=8192 NUMA pSeries
[ 2480.578200] Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack bonding nf_defrag_ipv6 nf_defrag_ipv4 tls rfkill ip_set nf_tables nfnetlink kmem device_dax pseries_rng vmx_crypto dax_pmem fuse ext4 crc16 mbcache jbd2 sd_mod nd_pmem sg papr_scm libnvdimm ibmvscsi ibmveth scsi_transport_srp pseries_wdt [ 2480.578234] CPU: 31 UID: 0 PID: 1895 Comm: sshd Kdump: loaded Not tainted 6.19.0-rc1-next-20251219 #1 VOLUNTARY [ 2480.578239] Hardware name: IBM,9080-HEX Power11 (architected) 0x820200 0xf000007 of:IBM,FW1110.01 (NH1110_069) hv:phyp pSeries [ 2480.578243] NIP:  c000000000f92830 LR: c000000000f92830 CTR: c00000000002852c [ 2480.578246] REGS: c000000071d3f0c0 TRAP: 0300   Not tainted (6.19.0- rc1-next-20251219)


This looks like the same NULL pointer dereference in __dev_xmit_skb() fixed in v6.19-rc4 (https://lore.kernel.org/all/[email protected]/).

https://lore.kernel.org/all/[email protected]/

https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c04de0c79534


Thanks,
Alok

Reply via email to