Public bug reported:
I am reporting a possible kernel regression involving CIFS/netfs writes
on an Ubuntu 26.04 LTS Hyper-V guest.
Problem
=======
The system experienced repeated kernel crashes while running
7.0.0-34-generic during sustained SMB/CIFS activity.
The preserved crash evidence includes a NULL pointer dereference in:
iov_iter_advance
The affected workqueue was:
netfs_write_collection_worker [netfs]
The call trace also includes CIFS/netfs write-path functions including
cifs_prepare_write and netfs_reissue_write.
The failure ultimately resulted in:
Kernel panic - not syncing: Fatal exception
The kernel was not tainted.
Regression information
======================
The same VM also has 7.0.0-31-generic installed.
I booted 7.0.0-31-generic without changing the VM configuration, CIFS
configuration, SMB server, or underlying storage and performed controlled
CIFS load testing.
Test 1:
- 2 GiB sequential CIFS write
- 2 GiB direct CIFS read
- completed successfully
- no CIFS/netfs errors or kernel fault
Test 2:
- 10 GiB sustained CIFS write
- blocked processes reached 11
- I/O wait reached approximately 62%
- operation completed successfully
- no CIFS/netfs errors, Oops, NULL pointer dereference, or panic
Test 3:
- simultaneous 5 GiB CIFS read and 5 GiB CIFS write
- additional normal background CIFS activity was present
- blocked processes reached 11
- I/O wait reached approximately 34%
- both operations completed successfully
- CIFS remained responsive
- no CIFS/netfs errors, Oops, NULL pointer dereference, or panic
Immediately before one of the 7.0.0-34 failures, monitoring had shown
approximately 8 blocked processes and 61% I/O wait.
Therefore 7.0.0-31 has so far survived controlled CIFS I/O pressure
comparable to or greater than conditions observed before a 7.0.0-34
failure.
Environment
===========
- Ubuntu 26.04 LTS
- Hyper-V Generation 2 guest
- 4 vCPUs
- Hyper-V dynamic memory
- CIFS/SMB 3.1.1
- SMB server is a Windows 11 system
- CIFS mounts use cache=strict
Additional observation
======================
An hv_storvsc SCSI status message was observed near one previous failure.
A similar hv_storvsc message has also occurred while running
7.0.0-31-generic without a subsequent kernel failure, so I do not have
evidence that this message is causal.
Expected result
===============
Sustained/concurrent CIFS reads and writes should complete without a
kernel NULL pointer dereference or panic.
Actual result
=============
7.0.0-34-generic has repeatedly experienced a NULL pointer dereference
involving iov_iter_advance / netfs_write_collection_worker during CIFS
activity, followed by a fatal kernel panic.
7.0.0-31-generic has not reproduced the failure so far, including under
controlled high-I/O CIFS testing.
Crash dumps from the 7.0.0-34 failures have been preserved and can be
provided if useful.
ProblemType: Bug
DistroRelease: Ubuntu 26.04
Package: linux-image-7.0.0-31-generic 7.0.0-31.31
ProcVersionSignature: Ubuntu 7.0.0-31.31-generic 7.0.14
Uname: Linux 7.0.0-31-generic x86_64
AlsaDevices:
total 0
crw-rw---- 1 root audio 116, 1 Oct 1 07:53 seq
crw-rw---- 1 root audio 116, 33 Oct 1 07:53 timer
AplayDevices: Error: [Errno 2] No such file or directory: 'aplay'
ApportVersion: 2.34.1-0ubuntu0.1
Architecture: amd64
ArecordDevices: Error: [Errno 2] No such file or directory: 'arecord'
AudioDevicesInUse: Error: command ['fuser', '-v', '/dev/snd/seq',
'/dev/snd/timer'] failed with exit code 1:
CRDA: N/A
CasperMD5CheckResult: pass
CurrentDmesg: Error: command ['dmesg'] failed with exit code 1: dmesg: read
kernel buffer failed: Operation not permitted
Date: Thu Oct 1 10:02:56 2026
InstallationDate: Installed on 2026-08-15 (48 days ago)
InstallationMedia: Ubuntu-Server 26.04 "Resolute Raccoon" - Release amd64
(20260420.1)
Lspci:
Lspci-vt:
Lsusb: Error: command ['lsusb'] failed with exit code 1:
Lsusb-t:
Lsusb-v: Error: command ['lsusb', '-v'] failed with exit code 1:
MachineType: Microsoft Corporation Virtual Machine
PciMultimedia:
ProcEnviron:
LANG=en_US.UTF-8
PATH=(custom, no user)
SHELL=/bin/bash
TERM=xterm-256color
XDG_RUNTIME_DIR=<set>
ProcFB: 0 hyperv_drmdrmfb
ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-31-generic
root=/dev/mapper/ubuntu--vg-ubuntu--lv ro
crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M
RfKill: Error: [Errno 2] No such file or directory: 'rfkill'
SourcePackage: linux
UpgradeStatus: No upgrade log present (probably fresh install)
acpidump:
dmi.bios.date: 09/25/2025
dmi.bios.release: 4.1
dmi.bios.vendor: Microsoft Corporation
dmi.bios.version: Hyper-V UEFI Release v4.1
dmi.board.asset.tag: None
dmi.board.name: Virtual Machine
dmi.board.vendor: Microsoft Corporation
dmi.board.version: Hyper-V UEFI Release v4.1
dmi.chassis.asset.tag: 9759-7365-3244-1492-7504-6167-90
dmi.chassis.type: 3
dmi.chassis.vendor: Microsoft Corporation
dmi.chassis.version: Hyper-V UEFI Release v4.1
dmi.modalias:
dmi:bvnMicrosoftCorporation:bvrHyper-VUEFIReleasev4.1:bd09/25/2025:br4.1:svnMicrosoftCorporation:pnVirtualMachine:pvrHyper-VUEFIReleasev4.1:rvnMicrosoftCorporation:rnVirtualMachine:rvrHyper-VUEFIReleasev4.1:cvnMicrosoftCorporation:ct3:cvrHyper-VUEFIReleasev4.1:skuNone:pfaVirtualMachine:
dmi.product.family: Virtual Machine
dmi.product.name: Virtual Machine
dmi.product.sku: None
dmi.product.version: Hyper-V UEFI Release v4.1
dmi.sys.vendor: Microsoft Corporation
** Affects: linux (Ubuntu)
Importance: Undecided
Status: New
** Tags: amd64 apport-bug resolute
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169171
Title:
7.0.0-34-generic: repeated NULL pointer dereference in
iov_iter_advance during CIFS/netfs writes on Hyper-V
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169171/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs