Locietta / Locietta/xanmod-kernel-WSL2
[Bug] kernel NULL pointer dereference
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 248
- Forks
- 41
- Avg merge
- 2h 9m
- Merged PRs (30d)
- 1
Description
### Bug Description and Repro
```rust
[ 63.280501] BUG: kernel NULL pointer dereference, address: 0000000000000051
[ 63.288744] #PF: supervisor read access in kernel mode
[ 63.288953] #PF: error_code(0x0000) - not-present page
[ 63.289154] PGD 0 P4D 0
[ 63.289288] Oops: Oops: 0000 [#1] SMP NOPTI
[ 93.145865] BUG: kernel NULL pointer dereference, address: 0000000000000051
[ 93.146575] #PF: supervisor read access in kernel mode
[ 93.146861] #PF: error_code(0x0000) - not-present page
[ 93.147460] PGD 0 P4D 0
[ 93.147703] Oops: Oops: 0000 [#1] SMP NOPTI
[ 93.148425] CPU: 15 UID: 0 PID: 386 Comm: kworker/15:1H Not tainted 6.18.2-locietta-WSL2-xanmod1 #1 PREEMPT(full)
[ 93.149053] Workqueue: 0x0 (kblockd)
[ 93.149291] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 93.151050] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 93.152856] RSP: 0018:ffffbaa100cebd30 EFLAGS: 00010046
[ 93.153348] RAX: 0000000000000000 RBX: ffff9a45b79f1180 RCX: 0000000000000000
[ 93.154072] RDX: 0000000000000000 RSI: ffffffc59b884000 RDI: ffff9a240d042800
[ 93.155586] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000800
[ 93.156133] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 93.156762] R13: 0000000000000000 R14: ffff9a240d042800 R15: ffff9a45b79f1280
[ 93.157290] FS: 0000000000000000(0000) GS:ffff9a45fb39f000(0000) knlGS:0000000000000000
[ 93.157889] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 93.158388] CR2: 0000000000000051 CR3: 000000108646d000 CR4: 0000000000b50ef0
[ 93.159151] Call Trace:
[ 93.159310]
[ 93.159416] pick_next_task_fair+0x28/0x2d0
[ 93.159597] __pick_next_task+0x4c/0x1f0
[ 93.159750] __schedule+0x1a3/0x1460
[ 93.159958] ? process_scheduled_works+0x2e5/0x470
[ 93.162540] schedule+0x6e/0xe0
[ 93.162876] worker_thread+0x265/0x310
[ 93.163099] ? _raw_spin_unlock_irqrestore+0xe/0x40
[ 93.163378] ? __cfi_worker_thread+0x10/0x10
[ 93.163745] kthread+0x225/0x260
[ 93.164025] ? __cfi_kthread+0x10/0x10
[ 93.164267] ret_from_fork+0x105/0x1c0
[ 93.164676] ? __cfi_kthread+0x10/0x10
[ 93.164883] ret_from_fork_asm+0x1a/0x30
[ 93.165124]
[ 93.165256] Modules linked in:
[ 93.165407] CR2: 0000000000000051
[ 93.165592] ---[ end trace 0000000000000000 ]---
[ 93.165823] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 93.166454] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 93.167622] RSP: 0018:ffffbaa100cebd30 EFLAGS: 00010046
[ 93.167914] RAX: 0000000000000000 RBX: ffff9a45b79f1180 RCX: 0000000000000000
[ 93.169080] RDX: 0000000000000000 RSI: ffffffc59b884000 RDI: ffff9a240d042800
[ 93.169773] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000800
[ 93.170788] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 93.171751] R13: 0000000000000000 R14: ffff9a240d042800 R15: ffff9a45b79f1280
[ 93.172224] FS: 0000000000000000(0000) GS:ffff9a45fb39f000(0000) knlGS:0000000000000000
[ 93.172659] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 93.173071] CR2: 0000000000000051 CR3: 000000108646d000 CR4: 0000000000b50ef0
[ 93.173597] Kernel panic - not syncing: Fatal exception
[ 93.175427] Kernel Offset: 0x38000000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)
Die Verbindung mit dem virtuellen Computer oder Container wurde geschlossen.
[ 48.084004] WSL (2 - init-systemd(Ubuntu)) ERROR: WaitForBootProcess:3438: /sbin/init failed to start within 10000ms
[ 49.454960] BUG: kernel NULL pointer dereference, address: 0000000000000051
[ 49.455604] #PF: supervisor read access in kernel mode
[ 49.455977] #PF: error_code(0x0000) - not-present page
[ 49.456314] PGD 196816067 P4D 196816067 PUD 196815067 PMD 0
[ 49.456891] Oops: Oops: 0000 [#1] SMP NOPTI
[ 49.457178] CPU: 28 UID: 0 PID: 7499 Comm: containerd-shim Not tainted 6.18.2-locietta-WSL2-xanmod1 #1 PREEMPT(full)
[ 49.457875] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 49.458393] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 49.459705] RSP: 0018:ffffaa1d0152fb58 EFLAGS: 00010046
[ 49.460024] RAX: 0000000000000000 RBX: ffff9f2b37d31180 RCX: 0000000000000000
[ 49.460803] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff9ef368c90000
[ 49.461358] RBP: 0000000000000000 R08: 0000000000000400 R09: 0000000000000400
[ 49.461964] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 49.462490] R13: 0000000000000000 R14: ffff9ef368c90000 R15: ffff9f2b37d31280
[ 49.463061] FS: 000000c000051898(0000) GS:ffff9f2ba86df000(0000) knlGS:0000000000000000
[ 49.463604] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 49.464069] CR2: 0000000000000051 CR3: 000000019681b000 CR4: 0000000000b50ef0
[ 49.464798] Call Trace:
[ 49.465083]
[ 49.465274] pick_next_task_fair+0x28/0x2d0
[ 49.465517] __pick_next_task+0x4c/0x1f0
[ 49.465790] __schedule+0x1a3/0x1460
[ 49.466150] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.466640] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.467061] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.467427] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.467977] schedule+0x6e/0xe0
[ 49.468291] x64_sys_call+0x1619/0x1870
[ 49.468610] do_syscall_64+0x85/0x200
[ 49.468955] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.469343] ? do_syscall_64+0xb6/0x200
[ 49.469646] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.469993] ? __x64_sys_openat+0x80/0xa0
[ 49.470248] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.470628] ? do_syscall_64+0xb6/0x200
[ 49.470923] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.471304] ? do_syscall_64+0xb6/0x200
[ 49.471753] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.472126] ? do_syscall_64+0xb6/0x200
[ 49.472388] ? do_epoll_ctl+0x11d/0x3a0
[ 49.472654] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.472984] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.473352] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.473826] ? __se_sys_fcntl+0x9e/0xb0
[ 49.474224] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.474592] ? do_syscall_64+0xb6/0x200
[ 49.474863] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.475220] ? __se_sys_fcntl+0x9e/0xb0
[ 49.475464] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.475866] ? do_syscall_64+0xb6/0x200
[ 49.476183] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.476488] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.476798] ? do_syscall_64+0xb6/0x200
[ 49.477060] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.477377] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 49.477734] RIP: 0033:0x479147
[ 49.478001] Code: 0f 05 48 3d 01 f0 ff ff 76 0b c7 04 25 f1 00 00 00 f1 00 00 00 48 83 c4 20 5d c3 cc cc cc cc cc cc cc cc b8 18 00 00 00 0f 05 cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc
[ 49.479196] RSP: 002b:000000c00020fdd8 EFLAGS: 00000297 ORIG_RAX: 0000000000000018
[ 49.479682] RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 0000000000479147
[ 49.480215] RDX: 0000000000000101 RSI: 0000000000000000 RDI: 0000000000000004
[ 49.480814] RBP: 000000c00020fe30 R08: 0000000000000005 R09: 0000000000000101
[ 49.481288] R10: 000000c00004e001 R11: 0000000000000297 R12: 000000c00020fd98
[ 49.481868] R13: 000000c0000393a8 R14: 000000c000005880 R15: 000000c000216080
[ 49.482346]
[ 49.482529] Modules linked in:
[ 49.482793] CR2: 0000000000000051
[ 49.483269] ---[ end trace 0000000000000000 ]---
[ 49.483616] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 49.484061] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 49.485163] RSP: 0018:ffffaa1d0152fb58 EFLAGS: 00010046
[ 49.485453] RAX: 0000000000000000 RBX: ffff9f2b37d31180 RCX: 0000000000000000
[ 49.485991] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff9ef368c90000
[ 49.486570] RBP: 0000000000000000 R08: 0000000000000400 R09: 0000000000000400
[ 49.487036] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 49.487492] R13: 0000000000000000 R14: ffff9ef368c90000 R15: ffff9f2b37d31280
[ 49.487983] FS: 000000c000051898(0000) GS:ffff9f2ba86df000(0000) knlGS:0000000000000000
[ 49.488466] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 49.488826] CR2: 0000000000000051 CR3: 000000019681b000 CR4: 0000000000b50ef0
[ 49.489275] Kernel panic - not syncing: Fatal exception
[ 49.490970] Kernel Offset: 0xb000000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)
Die Verbindung mit dem virtuellen Computer oder Container wurde geschlossen.
```
### Kernel version
6.18.2-locietta-WSL2-xanmod1 zen3
### WSL version
2.7.0.0
### Windows version
win11 25h2
### Distro
ubuntu 24.04
### Additional context
_No response_
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the panic on WSL 2.7.0.0 with kernel 6.18.2-locietta-WSL2-xanmod1, Ubuntu 24.04, and Windows 11 25H2. Read the trace around pick_task_fair and determine the cause of the NULL pointer dereference; done means the kernel no longer panics under the reported workload.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- operating-systems
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100