Locietta / Locietta/xanmod-kernel-WSL2

[Bug] kernel NULL pointer dereference

Open
#146 6 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

BUG INFO-NEEDED
Dominant language
Shell
Stars
248
Forks
41
Avg merge
2h 9m
Merged PRs (30d)
1

Description

### Bug Description and Repro

```rust
[ 63.280501] BUG: kernel NULL pointer dereference, address: 0000000000000051
[ 63.288744] #PF: supervisor read access in kernel mode
[ 63.288953] #PF: error_code(0x0000) - not-present page
[ 63.289154] PGD 0 P4D 0
[ 63.289288] Oops: Oops: 0000 [#1] SMP NOPTI
[ 93.145865] BUG: kernel NULL pointer dereference, address: 0000000000000051
[ 93.146575] #PF: supervisor read access in kernel mode
[ 93.146861] #PF: error_code(0x0000) - not-present page
[ 93.147460] PGD 0 P4D 0
[ 93.147703] Oops: Oops: 0000 [#1] SMP NOPTI
[ 93.148425] CPU: 15 UID: 0 PID: 386 Comm: kworker/15:1H Not tainted 6.18.2-locietta-WSL2-xanmod1 #1 PREEMPT(full)
[ 93.149053] Workqueue: 0x0 (kblockd)
[ 93.149291] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 93.151050] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 93.152856] RSP: 0018:ffffbaa100cebd30 EFLAGS: 00010046
[ 93.153348] RAX: 0000000000000000 RBX: ffff9a45b79f1180 RCX: 0000000000000000
[ 93.154072] RDX: 0000000000000000 RSI: ffffffc59b884000 RDI: ffff9a240d042800
[ 93.155586] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000800
[ 93.156133] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 93.156762] R13: 0000000000000000 R14: ffff9a240d042800 R15: ffff9a45b79f1280
[ 93.157290] FS: 0000000000000000(0000) GS:ffff9a45fb39f000(0000) knlGS:0000000000000000
[ 93.157889] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 93.158388] CR2: 0000000000000051 CR3: 000000108646d000 CR4: 0000000000b50ef0
[ 93.159151] Call Trace:
[ 93.159310]
[ 93.159416] pick_next_task_fair+0x28/0x2d0
[ 93.159597] __pick_next_task+0x4c/0x1f0
[ 93.159750] __schedule+0x1a3/0x1460
[ 93.159958] ? process_scheduled_works+0x2e5/0x470
[ 93.162540] schedule+0x6e/0xe0
[ 93.162876] worker_thread+0x265/0x310
[ 93.163099] ? _raw_spin_unlock_irqrestore+0xe/0x40
[ 93.163378] ? __cfi_worker_thread+0x10/0x10
[ 93.163745] kthread+0x225/0x260
[ 93.164025] ? __cfi_kthread+0x10/0x10
[ 93.164267] ret_from_fork+0x105/0x1c0
[ 93.164676] ? __cfi_kthread+0x10/0x10
[ 93.164883] ret_from_fork_asm+0x1a/0x30
[ 93.165124]
[ 93.165256] Modules linked in:
[ 93.165407] CR2: 0000000000000051
[ 93.165592] ---[ end trace 0000000000000000 ]---
[ 93.165823] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 93.166454] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 93.167622] RSP: 0018:ffffbaa100cebd30 EFLAGS: 00010046
[ 93.167914] RAX: 0000000000000000 RBX: ffff9a45b79f1180 RCX: 0000000000000000
[ 93.169080] RDX: 0000000000000000 RSI: ffffffc59b884000 RDI: ffff9a240d042800
[ 93.169773] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000800
[ 93.170788] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 93.171751] R13: 0000000000000000 R14: ffff9a240d042800 R15: ffff9a45b79f1280
[ 93.172224] FS: 0000000000000000(0000) GS:ffff9a45fb39f000(0000) knlGS:0000000000000000
[ 93.172659] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 93.173071] CR2: 0000000000000051 CR3: 000000108646d000 CR4: 0000000000b50ef0
[ 93.173597] Kernel panic - not syncing: Fatal exception
[ 93.175427] Kernel Offset: 0x38000000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)
Die Verbindung mit dem virtuellen Computer oder Container wurde geschlossen.
[ 48.084004] WSL (2 - init-systemd(Ubuntu)) ERROR: WaitForBootProcess:3438: /sbin/init failed to start within 10000ms
[ 49.454960] BUG: kernel NULL pointer dereference, address: 0000000000000051
[ 49.455604] #PF: supervisor read access in kernel mode
[ 49.455977] #PF: error_code(0x0000) - not-present page
[ 49.456314] PGD 196816067 P4D 196816067 PUD 196815067 PMD 0
[ 49.456891] Oops: Oops: 0000 [#1] SMP NOPTI
[ 49.457178] CPU: 28 UID: 0 PID: 7499 Comm: containerd-shim Not tainted 6.18.2-locietta-WSL2-xanmod1 #1 PREEMPT(full)
[ 49.457875] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 49.458393] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 49.459705] RSP: 0018:ffffaa1d0152fb58 EFLAGS: 00010046
[ 49.460024] RAX: 0000000000000000 RBX: ffff9f2b37d31180 RCX: 0000000000000000
[ 49.460803] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff9ef368c90000
[ 49.461358] RBP: 0000000000000000 R08: 0000000000000400 R09: 0000000000000400
[ 49.461964] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 49.462490] R13: 0000000000000000 R14: ffff9ef368c90000 R15: ffff9f2b37d31280
[ 49.463061] FS: 000000c000051898(0000) GS:ffff9f2ba86df000(0000) knlGS:0000000000000000
[ 49.463604] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 49.464069] CR2: 0000000000000051 CR3: 000000019681b000 CR4: 0000000000b50ef0
[ 49.464798] Call Trace:
[ 49.465083]
[ 49.465274] pick_next_task_fair+0x28/0x2d0
[ 49.465517] __pick_next_task+0x4c/0x1f0
[ 49.465790] __schedule+0x1a3/0x1460
[ 49.466150] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.466640] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.467061] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.467427] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.467977] schedule+0x6e/0xe0
[ 49.468291] x64_sys_call+0x1619/0x1870
[ 49.468610] do_syscall_64+0x85/0x200
[ 49.468955] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.469343] ? do_syscall_64+0xb6/0x200
[ 49.469646] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.469993] ? __x64_sys_openat+0x80/0xa0
[ 49.470248] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.470628] ? do_syscall_64+0xb6/0x200
[ 49.470923] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.471304] ? do_syscall_64+0xb6/0x200
[ 49.471753] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.472126] ? do_syscall_64+0xb6/0x200
[ 49.472388] ? do_epoll_ctl+0x11d/0x3a0
[ 49.472654] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.472984] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.473352] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.473826] ? __se_sys_fcntl+0x9e/0xb0
[ 49.474224] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.474592] ? do_syscall_64+0xb6/0x200
[ 49.474863] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.475220] ? __se_sys_fcntl+0x9e/0xb0
[ 49.475464] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.475866] ? do_syscall_64+0xb6/0x200
[ 49.476183] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.476488] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.476798] ? do_syscall_64+0xb6/0x200
[ 49.477060] ? srso_alias_return_thunk+0x5/0xfbef5
[ 49.477377] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 49.477734] RIP: 0033:0x479147
[ 49.478001] Code: 0f 05 48 3d 01 f0 ff ff 76 0b c7 04 25 f1 00 00 00 f1 00 00 00 48 83 c4 20 5d c3 cc cc cc cc cc cc cc cc b8 18 00 00 00 0f 05 cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc
[ 49.479196] RSP: 002b:000000c00020fdd8 EFLAGS: 00000297 ORIG_RAX: 0000000000000018
[ 49.479682] RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 0000000000479147
[ 49.480215] RDX: 0000000000000101 RSI: 0000000000000000 RDI: 0000000000000004
[ 49.480814] RBP: 000000c00020fe30 R08: 0000000000000005 R09: 0000000000000101
[ 49.481288] R10: 000000c00004e001 R11: 0000000000000297 R12: 000000c00020fd98
[ 49.481868] R13: 000000c0000393a8 R14: 000000c000005880 R15: 000000c000216080
[ 49.482346]
[ 49.482529] Modules linked in:
[ 49.482793] CR2: 0000000000000051
[ 49.483269] ---[ end trace 0000000000000000 ]---
[ 49.483616] RIP: 0010:pick_task_fair.llvm.17008003011273840175+0xea/0x1b0
[ 49.484061] Code: c2 49 0f af f0 48 01 f1 48 8b 70 70 49 2b 76 30 48 0f af f2 48 39 f1 0f 8d 63 ff ff ff be 01 00 00 00 4c 89 f7 e8 46 88 00 00 <80> 78 51 00 74 30 ba 01 02 00 00 48 89 df 48 89 c6 e8 a0 20 00 00
[ 49.485163] RSP: 0018:ffffaa1d0152fb58 EFLAGS: 00010046
[ 49.485453] RAX: 0000000000000000 RBX: ffff9f2b37d31180 RCX: 0000000000000000
[ 49.485991] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff9ef368c90000
[ 49.486570] RBP: 0000000000000000 R08: 0000000000000400 R09: 0000000000000400
[ 49.487036] R10: 0000000000000002 R11: 0000000000000000 R12: 0000000000000002
[ 49.487492] R13: 0000000000000000 R14: ffff9ef368c90000 R15: ffff9f2b37d31280
[ 49.487983] FS: 000000c000051898(0000) GS:ffff9f2ba86df000(0000) knlGS:0000000000000000
[ 49.488466] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 49.488826] CR2: 0000000000000051 CR3: 000000019681b000 CR4: 0000000000b50ef0
[ 49.489275] Kernel panic - not syncing: Fatal exception
[ 49.490970] Kernel Offset: 0xb000000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)
Die Verbindung mit dem virtuellen Computer oder Container wurde geschlossen.
```

### Kernel version

6.18.2-locietta-WSL2-xanmod1 zen3

### WSL version

2.7.0.0

### Windows version

win11 25h2

### Distro

ubuntu 24.04

### Additional context

_No response_

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the panic on WSL 2.7.0.0 with kernel 6.18.2-locietta-WSL2-xanmod1, Ubuntu 24.04, and Windows 11 25H2. Read the trace around pick_task_fair and determine the cause of the NULL pointer dereference; done means the kernel no longer panics under the reported workload.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
operating-systems
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.