On 1/2/2026 9:51 AM, Venkat Rao Bagalkote wrote:
Greetings!!!
IBM CI has reported a below crash. This occurs, in the TX path while
sending data over TCP. e.g., cloning the linux repo or running iperf3 tool.
Environment
-----------
- Platform: IBM,9080-HEX Power11 (architected), HV: phyp (pSeries)
- Firmware: FW1110.01 (NH1110_069)
- Kernel: v6.19-rc3 (Linus master)
- Config: LE, PAGE_SIZE=64K, MMU=Radix, SMP NR_CPUS=8192, NUMA pSeries
- Workload: sustained TCP send from sshd
Traces:
[ 2480.578185] BUG: Kernel NULL pointer dereference on read at 0x00000000
[ 2480.578189] Faulting instruction address: 0xc000000000f92830
[ 2480.578192] Oops: Kernel access of bad area, sig: 11 [#1]
[ 2480.578195] LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=8192 NUMA pSeries
[ 2480.578200] Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6
nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct
nft_chain_nat nf_nat nf_conntrack bonding nf_defrag_ipv6 nf_defrag_ipv4
tls rfkill ip_set nf_tables nfnetlink kmem device_dax pseries_rng
vmx_crypto dax_pmem fuse ext4 crc16 mbcache jbd2 sd_mod nd_pmem sg
papr_scm libnvdimm ibmvscsi ibmveth scsi_transport_srp pseries_wdt
[ 2480.578234] CPU: 31 UID: 0 PID: 1895 Comm: sshd Kdump: loaded Not
tainted 6.19.0-rc1-next-20251219 #1 VOLUNTARY
[ 2480.578239] Hardware name: IBM,9080-HEX Power11 (architected)
0x820200 0xf000007 of:IBM,FW1110.01 (NH1110_069) hv:phyp pSeries
[ 2480.578243] NIP: c000000000f92830 LR: c000000000f92830 CTR:
c00000000002852c
[ 2480.578246] REGS: c000000071d3f0c0 TRAP: 0300 Not tainted (6.19.0-
rc1-next-20251219)
This looks like the same NULL pointer dereference in __dev_xmit_skb()
fixed in v6.19-rc4
(https://lore.kernel.org/all/[email protected]/).
https://lore.kernel.org/all/[email protected]/
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c04de0c79534
Thanks,
Alok