Public bug reported:

I got this backtrace when running my up-to-date Kubuntu natty on Lenovo
X200s with standard apps + VirtualBox:


Mar  2 07:54:00 lure kernel: [  383.787907] warning: `VirtualBox' uses 32-bit 
capabilities (legacy support in use)
Mar  2 09:17:05 lure kernel: [ 5368.527074] kernel tried to execute 
NX-protected page - exploit attempt? (uid: 1001)
Mar  2 09:17:05 lure kernel: [ 5368.527120] BUG: unable to handle kernel paging 
request at ffffffff816bfca3
Mar  2 09:17:05 lure kernel: [ 5368.527157] IP: [<ffffffff816bfca3>] 
__func__.16232+0x39470/0x1b8635
Mar  2 09:17:05 lure kernel: [ 5368.527197] PGD 1a05067 PUD 1a09063 PMD 
80000000016001e1
Mar  2 09:17:05 lure kernel: [ 5368.527233] Oops: 0011 [#1] SMP
Mar  2 09:17:05 lure kernel: [ 5368.527255] last sysfs file: 
/sys/devices/LNXSYSTM:00/device:00/PNP0A08:00/device:01/PNP0C09:00/PNP0C0A:00/power_supply/BAT0/energy_now
Mar  2 09:17:05 lure kernel: [ 5368.527315] CPU 0
Mar  2 09:17:05 lure kernel: [ 5368.527328] Modules linked in: rfcomm sco bnep 
l2cap vboxnetadp vboxnetflt vboxdrv microcode parport_pc ppdev arc4 
snd_hda_codec_conexant snd_hda_intel snd_hda_codec iwlagn thinkpad_acpi 
snd_hwdep snd_pcm snd_seq_midi iwlcore snd_rawmidi snd_seq_midi_event snd_seq 
snd_timer snd_seq_device mac80211 snd cfg80211 snd_page_alloc psmouse serio_raw 
btusb soundcore bluetooth lp parport nvram tpm_tis tpm tpm_bios sha256_generic 
cryptd aes_x86_64 aes_generic dm_crypt i915 usb_storage uas drm_kms_helper 
e1000e ahci drm i2c_algo_bit video libahci

Mar  2 09:17:05 lure kernel: [ 5368.527661]
Mar  2 09:17:05 lure kernel: [ 5368.527673] Pid: 1851, comm: yakuake Not 
tainted 2.6.38-5-generic #32-Ubuntu LENOVO 74705HG/74705HG
Mar  2 09:17:05 lure kernel: [ 5368.527726] RIP: 0010:[<ffffffff816bfca3>]  
[<ffffffff816bfca3>] __func__.16232+0x39470/0x1b8635
Mar  2 09:17:05 lure kernel: [ 5368.527773] RSP: 0018:ffff88010d6b5aa8  EFLAGS: 
00010246
Mar  2 09:17:05 lure kernel: [ 5368.527801] RAX: 00000000fffffffc RBX: 
ffff88010d6b5b98 RCX: 00000000c0000100
Mar  2 09:17:05 lure kernel: [ 5368.527837] RDX: 0000000000000000 RSI: 
ffff880133742d80 RDI: ffff8800bd213b00
Mar  2 09:17:05 lure kernel: [ 5368.527872] RBP: ffff88010d6b5aa8 R08: 
ffff88010d6b4000 R09: 000000000000037c
Mar  2 09:17:05 lure kernel: [ 5368.527908] R10: 0000000000000001 R11: 
0000000000000001 R12: ffff88010d6b5e44
Mar  2 09:17:05 lure kernel: [ 5368.527943] R13: ffff880132b2e9c0 R14: 
ffff88010d6b5b98 R15: ffff88010d6b5e44
Mar  2 09:17:05 lure kernel: [ 5368.529595] FS:  00007f9e59af3780(0000) 
GS:ffff8800bd200000(0000) knlGS:0000000000000000
Mar  2 09:17:05 lure kernel: [ 5368.530009] CS:  0010 DS: 0000 ES: 0000 CR0: 
000000008005003b
Mar  2 09:17:05 lure kernel: [ 5368.530009] CR2: ffffffff816bfca3 CR3: 
000000010d601000 CR4: 00000000000026f0

Mar  2 09:17:05 lure kernel: [ 5368.530009] DR0: 0000000000000000 DR1: 
0000000000000000 DR2: 0000000000000000
Mar  2 09:17:05 lure kernel: [ 5368.530009] DR3: 0000000000000000 DR6: 
00000000ffff0ff0 DR7: 0000000000000400
Mar  2 09:17:05 lure kernel: [ 5368.530009] Process yakuake (pid: 1851, 
threadinfo ffff88010d6b4000, task ffff880119c00000)
Mar  2 09:17:05 lure kernel: [ 5368.530009] Stack:
Mar  2 09:17:05 lure kernel: [ 5368.530009]  ffff88010d6b5ad8 ffffffff81175b99 
ffff88010d6b5ad8 0000000000000000
Mar  2 09:17:05 lure kernel: [ 5368.530009]  0000000000000000 0000000000000000 
ffff88010d6b5b78 ffffffff811761da
Mar  2 09:17:05 lure kernel: [ 5368.530009]  0000000000000000 ffff880119c00000 
00ff88010d6b5b38 0000000000000000
Mar  2 09:17:05 lure kernel: [ 5368.530009] Call Trace:
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff81175b99>] 
poll_schedule_timeout+0x49/0x70
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff811761da>] 
do_poll.clone.2+0x1ca/0x290
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff81177149>] 
do_sys_poll+0x1c9/0x240
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff81175c70>] ? 
__pollwait+0x0/0xf0
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff81175d60>] ? 
pollwake+0x0/0x60

Mar  2 09:17:05 lure kernel: last message repeated 6 times
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff81163422>] ? 
do_sync_read+0xd2/0x110
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff812784b3>] ? 
security_file_permission+0x93/0xb0
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff81163741>] ? 
rw_verify_area+0x61/0xf0
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff81163ca7>] ? 
vfs_read+0x167/0x180
Mar  2 09:17:05 lure kernel: [ 5368.530009]  [<ffffffff811772a6>] 
sys_poll+0x76/0x110

Mar  2 09:17:05 lure kernel: [ 5368.530009] Code: c0 3b 64 81 ff ff ff ff 00 3c 
64 81 ff ff ff ff 20 3c 64 81 ff ff ff ff c0 3c 64 81 ff ff ff ff 40 3d 64 81 
ff ff ff ff 62 3d 64 <81> ff ff ff ff 6a 3d 64 81 ff ff ff ff 72 3d 64 81 ff ff 
ff ff
Mar  2 09:17:05 lure kernel: [ 5368.530009] RIP  [<ffffffff816bfca3>] 
__func__.16232+0x39470/0x1b8635
Mar  2 09:17:05 lure kernel: [ 5368.530009]  RSP <ffff88010d6b5aa8>
Mar  2 09:17:05 lure kernel: [ 5368.530009] CR2: ffffffff816bfca3
Mar  2 09:17:05 lure kernel: [ 5368.609835] ---[ end trace bafcc5a6226e3a8e ]---

ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: linux-image-2.6.38-5-generic 2.6.38-5.32
Regression: Yes
Reproducible: No
ProcVersionSignature: Ubuntu 2.6.38-5.32-generic 2.6.38-rc6
Uname: Linux 2.6.38-5-generic x86_64
AlsaVersion: Advanced Linux Sound Architecture Driver Version 1.0.23.
Architecture: amd64
ArecordDevices:
 **** List of CAPTURE Hardware Devices ****
 card 0: Intel [HDA Intel], device 0: CONEXANT Analog [CONEXANT Analog]
   Subdevices: 1/1
   Subdevice #0: subdevice #0
AudioDevicesInUse:
 USER        PID ACCESS COMMAND
 /dev/snd/controlC0:  lukar      1815 F.... pulseaudio
 /dev/snd/pcmC0D0p:   lukar      1815 F...m pulseaudio
CRDA: Error: [Errno 2] No such file or directory
Card0.Amixer.info:
 Card hw:0 'Intel'/'HDA Intel at 0xf2620000 irq 46'
   Mixer name   : 'Conexant CX20561 (Hermosa)'
   Components   : 'HDA:14f15051,17aa20ff,00100000'
   Controls      : 16
   Simple ctrls  : 8
Card29.Amixer.info:
 Card hw:29 'ThinkPadEC'/'ThinkPad Console Audio Control at EC reg 0x30, fw 
7XHT24WW-1.06'
   Mixer name   : 'ThinkPad EC 7XHT24WW-1.06'
   Components   : ''
   Controls      : 1
   Simple ctrls  : 1
Card29.Amixer.values:
 Simple mixer control 'Console',0
   Capabilities: pswitch pswitch-joined penum
   Playback channels: Mono
   Mono: Playback [on]
Date: Wed Mar  2 09:56:33 2011
Frequency: Once every few days.
HibernationDevice: RESUME=UUID=16ac97e6-961b-4a8f-b763-fc40aeccc5a4
InstallationMedia: Kubuntu 11.04 "Natty Narwhal" - Alpha amd64 (20110129)
MachineType: LENOVO 74705HG
ProcEnviron:
 LANGUAGE=
 PATH=(custom, user)
 LANG=en_US.UTF-8
 SHELL=/bin/bash
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-2.6.38-5-generic 
root=/dev/mapper/plain-root ro quiet splash vt.handoff=7
RelatedPackageVersions:
 linux-restricted-modules-2.6.38-5-generic N/A
 linux-backports-modules-2.6.38-5-generic  N/A
 linux-firmware                            1.47
SourcePackage: linux
UpgradeStatus: No upgrade log present (probably fresh install)
dmi.bios.date: 03/10/2010
dmi.bios.vendor: LENOVO
dmi.bios.version: 6DET63WW (3.13 )
dmi.board.name: 74705HG
dmi.board.vendor: LENOVO
dmi.board.version: Not Available
dmi.chassis.asset.tag: No Asset Information
dmi.chassis.type: 10
dmi.chassis.vendor: LENOVO
dmi.chassis.version: Not Available
dmi.modalias: 
dmi:bvnLENOVO:bvr6DET63WW(3.13):bd03/10/2010:svnLENOVO:pn74705HG:pvrThinkPadX200s:rvnLENOVO:rn74705HG:rvrNotAvailable:cvnLENOVO:ct10:cvrNotAvailable:
dmi.product.name: 74705HG
dmi.product.version: ThinkPad X200s
dmi.sys.vendor: LENOVO

** Affects: linux (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug kernel-sound natty needs-upstream-testing 
regression-update

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/727652

Title:
  kernel tried to execute NX-protected page  -> NULL page request?

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to